Direkt zum Inhalt

Weishäupl, Eva

Towards a Multi-objective Optimization Model to Support Information Security Investment Decision-making

Weishäupl, Eva (2017) Towards a Multi-objective Optimization Model to Support Information Security Investment Decision-making. In: SHCIS’17, June 21-22, 2017, Neuchâtel, Switzerland.

Veröffentlichungsdatum dieses Volltextes: 20 Jun 2017 06:23
Konferenz- oder Workshop-Beitrag
DOI zum Zitieren dieses Dokuments: 10.5283/epub.35751


Zusammenfassung

The protection of assets, including IT resources, intellectual property and business processes, against security attacks has become a challenging task for organizations. From an economic perspective, firms need to minimize the probability of a successful security incident or attack while staying within the boundaries of their information security budget in order to optimize their investment ...

The protection of assets, including IT resources, intellectual property and business processes, against security attacks has become a challenging task for organizations. From an economic perspective, firms need to minimize the probability of a successful security incident or attack while staying within the boundaries of their information security budget in order to optimize their investment strategy. In this paper, an optimization model to support information security investment decision-making in organizations is proposed considering the two convicting objectives (simultaneously minimizing the costs of countermeasures while maximizing the security level). Decision models that support the firms’ decisions considering the trade-off between the security level and the investment allocation are beneficial for organizations to facilitate and justify security investment choices.



Beteiligte Einrichtungen


Details

DokumentenartKonferenz- oder Workshop-Beitrag (Paper)
Datum21 Juni 2017
InstitutionenWirtschaftswissenschaften > Institut für Wirtschaftsinformatik > Entpflichtete oder im Ruhestand befindliche Professoren > Professur für Wirtschaftsinformatik (Prof. Dr. Guido Schryen)
Identifikationsnummer
WertTyp
10.1145/3099012.3099013DOI
Stichwörter / KeywordsInformation security investment, decision-making, multi-objective optimization
Dewey-Dezimal-Klassifikation000 Informatik, Informationswissenschaft, allgemeine Werke > 004 Informatik
StatusVeröffentlicht
BegutachtetJa, diese Version wurde begutachtet
An der Universität Regensburg entstandenJa
URN der UB Regensburgurn:nbn:de:bvb:355-epub-357514
Dokumenten-ID35751

Bibliographische Daten exportieren

Nur für Besitzer und Autoren: Kontrollseite des Eintrags

nach oben