Decision support for the optimal allocation of security controls

作者:

Highlights:

• Information security investments are becoming an increasingly dominant part of IT and corporate spending.

• Yet, there is limited guidance on optimal allocation of these investments.

• This paper develops an optimization model for allocating controls, incorporating uncertainties in vulnerability assessments.

• The utility of the model is demonstrated for a realistic IT infrastructure.

摘要

We present constrained optimization models that could be used in a decision support system for configuring security solutions for an information systems infrastructure. We begin with a deterministic model that uses security breach probabilities as parameters. Since security breach data is not easily available, breach probabilities are often estimated via surveys, which could lead to estimation errors. To develop robust solutions in the presence of estimation errors, we then present a stochastic optimization model that handles uncertainties in breach probability estimations. Our model solutions incorporate quantifiable security risk and business impact as the models are detailed enough to capture various categories of security attacks, and different levels of security protection and loss values for data and applications. We demonstrate the utility of our models by proposing security solutions for a realistic IT infrastructure using breach probability estimates derived from surveys.

论文关键词:Design and evaluation of IT infrastructure,Constrained optimization,Stochastic programming,Analytical modeling,Decision support system,Risk management,Security breaches,Security survey

论文评审过程:Received 10 May 2018, Revised 2 October 2018, Accepted 3 October 2018, Available online 11 October 2018, Version of Record 12 November 2018.

论文官网地址:https://doi.org/10.1016/j.dss.2018.10.001