Zur Kurzanzeige

dc.contributor.authorWeiß, Steffen
dc.contributor.authorMeyer-Wegener, Klaus
dc.contributor.editorAlkassar, Ammar
dc.contributor.editorSiekmann, Jörg
dc.date.accessioned2019-04-03T13:29:13Z
dc.date.available2019-04-03T13:29:13Z
dc.date.issued2008
dc.identifier.isbn978-3-88579-222-2
dc.identifier.issn1617-5468
dc.identifier.urihttp://dl.gi.de/handle/20.500.12116/21498
dc.description.abstractAwareness of security has risen during the last years. As a result, the question of adequate protection against security risks increased, too. Management wants to decide whether and how to invest in this protection. As a result, quantitative statements about information-security risks are needed. Existing approaches in this domain either rely on guessed data or do not answer the question in a quantitative way. We think that this is due to the fact that no approach separates information that can be provided by a central organization (e.g. known attacks, available controls, and a control’s probability of protection) from information which must be provided individually (e.g. the controls installed). We have developed an approach that employs this separation and allows quantitative assessment of security with the help of a model. This model is presented here with a special look at the separation.en
dc.language.isoen
dc.publisherGesellschaft für Informatik e. V.
dc.relation.ispartofSICHERHEIT 2008 – Sicherheit, Schutz und Zuverlässigkeit. Beiträge der 4. Jahrestagung des Fachbereichs Sicherheit der Gesellschaft für Informatik e.V. (GI)
dc.relation.ispartofseriesLecture Notes in Informatics (LNI) - Proceedings, Volume P-128
dc.titleTowards solving the data problem in measurement of organizations’ securityen
dc.typeText/Conference Paper
dc.pubPlaceBonn
mci.reference.pages461-472
mci.conference.sessiontitleRegular Research Papers
mci.conference.locationSaarbrücken
mci.conference.date2.- 4. April 2008


Dateien zu dieser Ressource

Thumbnail

Zur Kurzanzeige