Title
Modeling and Simulating Information Security Management
Abstract
Security Management is a complex task. It requires several interconnected activities: designing, implementing and maintaining a robust technical infrastructure, developing suitable formal procedures and building a widespread, agreed upon security culture. Thus, security managers have to balance and integrate all these activities simultaneously, which involves short and long-term effects and risks. For this reason, security managers need to correctly understand, achieve and maintain a dynamic equilibrium between all of them. The development of a simulation model can be an efficient approach towards this objective, as it involves making explicit key factors in security management and their interconnections to efficiently reduce organizational security risks. This endogenous perspective of the problem can help managers to design and implement more effective policies. This paper presents a methodology for developing simulation models for information security management. The use of this methodology is illustrated through examples.
Year
DOI
Venue
2007
10.1007/978-3-540-89173-4_27
Critical Information Infrastructures Security
Keywords
Field
DocType
efficient approach,simulation model,organizational security risk,dynamic equilibrium,simulation,effective policy,system dynamics,security management,modeling,simulating information security management,complex task,security culture,security manager,information security management,modeling and simulation
Security culture,Computer science,Software security assurance,Security engineering,Computer security,Information security management,System dynamics,Security information and event management,Computer security model,Security management
Conference
Volume
ISSN
ISBN
5141
0302-9743
3-540-89095-5
Citations 
PageRank 
References 
2
0.42
5
Authors
6
Name
Order
Citations
PageRank
Jose Maria Sarriegi1536.43
Javier Santos2254.00
Jose M. Torres3182.10
David Imizcoz420.42
Elyoenai Egozcue540.81
Daniel Liberal620.42