A cost model for managing information security hazards

被引:11
作者
Ekenberg, L
Oberoi, S
Orci, I
机构
[1] TELIA,CORP SECUR,S-12386 FARSTA,SWEDEN
[2] ROYAL INST TECHNOL,DEPT COMP & SYST SCI,CTR SECUR INFORMAT,S-16440 KISTA,SWEDEN
关键词
Consequence analysis; Loss accounting; Risk analysis; Risk management; Uncertain reasoning;
D O I
10.1016/0167-4048(95)00021-6
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We present a model for the estimation of costs of risks and losses due to accidental or deliberate disclosure, transfer, delay, modification, or destruction of information. The model is characterized by (1) strong emphasis on consequence analysis, (2) high-level classification of risk objects, loss-provoking events, losses, loss costs and data items, and (3) typing data values according to their degree of vagueness. It has a sound theoretical background and is designed for practical use in the telecommunications industry. In order to provide a hrm basis for risk analysis and loss accounting we use an object-oriented approach to security called the PPIFEB approach. We compare this approach with some other approaches: (1) the organization-oriented approach found in most standard references; (2) the event/threat-oriented approach WAECUP of Bottom and Kostanoski [Introduction to Security and Loss Control, Prentice-Hall, New York, 1990]; and (3) the process-oriented approach of Post et al. [Security Administration: An Introduction to the Protective Services, 4th Edition, Butterworth-Heinemann, 1994] based on generic security functions. We claim that the PPI-FEB approach is the most appropriate for risk analysis and loss accounting.
引用
收藏
页码:707 / 717
页数:11
相关论文
共 24 条
  • [1] BOMAN M, 1995, NOV WORKSH DEC INT M
  • [2] BOTTOM N, 1990, INTRO SECURITY LOSS
  • [3] BRODER JF, 1984, RISK ANAL SECURITY S
  • [4] CARROLL JM, 1984, MANAGING RISK COMPUT
  • [5] COURTNEY RH, 1977, AFIPS NCC46
  • [6] DANIELSON M, 1995, THESIS ROYAL I TECHN
  • [7] DIXON G, 1990, RISKANALYS
  • [8] EKENBERG L, 1995, 11TH P IFIP SEC C, P357
  • [9] EKENBERG L, 1994, P INT C OP RES 94, P500
  • [10] EKENBERG L, 1995, P ICMAS 95, P89