Skip to main content
SHARE
Publication

Methodology for Evaluating Security Controls Based on Key Performance Indicators and Stakeholder Mission...

by Frederick T Sheldon, Robert K Abercrombie, Ali Mili
Publication Type
Conference Paper
Book Title
Proceedings of the 42nd Annual Hawaii International Conference on System Sciences
Publication Date
Page Numbers
1 to 10
Volume
0
Publisher Location
Los Alamitos, California, United States of America
Conference Name
42nd Annual Hawaii International Conference on System Sciences (HICSS-42)
Conference Location
Waikoloa, Hawaii, United States of America
Conference Sponsor
IEEE Computer Society, Unviersity of Hawaii at Manoa
Conference Date
-

Information security continues to evolve in response to disruptive changes with a persistent focus on information-centric controls and a healthy debate about balancing endpoint and network protection, with a goal of improved enterprise/business risk management. Economic uncertainty, intensively collaborative styles of work, virtualization, increased outsourcing and ongoing compliance pressures require careful consideration and adaptation. This paper proposes a Cyberspace Security Econometrics System (CSES) that provides a measure (i.e., a quantitative indication) of reliability, performance and/or safety of a system that accounts for the criticality of each requirement as a function of one or more stakeholders� interests in that requirement. For a given stakeholder, CSES reflects the variance that may exist among the stakes she/he attaches to meeting each requirement. This paper introduces the basis, objectives and capabilities for the CSES including inputs/outputs as well as the structural and mathematical underpinnings.