Back to Search Start Over

Optimizing Information Systems Security Design Based on Existing Security Knowledge

Authors :
Andreas Schilling
Brigitte Werners
Source :
Lecture Notes in Business Information Processing ISBN: 9783319192420, CAiSE Workshops
Publication Year :
2015
Publisher :
Springer International Publishing, 2015.

Abstract

Information systems and the information enclosed are of significant value and it is indispensable for organizations to ensure their protection. To achieve high security, existing knowledge is available and provides recommendations and guidelines to follow. Due to the large amount of data and the complex dependencies within their structure, it is often challenging to make informed design decisions. This paper proposes a quantitative model that is tailored to the optimal selection of security safeguards from an existing security knowledge base. The input data are extracted from the extensive IT baseline protection catalogues of the German Federal Office for Information Security (BSI). The total amount of data include more than 500 threats and 1200 safeguard options. In an application example, we illustrate that an optimal decision can reduce the number of required safeguards substantially while still maintaining a high security level.

Details

ISBN :
978-3-319-19242-0
ISBNs :
9783319192420
Database :
OpenAIRE
Journal :
Lecture Notes in Business Information Processing ISBN: 9783319192420, CAiSE Workshops
Accession number :
edsair.doi...........b52b1395f88e2e8c12cf038e90137132
Full Text :
https://doi.org/10.1007/978-3-319-19243-7_41