首页> 外文期刊>Future generation computer systems >Framework for Calculating Return on Security Investment (ROSI) for Security-Oriented Organizations
【24h】

Framework for Calculating Return on Security Investment (ROSI) for Security-Oriented Organizations

机译:为安全为导向的组织计算安全投资回报率的框架

获取原文
获取原文并翻译 | 示例
       

摘要

Today's business environment is extremely dynamic and reliant on innovative Information Technology (IT). Such dependence upon technology leads to an increased rate of successful cyber-attacks whose impact is greater than ever. Due to the exponential increase in security breaches, companies should secure their IT systems by adopting appropriate risk management framework. Organizations have to make justified investments in cyber security. However, it is quite challenging to convince higher management to invest in security measures, since such investments cannot be exactly translated into profits. The Return on Security Investment (ROSI) holds great importance to justify such security investments. A large number of ROSI solutions have already been proposed. However, these solutions do not provide any approach to analyze the impact of single security investment upon whole infrastructure. Furthermore, uncertainty of security incident emerges as another important challenge. The existing ROSI frameworks work on approximations, which can be influenced by employees' exposure and experience, resulting in wrong estimation. The objective of this research is to propose a comprehensive framework to measure ROSI effectively by overcoming gaps in the traditional approaches. The framework has been validated with the help of Common Vulnerability Security System (CVSS) attack dataset. The results show that the annual loss in the absence of security mechanisms is very high i.e. 585,553. However, by following the proposed systematic approach to determine ROSI, it can be reduced to 146,388 which is comparatively low. As a result, organization can save its resources, time, money, trust, and reputation in the market. (C) 2019 Elsevier B.V. All rights reserved.
机译:今天的商业环境极其充满活力和依赖于创新信息技术(IT)。这种依赖性能够增加成功的网络攻击率,其影响大于以往任何时候。由于安全漏洞的指数增加,公司应通过采用适当的风险管理框架来保护其IT系统。组织必须对网络安全进行合理的投资。但是,说服更高的管理层投资安全措施是非常具有挑战性的,因为此类投资不能完全转化为利润。安全投资回报(ROSI)非常重视证明此类安全投资。已经提出了大量的ROSI解决方案。然而,这些解决方案没有提供任何方法来分析单一安全投资对整个基础架构的影响。此外,安全事件的不确定性成为另一个重要挑战。现有的ROSI框架在近似值上工作,可能受员工的曝光和经验影响,导致错误的估计。本研究的目的是提出通过克服传统方法中的差距有效地衡量ROSI的全面框架。框架已在常见漏洞安全系统(CVSS)攻击数据集的帮助下验证。结果表明,缺乏安全机制的年损失非常高,即585,553。然而,通过遵循所提出的系统方法来确定ROSI,可以减少到146,388,相对较低。因此,组织可以节省其资源,时间,金钱,信任和市场声誉。 (c)2019 Elsevier B.v.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号