Security risk analysis should be conducted regularly to maintain an acceptable level of security. In principle, all risks that are unacceptable according to the predefined criteria should be mitigated. However, risk mitigation comes at a cost, and only the countermeasures that cost-efficiently mitigate risks should be implemented. This paper presents an approach to integrate the countermeasure cost-benefit assessment into the risk analysis and to provide decision makers with the necessary decision support. The approach comes with the necessary modeling support, a calculus for reasoning about the countermeasure cost and effect, as well as means for visualization of the results to aid decision makers. © 2013 IFIP International Federation for Information Processing.
CITATION STYLE
Tran, L. M. S., Solhaug, B., & Stølen, K. (2013). An approach to select cost-effective risk countermeasures. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 7964 LNCS, pp. 266–273). https://doi.org/10.1007/978-3-642-39256-6_18
Mendeley helps you to discover research relevant for your work.