Selecting security control portfolios

Author(s)
Elmar Kiesling, Andreas Ekelhart, Bernhard Grill, Christine Strauss, Christian Stummer
Abstract

Organizations’ information infrastructures are exposed to a large variety of threats. The most complex of these threats unfold in stages, as actors exploit multiple attack vectors in a sequence of calculated steps. Deciding how to respond to such serious threats poses a challenge that is of substantial practical relevance to IT security managers. These critical decisions require an understanding of the threat actors—including their various motivations, resources, capabilities, and points of access—as well as detailed knowledge about the complex interplay of attack vectors at their disposal. In practice, however, security decisions are often made in response to acute short-term requirements, which results in inefficient resource allocations and ineffective overall threat mitigation. The decision support methodology introduced in this paper addresses this issue. By anchoring IT security managers’
decisions in an operational model of the organization’s information infrastructure, we provide the means to develop a better understanding of security problems, improve situational awareness, and bridge the gap between strategic security investment and operational implementation decisions. To this end, we combine conceptual modeling of security knowledge with a simulation-based optimization that hardens a modeled infrastructure against simulated attacks, and provide a decision support component for selecting from efficient combinations of security controls. We describe the prototypical implementation of this approach, demon-strate how it can be applied, and discuss the results of an in-depth expert evaluation.

Organisation(s)
Department of Accounting, Innovation and Strategy
External organisation(s)
Technische Universität Wien, Secure Business Austria (SBA), Universität Bielefeld
Journal
EURO Journal on Decision Processes
Volume
4
Pages
85-117
No. of pages
33
ISSN
2193-9438
DOI
https://doi.org/10.1007/s40070-016-0055-7
Publication date
06-2016
Peer reviewed
Yes
Austrian Fields of Science 2012
101015 Operations research, 102016 IT security, 502050 Business informatics, 102009 Computer simulation
Keywords
ASJC Scopus subject areas
Decision Sciences(all), Business, Management and Accounting (miscellaneous), Statistics and Probability, Applied Mathematics, Computational Mathematics
Portal url
https://ucris.univie.ac.at/portal/en/publications/selecting-security-control-portfolios(adfa8662-2022-4b3a-b214-61b7e9a9817d).html