loading...
Quantitative Assessment of Enterprise Security System
March 04-March 07
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/ARES.2008.1642008 Third International Conference o ...
 This Article 
 
PDF
HTML
 
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
In this paper we extend a model-based approach to security management with concepts and methods that provide a possibility for quantitative assessments. For this purpose we introduce security metrics and explain how they are aggregated using the underlying model as a frame. We measure numbers of attack of certain threats and estimate their likelihood of propagation along the dependencies in the underlying model. Using this approach we can identify which threats have the strongest impact on business security objectives and how various security controls might differ with regard to their effect in reducing these threats.
Index Terms:
Information Security, Risk Management
Citation:
Ruth Breu, Frank Innerhofer-Oberperfler, Artsiom Yautsiukhin, "Quantitative Assessment of Enterprise Security System," ares, pp.921-928, 2008 Third International Conference on Availability, Reliability and Security, 2008
Usage of this product signifies your acceptance of the Terms of Use.