Cost Tradeoffs for Information Security Assurance.
Ritesh Kumar Tiwari, Kamalakar Karlapalem · WEIS · 2005
Information security is important in proportion to an organization’s dependence on information technology. Security of a computer based information system should protect the Confidentiality, Integrity and Availability (CIA) aspects of the system. With the increasing dependence of business processes on information technology, the number of attacks against CIA aspects have increased manifold. Since achieving perfect security is monetarily and practically infeasible, organizations are using risk management concepts to forego perfection and instead making tradeoffs in pursuit of security goals. In this paper, we focus to analyze such tradeoffs in terms of investment costs and opportunity cost (from perspective of defender and attacker respectively).