conference paper
Information security risk assessment, aggregation, and mitigation
2004
Information Security And Privacy, Proceedings
As part of their compliance process with the Basel 2 operational risk management requirements, banks must define how they deal with information security risk management. In this paper we describe work in progress on a new quantitative model to assess and aggregate information security risks that is currently under development for deployment. We show how to find a risk mitigation strategy that is optimal with respect to the model used and the available budget.
Type
conference paper
Author(s)
Voss, T.
Date Issued
2004
Published in
Information Security And Privacy, Proceedings
Series title/Series vol.
Lecture Notes In Computer Science; 3108
Start page
391
End page
401
Editorial or Peer reviewed
NON-REVIEWED
Written at
OTHER
EPFL units
| Event name | Event place | Event date |
Sydney, AUSTRALIA | Jul 13-15, 2004 | |
Available on Infoscience
March 29, 2011
Use this identifier to reference this record