Necessary measures - Metric-driven information security risk assessment and decision making

被引:18
作者
Baker, Wade H. [1 ]
Rees, Loren Paul
Tippett, Peter S.
机构
[1] Virginia Tech, Blacksburg, VA 24061 USA
[2] Virginia Tech, Dept Business Informat Technol, Blacksburg, VA USA
[3] ICSA Labs, Mechanicsburg, PA USA
关键词
D O I
10.1145/1290958.1290969
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Measurable, reliable real-world metrics are being used to improve information security decision making. Management is identifying and understanding the threats facing the organization to be able to take systematic action to reduce risk. Various taxonomies using a variety of techniques have been proposed to classify and systematize threats to information security. Security initiatives are more commonly driven by compliance mandates than by the principles of risk management. A more reasoned approach to measure and model security factors, including carefully delineating threats, gathering impact and financial loss data, and calculating reduced vulnerability through countermeasures, is required. Improved analysis and decision making should be expected to follow after taking these necessary measures.
引用
收藏
页码:101 / 106
页数:6
相关论文
共 11 条
[11]   Enemy at the gate: Threats to information security [J].
Whitman, ME .
COMMUNICATIONS OF THE ACM, 2003, 46 (08) :91-95