A risk simulation framework for information infrastructure protection
| Data(s) |
2012
|
|---|---|
| Resumo |
Information communication and technology (ICT) systems are almost ubiquitous in the modern world. It is hard to identify any industry, or for that matter any part of society, that is not in some way dependent on these systems and their continued secure operation. Therefore the security of information infrastructures, both on an organisational and societal level, is of critical importance. Information security risk assessment is an essential part of ensuring that these systems are appropriately protected and positioned to deal with a rapidly changing threat environment. The complexity of these systems and their inter-dependencies however, introduces a similar complexity to the information security risk assessment task. This complexity suggests that information security risk assessment cannot, optimally, be undertaken manually. Information security risk assessment for individual components of the information infrastructure can be aided by the use of a software tool, a type of simulation, which concentrates on modelling failure rather than normal operational simulation. Avoiding the modelling of the operational system will once again reduce the level of complexity of the assessment task. The use of such a tool provides the opportunity to reuse information in many different ways by developing a repository of relevant information to aid in both risk assessment and management and governance and compliance activities. Widespread use of such a tool allows the opportunity for the risk models developed for individual information infrastructure components to be connected in order to develop a model of information security exposures across the entire information infrastructure. In this thesis conceptual and practical aspects of risk and its underlying epistemology are analysed to produce a model suitable for application to information security risk assessment. Based on this work prototype software has been developed to explore these concepts for information security risk assessment. Initial work has been carried out to investigate the use of this software for information security compliance and governance activities. Finally, an initial concept for extending the use of this approach across an information infrastructure is presented. |
| Formato |
application/pdf |
| Identificador | |
| Publicador |
Queensland University of Technology |
| Relação |
http://eprints.qut.edu.au/51006/1/Mark_Branagan_Thesis.pdf Branagan, Mark Allan (2012) A risk simulation framework for information infrastructure protection. PhD thesis, Queensland University of Technology. |
| Fonte |
Faculty of Science and Technology; Information Security Institute |
| Palavras-Chave | #information security risk assessment, risk simulation, information infrastructure risk assessment, information infrastructure information security, risk, information security, compliance auditing, complex systems risk assessment, governance #critical infrastructure information security, information security documentation |
| Tipo |
Thesis |