ACM Home Page
Please provide us with feedback. Feedback
The future of systematic information protection
Full text PdfPdf (89 KB)
Source Symposium on Applied Computing archive
Proceedings of the 2005 ACM symposium on Applied computing table of contents
Santa Fe, New Mexico
SESSION: Keynote address table of contents
Pages: 1 - 1  
Year of Publication: 2005
ISBN:1-58113-964-0
Author
Bob Hutchinson  Sandia National Laboratory Albuquerque, NM
Sponsor
SIGAPP: ACM Special Interest Group on Applied Computing
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 5,   Downloads (12 Months): 29,   Citation Count: 0
Additional Information:

abstract  

Tools and Actions: Review this Article  
Save this Article to a Binder    Display Formats: BibTex  EndNote ACM Ref   
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1066677.1066679
What is a DOI?

ABSTRACT

Information plays a critical role in global economics as well as our security, safety, and quality of life. There is a growing disparity between the value of information and our capability to manage and protect it. Technical and policy research is needed to address this disparity. Fundamentally, we can not answer the following question, "how much security is enough?" We lack the capability to quantify the value of information, particularly information that has been processed and aggregated. We also face many difficulties when attempting to measure information security, characterize threats, understand vulnerabilities, or even formulate and sustain any specific security posture. As a result, we can not measure our risk and therefore can not manage it. Our efforts to address this problem can be divided into two categories, legal/policy and technical. Owners of physical assets, such as cash or gold, have the legal and technical means to augment fortification protections with armed guards and lethal force. From a legal perspective, protection of information is limited to fortification, in part because we lack sufficient attribution. From a technical perspective, we have built complex mountains of computer code on top of hardware architectures that will attempt to execute any arbitrary instructions. These systems cannot be effectively analyzed for vulnerabilities so as to ensure trustworthy and secure operation. Research is needed to address the systematic protection of information including information valuation, security metrics, strong attribution, trustworthy computing, sustainable security processes, and legal devices that will support comprehensive protection and risk management.