• DocumentCode
    2432469
  • Title

    Information security metric integrating enterprise objectives

  • Author

    Karabey, Bugra ; Baykal, Nazife

  • Author_Institution
    Inf. Inst., Middle East Tech. Univ., Ankara, Turkey
  • fYear
    2009
  • fDate
    5-8 Oct. 2009
  • Firstpage
    144
  • Lastpage
    148
  • Abstract
    Security is one of the key concerns in the domain of information technology systems. Maintaining the confidentiality, integrity and availability of such systems, mandates a rigorous prior analysis of the security risks that confront these systems. In order to analyze, mitigate and recover from these risks a metrics based approach is essential in prioritizing the response strategies against these risks. In addition to that the enterprise objectives must be focally integrated in the definition, impact calculation and prioritization phases of this analysis to come up with metrics that are useful both for the technical and managerial communities within an organization. Also the inclusion of enterprise objectives in the identification of information assets will act as a preliminary filter to overcome the real life scalability issues inherent with such threat modeling efforts. Within this study an attack tree based approach will be utilized to offer an information security risk metric that integrates the enterprise objectives with the information asset vulnerabilities within an organization. In the essential step of enterprise resource identification, the resource-based view of a company will be utilized.
  • Keywords
    information technology; risk analysis; security of data; enterprise objective; information security metric; information technology system; risk metric; Availability; Companies; Information filtering; Information filters; Information management; Information security; Information technology; Risk analysis; Risk management; Scalability; Information security; attack trees; enterprise objectives; resource based view; risk metrics;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security Technology, 2009. 43rd Annual 2009 International Carnahan Conference on
  • Conference_Location
    Zurich
  • Print_ISBN
    978-1-4244-4169-3
  • Electronic_ISBN
    978-1-4244-4170-9
  • Type

    conf

  • DOI
    10.1109/CCST.2009.5335549
  • Filename
    5335549