• DocumentCode
    3647562
  • Title

    Investment analysis of Information Security Management in Croatian seaports

  • Author

    Saša Aksentijević;Edvard Tijan;Bojan Hlača

  • Author_Institution
    Saipem Mediteran Usluge, Alda Colonnella 2, Rijeka, Croatia
  • fYear
    2012
  • fDate
    5/1/2012 12:00:00 AM
  • Firstpage
    1464
  • Lastpage
    1469
  • Abstract
    Existing models of Information Security Management Systems in seaports usually involve threat evaluation, vulnerability management and risk analysis. Threat evaluation is a catalogue based analysis, outlining various applicable protection levels related to architecture, hardware, software and personnel, aiming to standardize the information security management approach. Vulnerability analysis is attempting to evaluate organizational and technical aspects of all information security components in terms of their inherent flaws. Risk analysis combines both threat and vulnerability analysis in order to define countermeasures in an objective, measurable and sustainable way. However, very often all three possible approaches are devoid of economic and financial analysis of seaport information security investments. In this paper authors propose a combined model which includes both technical and financial approach to information security management and decision-making in Croatian Port Community Systems.
  • Keywords
    "Information security","Investments","Economics","Decision making","Software"
  • Publisher
    ieee
  • Conference_Titel
    MIPRO, 2012 Proceedings of the 35th International Convention
  • Print_ISBN
    978-1-4673-2577-6
  • Type

    conf

  • Filename
    6240883