DocumentCode :
1923810
Title :
Estimating ToE Risk Level Using CVSS
Author :
Houmb, Siv Hilde ; Franqueira, Virginia N L
Author_Institution :
Inf. Syst. Group, Univ. of Twente, Enschede
fYear :
2009
fDate :
16-19 March 2009
Firstpage :
718
Lastpage :
725
Abstract :
Security management is about calculated risk and requires continuous evaluation to ensure cost, time and resource effectiveness. Parts of which is to make future-oriented, cost-benefit investments in security. Security investments must adhere to healthy business principles where both security and financial aspects play an important role. Information on the current and potential risk level is essential to successfully trade-off security and financial aspects. Risk level is the combination of the frequency and impact of a potential unwanted event, often referred to as a security threat or misuse. The paper presents a risk level estimation model that derives risk level as a conditional probability over frequency and impact estimates. The frequency and impact estimates are derived from a set of attributes specified in the Common Vulnerability Scoring System (CVSS). The model works on the level of vulnerabilities (just as the CVSS) and is able to compose vulnerabilities into service levels. The service levels define the potential risk levels and are modelled as a Markov process, which are then used to predict the risk level at a particular time.
Keywords :
risk management; security of data; CVSS; Markov process; ToE risk level; common vulnerability scoring system; conditional probability; risk level estimation model; security management; target of evaluation; Availability; Conference management; Data security; Frequency estimation; Information security; Investments; Management information systems; National security; Niobium; Resource management; CVSS; Calculated risk; Operational security; Quantifying security; Risk estimation;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Availability, Reliability and Security, 2009. ARES '09. International Conference on
Conference_Location :
Fukuoka
Print_ISBN :
978-1-4244-3572-2
Electronic_ISBN :
978-0-7695-3564-7
Type :
conf
DOI :
10.1109/ARES.2009.151
Filename :
5066553
Link To Document :
بازگشت