Abstract
Loss measurement for personal information breach incidents can be used as a basis for decision making for information security investments. In this vein, reasonable loss measurement is important in determining information security policies. However, the previous research is focused on estimating the amount of loss which is incurred after incidents. In order to be base data for decision making, loss measurement should include incident-causing-factors before incidents occur. In this paper, we propose a loss measurement model based on an improved FAIR (Factor Analysis of Information Risk) risk analysis methodology. Additionally, we verify the effectiveness of the proposed model by applying it to a large scale personal information leakage case.
Original language | English |
---|---|
Title of host publication | Lecture Notes in Electrical Engineering |
Publisher | Springer Verlag |
Pages | 825-833 |
Number of pages | 9 |
DOIs | |
Publication status | Published - 2015 |
Publication series
Name | Lecture Notes in Electrical Engineering |
---|---|
Volume | 373 |
ISSN (Print) | 1876-1100 |
ISSN (Electronic) | 1876-1119 |
Bibliographical note
Publisher Copyright:© Springer Science+Business Media Singapore 2015.
Keywords
- Loss measurement model
- Personal information breach
- Security policy
ASJC Scopus subject areas
- Industrial and Manufacturing Engineering