A Decision Support System for Optimal Selection of Enterprise Information Security Preventative Actions
Autor: | Ferda Özdemir Sönmez, Banu Günel Kiliç |
---|---|
Rok vydání: | 2021 |
Předmět: |
Decision support system
Computer Networks and Communications business.industry Process (engineering) Computer science Information security Information visualization Risk analysis (engineering) Threat model Security management Electrical and Electronic Engineering business Risk management Budget constraint |
Zdroj: | IEEE Transactions on Network and Service Management. 18:3260-3279 |
ISSN: | 2373-7379 |
DOI: | 10.1109/tnsm.2020.3044865 |
Popis: | Types and complexity of information security related vulnerabilities are growing rapidly and present numerous challenges to the enterprises. One of the key challenges is to identify the optimal set of precautions with limited budget. Despite the fact that majority of enterprises have a budget constraint for installing and maintaining the protection systems, the majority of the previous work only focus on prioritization of security targets and do not consider the preventative actions and budget constraints. This article presents a decision support system (DSS) based on analytical hierarchical process and mixed integer programming techniques for optimal selection of enterprise information security preventative actions. The proposed approach enables maximizing the amount of risk prevented for a fixed amount of budget by identifying the optimal set of precautions. The new DSS also assists enterprise decision-makers in determining the minimum enterprise information security budget for a given level of risk. The main contribution of the paper is that it provides a risk management method to identify a multi-level threat model and the corresponding optimal combination of preventative actions for an enterprise while considering the budget constraints. The treemap information visualization technique is also integrated into the proposed method to improve information security related management decisions. |
Databáze: | OpenAIRE |
Externí odkaz: |