DocumentCode :
2554967
Title :
Method for insuring IT risks
Author :
Magnusson, Christer ; Yngström, Louise
Author_Institution :
Dept. of Comput. & Syst. Sci., Stockholm Univ., Sweden
fYear :
2004
fDate :
5-8 Jan. 2004
Abstract :
This paper explains in detail the method behind the insurance database estimated maximum information technology loss (EMitL). The database has been a crucial tool to make it possible to insure IT perils. It helps to insure IT-perils financially in the same professional way as consequences of traditional perils like fire, flood, and robbery are insured, and thereby secures shareholders\´ investments. EMitL estimates the security awareness in an existing IT-platform. Based on that information, existing security measures can be "priced" as they may reduce the estimated maximum loss figures - and thereby the costs for the insurance. In addition, a more cost-effective decision can be made on additional security measures. Furthermore, the costs for the loss exposure inherent in a business service/product can be estimated in a better way, and thereby be incorporated in the product\´s price. The IT insurances are based on the traditional industries\´ classes: liability, loss of property, and business interruption. The insurance class liability is divided into insurance policies for: business interruption, fraud and embezzlement, robbery and theft, defamation, infringement of privacy, and infringement of code, trademark etc. The insurance policies in the class loss of property are: fraud and embezzlement, and robbery and theft. The database EMitL layers insurance covers, which is a common method in the insurance industry. This means that the insurance policies are layered according to the amount of financial cover they provide. The insurance levels relate and are converted to security levels. These levels are built on the IT security properties integrity, availability and confidentiality, and are utilized differently, depending on the insurance level and the type of insurance policy. The properties and the levels constitute the base of the security polices produced by EMitL; they are used for the estimation of security awareness and as terms of insurance.
Keywords :
insurance; risk management; security of data; IT insurance; IT risk; IT-perils; business interruption; business product; business service; estimated maximum information technology loss; insurance class liability; insurance database; insurance industry; insurance policy; loss of property; security awareness; Costs; Data security; Databases; Fires; Floods; Information security; Information technology; Insurance; Investments; Loss measurement;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
System Sciences, 2004. Proceedings of the 37th Annual Hawaii International Conference on
Print_ISBN :
0-7695-2056-1
Type :
conf
DOI :
10.1109/HICSS.2004.1265445
Filename :
1265445
Link To Document :
بازگشت