• DocumentCode
    1804427
  • Title

    Process-Oriented Approach for Validating Asset Value for Evaluating Information Security Risk

  • Author

    Cha, Shi-Cho ; Liu, Li-Ting ; Yu, Bo-Chen

  • Author_Institution
    Nat. Taiwan Univ. of Sci. & Technol., Taipei, Taiwan
  • Volume
    3
  • fYear
    2009
  • fDate
    29-31 Aug. 2009
  • Firstpage
    379
  • Lastpage
    385
  • Abstract
    To provide a systematic means of identifying and assessing information security risks, organizations typically adopt asset-driven (or asset-oriented) risk assessment schemes. These schemes require organizations to identify their information assets, find out potential incidents to those assets, and assess expected losses associated with those incidents. While asset value is important in determining loss expectancies for associated incidents, the accuracy of asset valuation is crucial. Although numerous guidelines exist regarding how best to evaluate asset value, current risk assessment schemes generally overlook how to validate assessments of asset value. Consequently, this work presents a process-oriented approach that organizations can employ to validate and adjust asset value. The approach presented in this study can help organizations represent their business processes and information assets used in those processes using flowcharts, and also mark dependencies among assets based on confidentiality, integrity, and availability requirements on flowcharts. Organizations can use the markings of dependencies to validate and correct results associated with asset valuation. If organizations can more accurately evaluate asset value, they can improve the effectiveness of their risk assessment. Therefore, the approach presented in this study can hopefully help improve organizational information security.
  • Keywords
    data integrity; flowcharting; formal specification; risk management; security of data; asset-driven information security risk assessment; asset-oriented risk assessment scheme; business process; data availability requirements; data confidentiality requirements; data integrity requirements; dependency marking; flow chart; information asset value validation; information security risk identification; information security risk management process; loss expectancy; organizational information security risk evaluation; potential incident; process-oriented approach; Availability; Cost accounting; Flowcharts; Guidelines; ISO standards; Information security; Management information systems; Performance evaluation; Risk management; Standards organizations; Information Asset Valuation; Risk Assessment; Risk Management;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computational Science and Engineering, 2009. CSE '09. International Conference on
  • Conference_Location
    Vancouver, BC
  • Print_ISBN
    978-1-4244-5334-4
  • Electronic_ISBN
    978-0-7695-3823-5
  • Type

    conf

  • DOI
    10.1109/CSE.2009.217
  • Filename
    5283298