首页> 外文会议>IEEE Military Communications Conference >Analytical Frameworks to Assess the Effectiveness and Economic-Returns of Cybersecurity Investments
【24h】

Analytical Frameworks to Assess the Effectiveness and Economic-Returns of Cybersecurity Investments

机译:评估网络安全投资的有效性和经济回报的分析框架

获取原文

摘要

Critical considerations in engineering today's systems are securing the collection, access, and dissemination of the information they contain. Advanced computing technologies, ubiquitous environments, and sophisticated networks enable globally distributed information access to an uncountable number of consumers - and adversaries. Assuring the integrity of today's missions, and the highly networked systems they depend on, requires economic decisions in rapidly changing technology and cyber threat environments. Knowing that countermeasures effective against today's threats can be ineffective tomorrow, decision-makers need agile ways to assess the efficacies of investments in cyber security on assuring mission outcomes. Analytical methods in cyber security economics need to be flexible in their information demands. Some investment decisions may necessitate methods that use in-depth knowledge about a mission's information systems and networks, vulnerabilities, and adversary abilities to exploit weaknesses. Other investment decisions may necessitate methods that use only a high-level understanding of these dimensions. The sophistication of methods to conduct economic-benefit tradeoffs of mission assuring investments must calibrate to the range of knowledge environments present within an organization. This paper presents a family of analytical frameworks to assess and measure the effectiveness of cyber security and the economic-benefit tradeoffs of competing cyber security investments. These frameworks demonstrate ways to think through and shape an analysis of the economic-benefit returns on cyber security investments - rather than being viewed as rigid model structures.
机译:当今系统在工程设计中的关键考虑因素是确保其包含的信息的收集,访问和传播。先进的计算技术,无处不在的环境和复杂的网络使全球分布的信息可以访问无数消费者和对手。要确保当今任务的完整性以及它们所依赖的高度网络化系统的完整性,就需要在瞬息万变的技术和网络威胁环境中做出经济决策。决策者知道对抗当今威胁的有效对策明天可能无效,因此决策者需要灵活的方法来评估网络安全投资对确保任务成果的有效性。网络安全经济学中的分析方法需要灵活地满足其信息需求。一些投资决策可能需要采用对任务的信息系统和网络,漏洞和对手能力有深入了解的方法来利用弱点。其他投资决策可能需要仅使用对这些方面的高级理解的方法。进行任务保证投资的经济效益权衡的方法的复杂性必须根据组织内部存在的知识环境的范围进行校准。本文提出了一系列分析框架,用于评估和衡量网络安全的有效性以及竞争性网络安全投资的经济利益权衡。这些框架展示了思考和塑造对网络安全投资的经济效益回报的方法,而不是被视为僵化的模型结构。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号