首页> 外文会议>Americas Conference on Information Systems(AMCIS 2006) vol.6 >A Framework for Assessing IT Security Investment Portfolios
【24h】

A Framework for Assessing IT Security Investment Portfolios

机译:评估IT安全投资组合的框架

获取原文

摘要

Organizations are faced with different types of information security threats and implement several security technologies to mitigate these security threats. The security technologies vary in their ability to deal with different types of security threats and hence, organizations usually implement a portfolio of security technologies. A key challenge for organizations is to evaluate and determine the value of the counter-measures in the context of these portfolios. This research develops a framework for systematically evaluating the value of portfolios of different types of security investments given the threats and business environment faced by an organization. The proposed framework builds on the theory of financial asset valuation and develops a simulation model that considers a variety of factors such as type of threat, frequency of arrival, possible damage, and recovery time from damage.
机译:组织面临着不同类型的信息安全威胁,并实施了多种安全技术来缓解这些安全威胁。安全技术应对各种类型的安全威胁的能力各不相同,因此,组织通常会实施一系列安全技术。组织面临的主要挑战是在这些项目组合的背景下评估和确定对策的价值。这项研究开发了一个框架,可以根据组织面临的威胁和商业环境,系统地评估不同类型的安全投资的投资组合的价值。拟议的框架建立在金融资产估值理论的基础上,并开发了一个模拟模型,该模型考虑了多种因素,例如威胁的类型,到达的频率,可能的损害以及从损害中恢复的时间。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号