DocumentCode
2432469
Title
Information security metric integrating enterprise objectives
Author
Karabey, Bugra ; Baykal, Nazife
Author_Institution
Inf. Inst., Middle East Tech. Univ., Ankara, Turkey
fYear
2009
fDate
5-8 Oct. 2009
Firstpage
144
Lastpage
148
Abstract
Security is one of the key concerns in the domain of information technology systems. Maintaining the confidentiality, integrity and availability of such systems, mandates a rigorous prior analysis of the security risks that confront these systems. In order to analyze, mitigate and recover from these risks a metrics based approach is essential in prioritizing the response strategies against these risks. In addition to that the enterprise objectives must be focally integrated in the definition, impact calculation and prioritization phases of this analysis to come up with metrics that are useful both for the technical and managerial communities within an organization. Also the inclusion of enterprise objectives in the identification of information assets will act as a preliminary filter to overcome the real life scalability issues inherent with such threat modeling efforts. Within this study an attack tree based approach will be utilized to offer an information security risk metric that integrates the enterprise objectives with the information asset vulnerabilities within an organization. In the essential step of enterprise resource identification, the resource-based view of a company will be utilized.
Keywords
information technology; risk analysis; security of data; enterprise objective; information security metric; information technology system; risk metric; Availability; Companies; Information filtering; Information filters; Information management; Information security; Information technology; Risk analysis; Risk management; Scalability; Information security; attack trees; enterprise objectives; resource based view; risk metrics;
fLanguage
English
Publisher
ieee
Conference_Titel
Security Technology, 2009. 43rd Annual 2009 International Carnahan Conference on
Conference_Location
Zurich
Print_ISBN
978-1-4244-4169-3
Electronic_ISBN
978-1-4244-4170-9
Type
conf
DOI
10.1109/CCST.2009.5335549
Filename
5335549
Link To Document