A formal approach for secured risk analysis in information security management
Kengo Zenitani · 2022
Information security management is a managerial activity that tries to keep the level of the information security risk of an enterprise under some acceptable level. The process requires the iteration of information security risk assessment and the resources needed for the effort. At the same time, business executives compete for finite resources to invest in general business activities. The executives can intentionally reduce the resource assignment for risk assessment to broaden the variance of estimated risks and then choose the lower limit to underestimate the true risks. This study proposes a model-based risk assessment approach; it guarantees that an additional, thus expected to be costly, fine-grained risk assessment always gives a refined subset of the possible incidents compared to that of the relatively coarse-grained, thus expected to be cheaper, risk assessment. In other words, estimated incidents roughly decrease with the growth of assessment cost. We expect this property to secure the risk management process from conflicts between the business executives and the security practitioners. We refer to several actual incidents to show that the conflict is the reality and then elaborate on our approach to show how it works. Our approach introduces the concept named aggregation and segregation of facts appearing in Datalog programs. Datalog is a logic programming language used for attack graph analysis, a prominent approach in model-based network security risk analysis. This study contributes to expanding the attack graph analysis to enable secured business risk assessment.