Assessing Damages of Information Security Incidents and Selecting Control Measures, a Case Study Approach.

Fariborz Farahmand, Shamkant B. Navathe, Gunter P. Sharp, Philip H. Enslow · WEIS · 2005

Information security executives have always been faced with the problem of justifying security technology investments because the technology benefits are difficult to estimate. There are tangible and intangible benefits that accrue from implementation of security measures; similarly the losses due to security incidents fall into both of these categories. This further complicates estimation. Currently a formal approach to assess damages to information security systems does not exist, neither does a model to select control measures. This paper provides a real world study of the threats to information systems, their damages, and maps some control measures to the threats that can cause these damages.

Read the paper · More papers on PaperTik