How Secure is Our Information Infrastructure?

Managers of critical information infrastructures need better tools for managing risk than the qualitative or compliance-based metrics commonly used today in critical infrastructure protection. This paper provides a performance-based metric that can be used to obtain a quantitative measure of the sec...

Ausführliche Beschreibung

Bibliographische Detailangaben
Veröffentlicht in:Journal of Information Warfare. - Peregrine Technical Solutions. - 15(2016), 3, Seite 24-34
1. Verfasser: Ryan, JJCH (VerfasserIn)
Weitere Verfasser: Ryan, DJ
Format: Online-Aufsatz
Sprache:English
Veröffentlicht: 2016
Zugriff auf das übergeordnete Werk:Journal of Information Warfare
Schlagworte:Risk Management Information Security Security and Protection Applied sciences Information science Political science Behavioral sciences Mathematics Economics Social sciences
Beschreibung
Zusammenfassung:Managers of critical information infrastructures need better tools for managing risk than the qualitative or compliance-based metrics commonly used today in critical infrastructure protection. This paper provides a performance-based metric that can be used to obtain a quantitative measure of the security of information infrastructures. The metric can be used to compare the security status of different information infrastructures, or to track the evolution of security within a single infrastructure. Since, as all managers know, ‘If you can’t measure it, you can’t manage it’, the methodology presented here will improve managers’ ability to successfully protect critical information infrastructures.
ISSN:14453347