EconPapers    
Economics at your fingertips  
 

Mapping the variations for implementing information security controls to their operational research solutions

Mauricio Diéguez (), Jaime Bustos and Carlos Cares
Additional contact information
Mauricio Diéguez: Universidad de La Frontera
Jaime Bustos: Universidad de La Frontera
Carlos Cares: Universidad de La Frontera

Information Systems and e-Business Management, No 0, 30 pages

Abstract: Abstract Information Security Management is currently guided by process-based standards. Achieving one or some of these standards means deploying their corresponding set of security controls under different constraints on resources, budgets, information assets to protect, and risks to avoid or mitigate, among other factors. This constitutes a complex combinatorial problem in the decision-making process. To select, schedule and deploy these security controls, qualitative approaches have mainly been proposed. Quantitative approaches to information security management are just emerging, and they have been applied only to simplified theoretical cases. The purpose of this paper is to support the notion that the problems of implementing information security controls, in the sense of being put into effect, can be formulated as a family of existing and already solved optimization problems. The main result is a mapping from a set of seven information security management types of problems to their corresponding operational research formulations. A solved case from a governmental institution illustrates the use of the proposed map.

Keywords: Information security management; Security standard; Security controls; Optimization; Operational research (search for similar items in EconPapers)
References: View references in EconPapers View complete reference list from CitEc
Citations:

Downloads: (external link)
http://link.springer.com/10.1007/s10257-020-00470-8 Abstract (text/html)
Access to the full text of the articles in this series is restricted.

Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.

Export reference: BibTeX RIS (EndNote, ProCite, RefMan) HTML/Text

Persistent link: https://EconPapers.repec.org/RePEc:spr:infsem:v::y::i::d:10.1007_s10257-020-00470-8

Ordering information: This journal article can be ordered from
http://www.springer. ... ystems/journal/10257

DOI: 10.1007/s10257-020-00470-8

Access Statistics for this article

Information Systems and e-Business Management is currently edited by Jörg Becker and Michael J. Shaw

More articles in Information Systems and e-Business Management from Springer
Bibliographic data for series maintained by Sonal Shukla () and Springer Nature Abstracting and Indexing ().

 
Page updated 2025-03-20
Handle: RePEc:spr:infsem:v::y::i::d:10.1007_s10257-020-00470-8