A Study on Information Security Situation Modelling

Ashish Kr. Srivastava, Pallavi Shrivastava · 2018

With the advent of digitization and new technologies, organizational information security has become a major concern. As information elements are spreading across the world, there comes the threat to security of information. Enterprises are investing pretty good amount in taking various measures for securing their information. The most important step for securing the information is about knowing current situation of information security of organization. Knowing situation requires some kind of evaluation method. The evaluation of security situation is currently the qualitative analysis. The aim of the evaluation is to help the decision maker to percept the security situation quickly and correctly. In this paper, it is attempted to put this measurement and prediction of security (or evaluation of security) quantitatively. This quantitative method of evaluation of situation has few advantages over qualitative method. First advantage is transparency, less human intervention., possibility of benchmarking and second is possibility of computer automation of measurement method. Quantitative model of information security situation (QMISS) is described in section-2 of paper. This model is based on much known tenets of information security. This QMISS model further can be used for predicting and computing current value of security situation (VSS). QMISS has several components. Out of these components., in this paper., prediction part is done only for one component that is information security incidents (lSI).ISI can be thought most important parameter while evaluating organizational security situation. Neural network is used while establishing prediction mechanism for parameter ISI., described in section 3. Thus in this paper., mainly two work is done. First quantitative model for security situation QMISS is proposed and second Neural Net (NN) based prediction mechanism is described for information security incidents (ISI). With above predicted number of ISIs and knowledge of other parameter of QMISS., VSS can be computed. With VSS., one can benchmark one's organization's security situation. On this basis., security-head can take suitable actions on improvement of VSS of her organization.

Read the paper · More papers on PaperTik