4.7 Article

Quantitatively assessing the vulnerability of critical information systems: A new method for evaluating security enhancements

Journal

INTERNATIONAL JOURNAL OF INFORMATION MANAGEMENT
Volume 28, Issue 6, Pages 483-491

Publisher

ELSEVIER SCI LTD
DOI: 10.1016/j.ijinfomgt.2008.01.009

Keywords

Information security; Risk analysis; Information-security measurement; Security threats; Vulnerability measurement

Ask authors/readers for more resources

This paper proposes a new approach for assessing the organization's vulnerability to information-security breaches. Although Much research has been done on qualitative approaches, the literature on numerical approaches to quantify information-security risk is scarce. This paper Suggests a method to quantify risk in terms of a numeric value or degree of cybersecurity. To help quantitatively measure the level of cybersecurity for a computer-based information system. we present two indices, the threat-impact index and the cyber-vulnerability index, based on vulnerability trees. By calculating and comparing the indices for various possible security enhancements, managers can select the best security enhancement choice, prioritize the choices by their relative effectiveness, and statistically justify spending resources on the selected choice. By qualifying information security quantitatively, the method can also help managers establish a specific target of security level that they can track. We illustrate the use of the proposed methodology on the security of supervisory control and data acquisition (SCADA) systems using data from the SCADA system test bed implemented at the University of Louisville as a case study, and then show the use of the proposed indices on this information system before and after two security enhancements. (C) 2008 Elsevier Ltd. All rights reserved.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

4.7
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available