Title:
Developing a Risk Management System for Information Systems Security Incidents

dc.contributor.advisor Navathe, Shamkant B.
dc.contributor.author Farahmand, Fariborz en_US
dc.contributor.committeeMember Sharp, Gunter P.
dc.contributor.committeeMember Camp, L. Jean
dc.contributor.committeeMember Enslow, Philip H.
dc.contributor.committeeMember DeMillo, Richard
dc.contributor.committeeMember Malik, William J.
dc.contributor.department Computing en_US
dc.date.accessioned 2006-01-18T22:27:54Z
dc.date.available 2006-01-18T22:27:54Z
dc.date.issued 2004-11-22 en_US
dc.description.abstract The Internet and information systems have enabled businesses to reduce costs, attain greater market reach, and develop closer business partnerships along with improved customer relationships. However, using the Internet has led to new risks and concerns. This research provides a management perspective on the issues confronting CIOs and IT managers. It outlines the current state of the art of information security, the important issues confronting managers, security enforcement measure/techniques, and potential threats and attacks. It develops a model for classification of threats and control measures. It also develops a scheme for probabilistic evaluation of the impact of security threats with some illustrative examples. It involves validation of information assets and probabilities of success of attacks on those assets in organizations and evaluates the expected damages of these attacks. The research outlines some suggested control measures and presents some cost models for quantifying damages from these attacks and compares the tangible and intangible costs of these attacks. This research also develops a risk management system for information systems security incidents in five stages: 1- Resource and application value analysis, 2- Vulnerability and risk analysis, 3- Computation of losses due to threats and benefits of control measures, 4- Selection of control measures, and 5- Implementation of alternatives. The outcome of this research should help decision makers to select the appropriate control measure(s) to minimize damage or loss due to security incidents. Finally, some recommendations for future work are provided to improve the management of security in organizations. en_US
dc.description.degree Ph.D. en_US
dc.format.extent 717108 bytes
dc.format.mimetype application/pdf
dc.identifier.uri http://hdl.handle.net/1853/7600
dc.language.iso en_US
dc.publisher Georgia Institute of Technology en_US
dc.subject Business en_US
dc.subject Information systems
dc.subject Management information systems Risk management
dc.subject Management information systems Security measures
dc.subject Risk
dc.subject Security
dc.title Developing a Risk Management System for Information Systems Security Incidents en_US
dc.type Text
dc.type.genre Dissertation
dspace.entity.type Publication
local.contributor.advisor Navathe, Shamkant B.
local.contributor.corporatename College of Computing
local.relation.ispartofseries Doctor of Philosophy with a Major in Computer Science
relation.isAdvisorOfPublication 9a3ecea2-fb35-40ed-adc3-4d1802a4ddcf
relation.isOrgUnitOfPublication c8892b3c-8db6-4b7b-a33a-1b67f7db2021
relation.isSeriesOfPublication 41e6384f-fa8d-4c63-917f-a26900b10f64
Files
Original bundle
Now showing 1 - 1 of 1
Thumbnail Image
Name:
Farahmand_Fariborz_200411_Phd.pdf
Size:
700.3 KB
Format:
Adobe Portable Document Format
Description: