Author List: Kumar, Ram L.; Park, SungJune; Subramaniam, Chandrasekar;
Journal of Management Information Systems, 2008, Volume 25, Issue 2, Page 241-279.
Organizations are faced with a variety of information security threats and implement several information system security countermeasures (ISSCs) to mitigate possible damage due to security attacks. These security countermeasures vary in their ability to deal with different types of security attacks and, hence, are implemented as a portfolio of ISSCs. A key challenge for organizations is to understand the economic consequences of security attacks relative to the ISSC portfolio implemented. This paper combines the risk analysis and disaster recovery perspectives to build an integrated simulation model of ISSC portfolio value. The model incorporates the characteristics of an ISSC portfolio relative to the threat and business environments and includes the type of attack, frequency of attacks, possible damage, and the extent and time of recovery from damage. The simulation experiments provide interesting insights into the interactions between ISSC portfolio components and characteristics of business and threat environments in determining portfolio value.
Keywords: business value of IT; economics of IS security; information systems security; IT asset valuation
Algorithm:

List of Topics

#73 0.330 security threat information users detection coping configuration avoidance response firm malicious attack intrusion appraisal countermeasures benefit costs threats ability rate
#223 0.146 insurance companies growth portfolios intensity company life portfolio industry newly vulnerable terms composition operating implemented factors asset focus disaggregation choices
#143 0.103 value business benefits technology based economic creation related intangible cocreation assessing financial improved key economics assess question created create understanding
#97 0.087 set approach algorithm optimal used develop results use simulation experiments algorithms demonstrate proposed optimization present analytical distribution selection number existing
#0 0.056 information types different type sources analysis develop used behavior specific conditions consider improve using alternative understanding data available main target
#225 0.052 information environment provide analysis paper overall better relationships outcomes increasingly useful valuable available increasing greater regarding levels decisions viewed relative