Understanding the value of countermeasure portfolios in information systems security

成果类型:
Article
署名作者:
Kumar, Ram L.; Park, Sungjune; Subramaniam, Chandrasekar
署名单位:
University of North Carolina; University of North Carolina Charlotte; University of North Carolina; University of North Carolina Charlotte
刊物名称:
JOURNAL OF MANAGEMENT INFORMATION SYSTEMS
ISSN/ISSBN:
0742-1222
DOI:
10.2753/MIS0742-1222250210
发表日期:
2008
页码:
241-279
关键词:
technology RISK performance simulation MODEL
摘要:
Organizations are faced with a variety of information security threats and implement several information system security countermeasures (ISSCs) to mitigate possible damage due to security attacks. These security countermeasures vary in their ability to deal with different types of security attacks and, hence, are implemented as a portfolio of ISSCs. A key challenge for organizations is to understand the economic consequences of security attacks relative to the ISSC portfolio implemented. This paper combines the risk analysis and disaster recovery perspectives to build an integrated simulation model of ISSC portfolio value. The model incorporates the characteristics of an ISSC portfolio relative to the threat and business environments and includes the type of attack, frequency of attacks, possible damage, and the extent and time of recovery from damage. The simulation experiments provide interesting insights into the interactions between ISSC portfolio components and characteristics of business and threat environments in determining portfolio value.