ACM Home Page
Please provide us with feedback. Feedback
Managing vulnerabilities of information systems to security incidents
Full text PdfPdf (219 KB)
Source ACM International Conference Proceeding Series; Vol. 50 archive
Proceedings of the 5th international conference on Electronic commerce table of contents
Pittsburgh, Pennsylvania
Pages: 348 - 354  
Year of Publication: 2003
ISBN:1-58113-788-5
Authors
Fariborz Farahmand  College of Computing, Georgia Institute of Technology
Shamkant B. Navathe  College of Computing, Georgia Institute of Technology
Philip H. Enslow  School of Industrial & Systems Engineering Georgia Institute of Technology
Gunter P. Sharp  College of Computing, Georgia Institute of Technology
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 19,   Downloads (12 Months): 528,   Citation Count: 1
Additional Information:

abstract   references   cited by   collaborative colleagues   peer to peer  

Tools and Actions: Review this Article  
Save this Article to a Binder    Display Formats: BibTex  EndNote ACM Ref   
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/948005.948050
What is a DOI?

ABSTRACT

Information security-conscious managers of organizations have the responsibility to advise their senior management of the level of risks faced by the information systems. This requires managers to conduct vulnerability assessment as the first step of a risk analysis approach. However, a lack of real world data classification of security threats and develops a three-axis view of the threat space. It develops a scheme for probabilistic evaluation of impact of the security threats and proposes a risk management system consisting of a five-step approach. The goal is to assess the expected damages due to attacks, and managing the risk of attacks.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
British Security Standard, BS 7799, British Standards, 1999.
 
2
Farahmand, F., and Navathe, S. B., Enslow, P. H., Electronic Commerce and Security -- a Management Perspective, ISS/INFORMS Seventh Annual Conference on Information Systems and Technology, San Jose, 2002, http://www.sba.uconn.edu/OPIM/CIST/
 
3
Farahmand, F., and Navathe, S. B., A Risk Management Model to Support Investment Decisions on Security of Database and Information Systems, Working paper, Database Research Group, College of Computing, Georgia Institute of Technology, Atlanta, GA, 2003.
4
 
5
Hoffman, L. J., "Inexact Risk Analysis", Proceedings of the IEEE 1980 International Conference on Cybernetics and Society, Boston, Mass., October 1980.
 
6
ISO, Information Processing Systems-Open Systems Interconnection-Basic Reference Model, Part 2: Security Architecture, ISO 7498-2, 1989.
 
7
Pate-Cornell, E., and Guikema, S., Probabilistic Modeling of Terrorist Attacks: A System Analysis Approach to Setting Priorities Among Countermeasures, Military Operation Research, October 2002.
 
8
Schmucker, Kurt. Fuzzy Sets, Natural Language Computations, and Risk Analysis, Computer Science Press, 1983.
 
9
Stonebumer, G., Goguen, A., and Feringa, A., Risk Management Guide for Information Technology Systems, NIST Special Publications 800-30, 2001.
 
10
 
11
Swanson, M. et al, Security Metrics Guide for Information Technology Systems, NIST Special Publications 800-55, 2002.
 
12
Tarr, C. J., Cost effective perimeter security, Security and Detection, European Convention on Security and Detection, 1995, pp. 183--187.
 
13

Collaborative Colleagues:
Fariborz Farahmand: colleagues
Shamkant B. Navathe: colleagues
Philip H. Enslow: colleagues
Gunter P. Sharp: colleagues

Peer to Peer - Readers of this Article have also read: