Over the last few years, perspectives in information security have been drawn, to a large extent, by risk management. The extensive use of risk management methodologies in organizations relying on an IT infrastructure proves the potential of the practice. In this survey we discuss the characteristics of the quantitative risk management methodologies, compare them and provide an overview on how these methodologies are entwined with the concept of adaptive security. We also discuss the challenges of quantitative risk management and adaptive security models and propose reliable criteria to compare the different approaches in the literature.
목차
Abstract 1. Introduction 2. Quantitative Risk Assessment Methodologies: State of the Art 2.1. Risk Coverage 2.2. Cyclic Risk Management 2.3. Complexity 2.4. Quantification Parameters 2.5. Adaptive Character 2.6. Summarizing Table 3. Quantitative Security Models: the Mathematical Representation 3.1. Quantifiable Input Data 3.2. Quantifiable Output 3.3. Mathematical Representation of Security Vectors 3.4. Summarizing Table 4. Estimating Security Metrics in Quantitative Risk Management 4.1. Choosing the Metrics 4.2. Estimation Methods 4.3. Contribution and Specificities 4.4. Summarizing table 5. Adaptive Risk Management Approaches 5.1. Model basis and Risk Coverage 5.2. Experimental Results 5.3. Summarizing Table 6. Conclusion Acknowledgement References
보안공학연구지원센터(IJUNESST) [Science & Engineering Research Support Center, Republic of Korea(IJUNESST)]
설립연도
2006
분야
공학>컴퓨터학
소개
1. 보안공학에 대한 각종 조사 및 연구
2. 보안공학에 대한 응용기술 연구 및 발표
3. 보안공학에 관한 각종 학술 발표회 및 전시회 개최
4. 보안공학 기술의 상호 협조 및 정보교환
5. 보안공학에 관한 표준화 사업 및 규격의 제정
6. 보안공학에 관한 산학연 협동의 증진
7. 국제적 학술 교류 및 기술 협력
8. 보안공학에 관한 논문지 발간
9. 기타 본 회 목적 달성에 필요한 사업
간행물
간행물명
International Journal of u- and e- Service, Science and Technology
간기
격월간
pISSN
2005-4246
수록기간
2008~2016
십진분류
KDC 505DDC 605
이 권호 내 다른 논문 / International Journal of u- and e- Service, Science and Technology Vol.8 No.5