Applying ROI analysis to support SOA information security investment decisions

被引:4
作者
Buck, Kevin [1 ]
Das, Prasant [1 ]
Hanf, Diane [2 ]
机构
[1] Mitre Corp, 7525 Colshire Dr, Mclean, VA 22102 USA
[2] Mitre Corp, Bedford, MA 01730 USA
来源
2008 IEEE CONFERENCE ON TECHNOLOGIES FOR HOMELAND SECURITY, VOLS 1 AND 2 | 2008年
关键词
D O I
10.1109/THS.2008.4534478
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Offering functionality and data in a secure manner poses significant challenges for Government enterprises that are embracing approaches, such as Service-Oriented Architectures (SOA), especially when there is a desire to promote information sharing across functional, organizational, or Community of Interest (CO-1) boundaries. Many Government organizations evaluate implementation of security measures against the risk that a particular vulnerability will be exploited by a particular threat. Informed information security investment decisions are made based upon analysis of cost, benefit, schedule, performance, and risk tradeoffs. The investment decision-making spacefor information security in a web-based, service-oriented environment is explored in this paper, and methods for evaluating operational, economic and performance implications are considered This paper discusses the value and practicality of applying Return-on-Investment (ROJ) analysis for Government information security investment decision-making, especially when information sharing is a key success driver. Recommendations are based upon preliminary findings of a MITRE Mission-Oriented Investigation and Experimentation (MOJE) effort related to SOA Performance Measures Expression in PerformanceBased Acquisition (PBA) Vehicles.
引用
收藏
页码:359 / +
页数:6
相关论文
共 11 条
[1]  
ALLEN J, CERT EXECUTIVES PODA
[2]  
[Anonymous], GUIDELINES DISCOUNT
[3]  
BRAUER B, 2005, KEY ELEMENTS SOA
[4]  
*DEF INF SYST AG, DOD PUBL KEY INFR PK
[5]  
*DISA, 2004, ARCH VERS 0 5 PIL
[6]  
*DISA, 2004, SUMM SEC ARCH NET CE
[7]  
FOSTER S, ANAL RETURN INVESTME, P5
[8]  
*OASD NII, 2005, HOR FUS PROTF MAN AC
[9]  
*OASIS, 2003, WEB SEV SEC SOAP MES
[10]  
PESCATORE J, 2005, GARTNER WIRELESS MOB, P8