Security Tailored to the Needs of Business

Fariborz Farahmand, Jonathan William, B Shamkant, H Philip · 2003

Electronic commerce and Internet have enabled businesses to reduce costs, attain greater market reach, and develop closer partner and customer relationships. However, using the Internet has led to new risks and concerns. This paper enables managers to have a better understanding of the security needs of their businesses. We summarize the state of art of the security issues of information technology, the challenges for businesses, and the current process of deploying resources by companies to face these challenges by drawing from the substantial industrial experience of one of the authors. We describe the nature of the threats to information systems and reasons for variability of losses resulting from similar exploitation. This paper also presents a model for threat classification and control measures, and a statistical overview of information security incidents. The conclusion of our empirical analysis of the existing available literature is that the highest amount of damage in terms of the financial/market evaluation of companies is caused by the violation of confidentiality of data. Problems such as intrusion when confidentiality of data is not compromised typically only result in direct damage such as denial service which is directly quantifiable; but such damage is not comparable to the potential longer term damage of loss or disclosure of confidential information.

Read the paper · More papers on PaperTik