Title :
Justifying information security investments in web software: (Quantitative techno-business modeling approach)
Author :
Zoric, Josip ; Helme, Arne ; Kvalheim, Håvard ; Sundve, Espen
Author_Institution :
Telenor GBD&R, Norwegian Univ. of Sci. & Technol., Trondheim, Norway
Abstract :
Security of services and platforms is a vital and complex aspect, which requires significant investments. We use a techno-business modeling (TBM) approach for analysis of service platform security, aiming at justifying the information security investments during the life-cycle of a web software platform. Techno-business environment influences the above-mentioned models and scenarios. It is analyzed by drivers and driver-based scenarios. The TBM had to be extended for security analyses. We have added the set of security drivers and scenarios, in order to model the effect of misuse cases (triggered by security breaches). After simulation of security breaches and misuse cases, their influence on the rest of the environmental drivers (and the TBM models and scenarios) is calculated. Quantitative analysis (value and cash flow based valuation) captured both the short-term and the long-term effects of the misuse cases. We demonstrate our modeling approach on the proof-of-the-concept case: web software solution for service delivery to social network sites.
Keywords :
Internet; security of data; social networking (online); Web software; information security investments; quantitative techno-business modeling; service platform security; social network sites; Security; Web software; service platform; techno-business modeling;
Conference_Titel :
Future Network and Mobile Summit, 2010
Conference_Location :
Florence
Print_ISBN :
978-1-905824-16-8