Quantifying information security risks using expert judgment elicitation

Quantifying information security risks using expert judgment elicitation

0.00 Avg rating0 Votes
Article ID: iaor20118140
Volume: 39
Issue: 4
Start Page Number: 774
End Page Number: 784
Publication Date: Apr 2012
Journal: Computers and Operations Research
Authors: , , , ,
Keywords: risk, simulation: applications, information
Abstract:

In the information security business, 30 years of practical and theoretical research has resulted in a fairly sophisticated appreciation for how to judge the qualitative level of risk faced by an enterprise. Based upon that understanding, there is a practical level of protection that a competent security manager can architect for a given enterprise. It would, of course, be better to use a quantitative approach to risk management, but, unfortunately, sufficient quantitative data that has been scientifically collected and analyzed does not exist. There have been many attempts to develop quantitative data using traditional quantitative methods, such as experiments, surveys, and observations, but there are significant weaknesses apparent in each approach. The research described in this paper was constructed to explore the utility of applying the well‐established method of expert judgment elicitation to the field of information security. The instrument for eliciting the expert judgments was developed by two information security specialists and two expert judgment analysis specialists. The resultant instrument was validated using a small set of information security experts. The final instrument was used to elicit answers to both the calibration and judgment questions through structured interviews. The data was compiled and analyzed by a specialist in expert judgment analysis. This research illustrates the development of prior distributions for the parameters of models for cyber attacks and uses expert judgment results to develop the distributions.

Reviews

Required fields are marked *. Your email address will not be published.