How Much Should We Pay for Security? (Invited Paper)

Information systems security has become a top priority issue for most organizations worldwide IT managers try to protect their systems through a series of technical security measures. Even though these measures can be determined through risk analysis, the appropriate amount that should be invested i...

Full description

Saved in:
Bibliographic Details
Published inSecurity Management, Integrity, and Internal Control in Information Systems pp. 59 - 69
Main Authors Katsikas, Sokratis K., Yannacopoulos, Athanasios N., Gritzalis, Stefanos, Lambrinoudakis, Costas, Hatzopoulos, Peter
Format Book Chapter
LanguageEnglish
Published Boston, MA Springer US
SeriesIFIP International Federation for Information Processing
Subjects
Online AccessGet full text

Cover

Loading…
More Information
Summary:Information systems security has become a top priority issue for most organizations worldwide IT managers try to protect their systems through a series of technical security measures. Even though these measures can be determined through risk analysis, the appropriate amount that should be invested in Information Systems security is, by and large, determined empirically. Organizations would also wish to insure their information systems against potential security incidents. In this case both parties, namely the organization and the insurance company would be interested in calculating a fair, mutually beneficial premium. In this paper a probabilistic structure, in the form of a Markov model, is used to provide some insight into these issues.
ISBN:0387298266
9780387298269
ISSN:1571-5736
DOI:10.1007/0-387-31167-X_4