On identifying proper security mechanisms

  • Authors:
  • Jakub Breier;Ladislav Hudec

  • Affiliations:
  • Faculty of Informatics and Information Technologies, Slovak University of Technology, Bratislava, Slovakia;Faculty of Informatics and Information Technologies, Slovak University of Technology, Bratislava, Slovakia

  • Venue:
  • ICT-EurAsia'13 Proceedings of the 2013 international conference on Information and Communication Technology
  • Year:
  • 2013

Quantified Score

Hi-index 0.00

Visualization

Abstract

Selection of proper security mechanisms that will protect the organization's assets against cyber threats is an important non-trivial problem. This paper introduces the approach based on statistical methods that will help to choose the proper controls with respect to actual security threats. First, we determine security mechanisms that support control objectives from ISO/IEC 27002 standard and assign them meaningful weights. Then we employ a factor analysis to reveal dependencies among control objectives. Then this knowledge can be reflected to security mechanisms, that inherit these dependencies from control objectives.