Security risk assessment in electronic data processing systems

  • Authors:
  • Robert H. Courtney, Jr.

  • Affiliations:
  • IBM Corporation, New York, New York

  • Venue:
  • AFIPS '77 Proceedings of the June 13-16, 1977, national computer conference
  • Year:
  • 1977

Quantified Score

Hi-index 0.00

Visualization

Abstract

Concern for the safety of a data processing facility and the data within it should result in the selection of such security measures, including insurance, as are appropriate to bringing the risk within tolerable limits at the lowest cost. These security measures should be selected on the basis of the benefit/cost relationships which they afford. This, in turn, requires a quantification of the potential benefits afforded by each security measure or group of measures for comparison with the cost. Because the benefit afforded by the security measure is lessening or elimination of security problems, which is risk reduction, we must be able to quantify the risk so as to measure the benefit afforded by its elimination or diminution. A workable procedure for doing this is described.