首页> 外文会议>2nd international conference on security of information and networks 2009 >Improving Risk Assessment Methodology: A Statistical Design of Experiments Approach
【24h】

Improving Risk Assessment Methodology: A Statistical Design of Experiments Approach

机译:改进风险评估方法:实验方法的统计设计

获取原文

摘要

In order to manage risks to the IT environments and to satisfy government and industry regulations, most enterprises are required to conduct risk assessments. These risk assessments are used to drive organizational decisions on information security. However, despite this need, current approaches lack granular guidance on some key steps and have focused on qualitative data rather than quantitative data which reduces the value of the results for the decision makers. This paper proposes a statistical design of experiments approach that will enhance the quantitative aspects of the risk assessment exercise and will make risk assessments smarter, more precise and more efficient. Specifically, our paper demonstrates that a Plackett-Burman design can be used to: (a) identify the subset of security controls that are critical to the enterprise; (b) determine the configuration of these controls; and (c) quantitatively analyze the impact of security enhancements. This paper expands on our previous research by applying statistical models at a macro security architecture level as opposed to determining parameters for individual controls.
机译:为了管理IT环境的风险并满足政府和行业法规,大多数企业都需要进行风险评估。这些风险评估用于驱动组织做出有关信息安全的决策。但是,尽管有这种需求,但是当前的方法在某些关键步骤上缺乏详尽的指导,并且只关注定性数据而不是定量数据,这降低了决策者的结果价值。本文提出了一种实验方法的统计设计,该方法将增强风险评估工作的定量方面,并使风险评估更智能,更精确,更有效。具体而言,我们的论文证明了Plackett-Burman设计可用于:(a)识别对企业至关重要的安全控制的子集; (b)确定这些控件的配置; (c)定量分析增强安全性的影响。本文通过在宏观安全体系结构级别应用统计模型(而不是为单个控件确定参数)来扩展我们以前的研究。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号