DocumentCode
3647562
Title
Investment analysis of Information Security Management in Croatian seaports
Author
Saša Aksentijević;Edvard Tijan;Bojan Hlača
Author_Institution
Saipem Mediteran Usluge, Alda Colonnella 2, Rijeka, Croatia
fYear
2012
fDate
5/1/2012 12:00:00 AM
Firstpage
1464
Lastpage
1469
Abstract
Existing models of Information Security Management Systems in seaports usually involve threat evaluation, vulnerability management and risk analysis. Threat evaluation is a catalogue based analysis, outlining various applicable protection levels related to architecture, hardware, software and personnel, aiming to standardize the information security management approach. Vulnerability analysis is attempting to evaluate organizational and technical aspects of all information security components in terms of their inherent flaws. Risk analysis combines both threat and vulnerability analysis in order to define countermeasures in an objective, measurable and sustainable way. However, very often all three possible approaches are devoid of economic and financial analysis of seaport information security investments. In this paper authors propose a combined model which includes both technical and financial approach to information security management and decision-making in Croatian Port Community Systems.
Keywords
"Information security","Investments","Economics","Decision making","Software"
Publisher
ieee
Conference_Titel
MIPRO, 2012 Proceedings of the 35th International Convention
Print_ISBN
978-1-4673-2577-6
Type
conf
Filename
6240883
Link To Document