Optimizing information systems security design based on existing security knowledge

3Citations
Citations of this article
10Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

Information systems and the information enclosed are of significant value and it is indispensable for organizations to ensure their protection. To achieve high security, existing knowledge is available and provides recommendations and guidelines to follow. Due to the large amount of data and the complex dependencies within their structure, it is often challenging to make informed design decisions. This paper proposes a quantitative model that is tailored to the optimal selection of security safeguards from an existing security knowledge base. The input data are extracted from the extensive IT baseline protection catalogues of the German Federal Office for Information Security (BSI). The total amount of data include more than 500 threats and 1200 safeguard options. In an application example, we illustrate that an optimal decision can reduce the number of required safeguards substantially while still maintaining a high security level.

Cite

CITATION STYLE

APA

Schilling, A., & Werners, B. (2015). Optimizing information systems security design based on existing security knowledge. In Lecture Notes in Business Information Processing (Vol. 215, pp. 447–458). Springer Verlag. https://doi.org/10.1007/978-3-319-19243-7_41

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free