Workshop-based Multiobjective Security Safeguard Selection

  • Authors:
  • Thomas Neubauer;Christian Stummer;Edgar Weippl

  • Affiliations:
  • Institute of Software Technology and Interactive Systems Vienna University of Technology, Austria;School of Business, Economics,and Statistics, Vienna University of Technology, Austria;Institute of Software Technology and Interactive Systems Vienna University of Technology, Austria

  • Venue:
  • ARES '06 Proceedings of the First International Conference on Availability, Reliability and Security
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

Companies spend considerable amounts of resources on minimizing security breaches but often neglect efficient security measures and/or are not aware whether their investments are effective. While security safeguards traditionally are evaluated through a single (aggregated) criterion such as the return on investment, this may not suffice any longer as economic and legal requirements force top management to pay more attention to security issues. Thus, there is a demand for decision support tools that assist decision makers in allocating security safeguards with respect to multiple objectives of the involved stakeholders. This paper proposes a tool called MOS3T (Multi-Objective Security Safeguard Selection Tool), that integrates ideas from multiobjective decision making in a workshop environment. The stepwise procedure for the assessment and interactive selection of sets of security safeguards improves security awareness of top management while minimizing the resources required for implementing a proper security environment that meets a corporate's needs.