A System Dynamics Model of Information Security Investments
نویسندگان
چکیده
Information security management has become an increasingly serious and high-stake challenge to organizations, due to growing reliance on the Internet as the business platform, the intrinsic vulnerability of Internet technologies, and the increasing value of information stored in information systems. Because of the complex nature and the large number of closely coupled variables associated with information security problems, sophisticated analytical tools are needed to help decision makers to address the management of information security with limited resources. In this paper, we adopt the system dynamics approach to security analysis, with the help of an information security life cycle model. By identifying the causal loop among such variables as the attractiveness of information target and the total number of attacks, we develop a system dynamics model for analyzing the effect of organizational security investments in the attack stage of the information security life cycle. Using this model, we simulate a number of security management scenarios and demonstrate the feasibility and validity of the system dynamics approach. The model presented in this paper is adaptive, and its parameters and relationships can be calibrated with empirical data for further refinement and customization for specific situations in real world organizations.
منابع مشابه
The effect of developing the dynamics of library software system on information security management (Case study: Libraries of Islamic Azad universities of the country)
Background and Objective: Information security is of vital importance in most organizations. This is especially central in academic libraries due to the specific type of visitors, exchange and transfer of information to the users. Thus, the purpose is to investigate the relationship of the development of library software and information security management in the libraries of Islamic Azad Uni...
متن کاملاز پیاده سازی معماری سرویس گرا تا چابکی سازمان با رویکرد مدلسازی پویایی سیستم
SOA is type of architecture that used service to simplify integration activities and use the components for reusable. Companies to survive in the dynamic environment needed to strengthen their organizations through information systems and service-oriented architecture is a way for the integration and effectiveness of the use of information systems and achieve organizational agility. In this pap...
متن کاملBuilding a Dynamic Manpower Planning Model: Focused on the Information Security Manpower Policy of Korea
The ability to forecast manpower requirements is crucial for an industry. On the demand side, companies rely on these forecasts to formulate their manpower planning strategies, while, on the supply side, they provide job seekers with a basis to assess the attractiveness of a given sector. Forecasts of supply and demand for manpower also make an important contribution to the governmental policy-...
متن کاملEconomic Aspects of Controlling Capital Investments in Cyberspace Security for Critical Infrastructure Assets
A model is developed which demonstrates that control systems for investments in information security have a positive net economic impact on an organization. This positive effect is an increasing function of the degree of asymmetric information (related to moral hazard and adverse selection) between Chief Security Officers and Chief Financial Officers within an organization. The role of external...
متن کاملA System Dynamics Model for Joint Upstream and Downstream Partner Selection in a Supply Chain Consisting of Suppliers and Retailers
Firms no longer compete as autonomous entities and prefer to join in a supply chain alliance to take advantage of highly competitive business situation. Supply chain coordination has a great impact on strategic partnering and success of a firm in competitive business environment. In this paper, we propose a system dynamics simulation model for strategic partner selection in supply chain. Our mo...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2007