A Simulation Model of Information Systems Security

Norman Pendegraft, Mark Rounds · International Journal of Information Security and Privacy · 2007

The value of IS security is evaluated by simulating interactions between an information system, its users, and a population of attackers. Results suggest that the marginal value of additional security may be positive or negative as can the time rate of change of system value. This implies that IT security policy makers should be aware of where they are in the state space before setting IT security policy.

Read the paper · More papers on PaperTik