Principles for Better Information Security through More Accurate, Transparent Risk Scoring
-
Kenneth G Crowther
This paper explores approaches for scoring information security risk that could lead to investment drivers and drive appropriate levels of security. Our approach is grounded on two important factors that determine cyber risk: (1) the information security resources (e.g., technologies, skills, and policies) that reduce the likelihood and consequences of successful information exploits; and (2) the security processes and capabilities that drive a continuous improvement of the security resources in use. The quality of a cyber defense system is the result of the integration of these two factors. This manuscript proposes such a two-factor hierarchical system of scoring, details candidate measures, and explores economic conditions for selecting appropriate measures. We review several scoring systems available that contain elements from this proposed system and discuss conditions for market adoption of information security scoring.
©2011 Walter de Gruyter GmbH & Co. KG, Berlin/Boston
Artikel in diesem Heft
- Book Review
- Review of Building an Enterprise-Wide Business Continuity Program
- Review of Filling the Ark: Animal Welfare in Disasters
- Review of Anti-Americanism and the American World Order
- Review of Homeland Security: Assessing the First Five Years
- Review of Disaster Management: Global Challenges and Local Solutions
- Review of Who's In Charge?: Leadership during Epidemics, Bioterror Attacks, and Other Public Health Crises
- Review of Managing Security Overseas: Protecting Employees and Assets in Volatile Regions
- Review of Floodplain Management: A New Approach for a New Era
- Review of The Law of Emergencies: Public Health and Disaster Management
- Review of Terrorism, the Worker and the City: Simulations and Security in a Time of Terror
- Review of Social Science for Counterterrorism: Putting the Pieces Together
- Review of High Tech Terror: Recognition, Management and Prevention of Biological, Chemical, and Nuclear Injuries Secondary to Acts of Terrorism
- Review of Debating Terrorism and Counterterrorism: Conflicting Perspectives on Causes, Contexts, and Responses
- Review of A Paradise Built in Hell: The Extraordinary Communities That Arise in Disaster
- Review of Women, Gender and Disaster: Global Issues and Initiatives
- Review of Safeguarding Homeland Security: Governors and Mayors Speak Out
- Review of Disasters and Public Health: Planning and Response
- Review of Terrorism, Risk and the Global City: Towards Urban Resilience
- Review of The New Global Insecurity: How Terrorism, Environmental Collapse, Economic Inequalities and Resource Shortages Are Changing Our World
- Review of Willful Neglect: The Dangerous Illusion of Homeland Security
- Review of The Political Economy of Hazards and Disasters
- Review of Is America Safe? Terrorism, Homeland Security, and Emergency Preparedness
- Review of Catastrophe: Law, Politics, and the Humanitarian Impulse
- Review of Rebecca Gilman's Play A True History of the Johnstown Flood: A Back to the Future View of Environmental Disasters
- Review of Emergency Response to Domestic Terrorism: How Bureaucracies Reacted to the 1995 Oklahoma City Bombing
- Review of The Disaster Game
- Review of Risk Analysis and Security Countermeasure Selection
- Review of The Economics of Climate Change Policy: International, National and Regional Mitigation Strategies
- Review of Unfunding Terror: The Legal Response to the Financing of Global Terrorism
- Review of Would-Be Warriors: Incidents of Jihadist Terrorist Radicalization in the United States Since September 11, 2001
- Review of Clear as Mud: Planning for the Rebuilding of New Orleans
- Review of Building Safer Communities, Risk Governance, Spatial Planning and Responses to Natural Hazards
- Review of Catastrophic Disaster Planning and Response
- Review of Terrorism, Security and the Power of Informal Networks
- Research Article
- Liability in Search and Rescues: Should Individuals who Necessitate Their Own Rescues Have to Pay?
- Adaptation and Application of Federal Capabilities-Based Planning Models to Individual States: State of Colorado Case Study
- Does Federal Assistance to Health Departments for Bioterrorism Preparedness Improve Local Public Health Activity? An Empirical Evaluation Using the 2005 NACCHO Profile of Local Health Departments
- Public Health Components of Academic Programs in Homeland Security
- Valuing the Risk of Death from Terrorist Attacks
- Hospital Group Preparation for the 2008 Democratic National Convention
- Leaving Deterrence Behind: War-Fighting and National Cybersecurity
- A Survey of County Emergency Managers' Response to Ice Storms
- Critical Infrastructure Protection Systems Effectiveness Evaluation
- A New Generation of National Security Strategies: Early Findings from the Netherlands and the United Kingdom
- Principles for Better Information Security through More Accurate, Transparent Risk Scoring
- Collaborative Relationships Resulting from the Urban Area Security Initiative
- A Study of First Moments in Underground Mine Emergency Response
- Enhancing Disaster Recovery: Lessons from Exemplary International Disaster Management Practices
- An Analysis of Texas Sheriffs' Opinions Concerning Domestic Terrorism: Training, Equipment, Funding and Perceptions Regarding Likelihood of Attack
- Policing and Community Relations in the Homeland Security Era
- Interorganizational Network Coordination under Stress Caused by Repeated Threats of Disasters
- Wet and Dry Tsunami Warning Systems: Lessons from High Reliability Organizations
- The Influence of Collaborative Partnerships on Private Sector Preparedness and Continuity Planning
- Crisis Preparedness Capabilities in Health
- Building Mass Fatality Management at the Regional Level for Pandemic and Catastrophic Response
- Disaster Resilience Indicators for Benchmarking Baseline Conditions
- Towards Shared Situational Awareness and Actionable Knowledge - An Enhanced, Human-Centered Paradigm for Public Health Information System Design
- Decision Evaluation of Response Strategies in Emergency Management Using Imprecise Assessments
- Understanding the Dynamics of Emergency Communication: Propositions for a Four-Channel Model
- Politics or Risks? An Analysis of Homeland Security Grant Allocations to the States
- A Review of Nurses in Disaster Preparedness and Response: Military and Civilian Collaboration
- Analysis of Informal Networking in Emergency Management
- Intelligence-Led Mitigation
- An Investigation of Hospital Disaster Preparedness in Turkey
- Live Fire Exercise: Preparing for Cyber War
- Effects on the U.S. of an H1N1 Epidemic: Analysis with a Quarterly CGE Model
- Next Generation 9-1-1: Architecture and Challenges in Realizing an IP-Multimedia-Based Emergency Service
- Enhancing Border Security: Local Values and Preferences at the Blue Water Bridge (Point Edward, Canada)
- Opinion
- The Elephant in the JIC: The Fundamental Flaw of Emergency Public Information within the NIMS Framework
- Resilience as a Goal and Standard in Emergency Management
- Law, Emergencies, and the Constitution: A Review of Outside the Law: Emergency and Executive Power
- Meeting Educational Challenges in Homeland Security and Emergency Management
- When Status Quo Becomes Obsolete: The Changing Use of Outdoor Warning Sirens
- Communication/News
- Domestic Federal Interagency Planning: Meeting a Homeland Security Need
- Health Care Logistics Response in a Disaster
- Preparedness versus Reactiveness: An Approach to Pre-Crisis Disaster Planning
- Comment
- Letter to the Editor
Artikel in diesem Heft
- Book Review
- Review of Building an Enterprise-Wide Business Continuity Program
- Review of Filling the Ark: Animal Welfare in Disasters
- Review of Anti-Americanism and the American World Order
- Review of Homeland Security: Assessing the First Five Years
- Review of Disaster Management: Global Challenges and Local Solutions
- Review of Who's In Charge?: Leadership during Epidemics, Bioterror Attacks, and Other Public Health Crises
- Review of Managing Security Overseas: Protecting Employees and Assets in Volatile Regions
- Review of Floodplain Management: A New Approach for a New Era
- Review of The Law of Emergencies: Public Health and Disaster Management
- Review of Terrorism, the Worker and the City: Simulations and Security in a Time of Terror
- Review of Social Science for Counterterrorism: Putting the Pieces Together
- Review of High Tech Terror: Recognition, Management and Prevention of Biological, Chemical, and Nuclear Injuries Secondary to Acts of Terrorism
- Review of Debating Terrorism and Counterterrorism: Conflicting Perspectives on Causes, Contexts, and Responses
- Review of A Paradise Built in Hell: The Extraordinary Communities That Arise in Disaster
- Review of Women, Gender and Disaster: Global Issues and Initiatives
- Review of Safeguarding Homeland Security: Governors and Mayors Speak Out
- Review of Disasters and Public Health: Planning and Response
- Review of Terrorism, Risk and the Global City: Towards Urban Resilience
- Review of The New Global Insecurity: How Terrorism, Environmental Collapse, Economic Inequalities and Resource Shortages Are Changing Our World
- Review of Willful Neglect: The Dangerous Illusion of Homeland Security
- Review of The Political Economy of Hazards and Disasters
- Review of Is America Safe? Terrorism, Homeland Security, and Emergency Preparedness
- Review of Catastrophe: Law, Politics, and the Humanitarian Impulse
- Review of Rebecca Gilman's Play A True History of the Johnstown Flood: A Back to the Future View of Environmental Disasters
- Review of Emergency Response to Domestic Terrorism: How Bureaucracies Reacted to the 1995 Oklahoma City Bombing
- Review of The Disaster Game
- Review of Risk Analysis and Security Countermeasure Selection
- Review of The Economics of Climate Change Policy: International, National and Regional Mitigation Strategies
- Review of Unfunding Terror: The Legal Response to the Financing of Global Terrorism
- Review of Would-Be Warriors: Incidents of Jihadist Terrorist Radicalization in the United States Since September 11, 2001
- Review of Clear as Mud: Planning for the Rebuilding of New Orleans
- Review of Building Safer Communities, Risk Governance, Spatial Planning and Responses to Natural Hazards
- Review of Catastrophic Disaster Planning and Response
- Review of Terrorism, Security and the Power of Informal Networks
- Research Article
- Liability in Search and Rescues: Should Individuals who Necessitate Their Own Rescues Have to Pay?
- Adaptation and Application of Federal Capabilities-Based Planning Models to Individual States: State of Colorado Case Study
- Does Federal Assistance to Health Departments for Bioterrorism Preparedness Improve Local Public Health Activity? An Empirical Evaluation Using the 2005 NACCHO Profile of Local Health Departments
- Public Health Components of Academic Programs in Homeland Security
- Valuing the Risk of Death from Terrorist Attacks
- Hospital Group Preparation for the 2008 Democratic National Convention
- Leaving Deterrence Behind: War-Fighting and National Cybersecurity
- A Survey of County Emergency Managers' Response to Ice Storms
- Critical Infrastructure Protection Systems Effectiveness Evaluation
- A New Generation of National Security Strategies: Early Findings from the Netherlands and the United Kingdom
- Principles for Better Information Security through More Accurate, Transparent Risk Scoring
- Collaborative Relationships Resulting from the Urban Area Security Initiative
- A Study of First Moments in Underground Mine Emergency Response
- Enhancing Disaster Recovery: Lessons from Exemplary International Disaster Management Practices
- An Analysis of Texas Sheriffs' Opinions Concerning Domestic Terrorism: Training, Equipment, Funding and Perceptions Regarding Likelihood of Attack
- Policing and Community Relations in the Homeland Security Era
- Interorganizational Network Coordination under Stress Caused by Repeated Threats of Disasters
- Wet and Dry Tsunami Warning Systems: Lessons from High Reliability Organizations
- The Influence of Collaborative Partnerships on Private Sector Preparedness and Continuity Planning
- Crisis Preparedness Capabilities in Health
- Building Mass Fatality Management at the Regional Level for Pandemic and Catastrophic Response
- Disaster Resilience Indicators for Benchmarking Baseline Conditions
- Towards Shared Situational Awareness and Actionable Knowledge - An Enhanced, Human-Centered Paradigm for Public Health Information System Design
- Decision Evaluation of Response Strategies in Emergency Management Using Imprecise Assessments
- Understanding the Dynamics of Emergency Communication: Propositions for a Four-Channel Model
- Politics or Risks? An Analysis of Homeland Security Grant Allocations to the States
- A Review of Nurses in Disaster Preparedness and Response: Military and Civilian Collaboration
- Analysis of Informal Networking in Emergency Management
- Intelligence-Led Mitigation
- An Investigation of Hospital Disaster Preparedness in Turkey
- Live Fire Exercise: Preparing for Cyber War
- Effects on the U.S. of an H1N1 Epidemic: Analysis with a Quarterly CGE Model
- Next Generation 9-1-1: Architecture and Challenges in Realizing an IP-Multimedia-Based Emergency Service
- Enhancing Border Security: Local Values and Preferences at the Blue Water Bridge (Point Edward, Canada)
- Opinion
- The Elephant in the JIC: The Fundamental Flaw of Emergency Public Information within the NIMS Framework
- Resilience as a Goal and Standard in Emergency Management
- Law, Emergencies, and the Constitution: A Review of Outside the Law: Emergency and Executive Power
- Meeting Educational Challenges in Homeland Security and Emergency Management
- When Status Quo Becomes Obsolete: The Changing Use of Outdoor Warning Sirens
- Communication/News
- Domestic Federal Interagency Planning: Meeting a Homeland Security Need
- Health Care Logistics Response in a Disaster
- Preparedness versus Reactiveness: An Approach to Pre-Crisis Disaster Planning
- Comment
- Letter to the Editor