A Dynamic Risk Model for Information Technology Security in a Critical Infrastructure Environment

John H. Saunders · 2003

The risk assessment, modeling, and simulation of critical infrastructure information technology (IT) security has been limited to broad, macro-level approaches. Concurrently, risk assessment in IT security has been limited to static analysis and modeling. This paper provides a dynamic risk framework and a model that synthesizes elements of an organizational decision model on both macro and micro levels. In the proposed dynamic model the focus is upon building the reactive capability of an infrastructure organization as well as preparing for time-based cascading effects.

Read the paper · More papers on PaperTik