Abstract
In earlier work, we presented a value based measure of cybersecurity that quantifies the security of a system in concrete terms, specifically, in terms of how much each system stakeholder stands to lose (in dollars per hour of operation) as a result of security threats and system vulnerabilities; our metric varies according to the stakes that each stakeholder has in meeting each security requirement. In this paper, we discuss the specification and design of a system that collects, updates, and maintains all the information that pertains to estimating our cybersecurity measure, and offers stakeholders quantitative means to make security-related decisions. © 2011 Springer-Verlag.
Author supplied keywords
Cite
CITATION STYLE
Aissa, A. B., Abercrombie, R. K., Sheldon, F. T., & Mili, A. (2012). Defining and computing a value based cyber-security measure. Information Systems and E-Business Management, 10(4), 433–453. https://doi.org/10.1007/s10257-011-0177-1
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.