A framework for making decision on optimal security investment to the proactive and reactive security solutions management

YH Choi - Journal of Internet Computing and Services, 2014 - koreascience.kr
Journal of Internet Computing and Services, 2014koreascience.kr
While IT security investment of organizations has been increased, the amount of the
monetary loss of organizations caused by IT security breaches did not decrease as much as
their expectation. Also, from surveys, it was discovered that the poor usage of their security
budget thwarted the improvement of the organization's security level. In this paper, to resolve
the poor usage of security budget of organizations, we propose a comprehensive economic
model for determining the optimal amount of investment in security solutions, including the …
Abstract
While IT security investment of organizations has been increased, the amount of the monetary loss of organizations caused by IT security breaches did not decrease as much as their expectation. Also, from surveys, it was discovered that the poor usage of their security budget thwarted the improvement of the organization's security level. In this paper, to resolve the poor usage of security budget of organizations, we propose a comprehensive economic model for determining the optimal amount of investment in security solutions, including the proactive security solutions (PSSs) and the reactive security solutions (RSSs). Using the proposed analytical model under different parameters of security solutions, we show the optimal condition to maximize the expected net benefits from IT security investment of organizations. Also, we verify the common belief that the optimal level of investment in security solutions is an increasing function of vulnerability. Through simulations, we find the optimal level of IT security investment, given parameters of different characteristics of security solutions.
koreascience.kr
以上显示的是最相近的搜索结果。 查看全部搜索结果