Vis enkel innførsel

dc.contributor.authorWangen, Gaute
dc.contributor.authorShalaginov, Andrii
dc.date.accessioned2018-02-12T11:46:59Z
dc.date.available2018-02-12T11:46:59Z
dc.date.created2016-04-11T16:03:22Z
dc.date.issued2016
dc.identifier.isbn978-3-319-31811-0
dc.identifier.urihttp://hdl.handle.net/11250/2484066
dc.description.abstractAchieving the quantitative risk assessment has long been an elusive problem in information security, where the subjective and qualitative assessments dominate. This paper discusses the appropriateness of statistical and quantitative methods for information security risk management. Through case studies, we discuss different types of risks in terms of quantitative risk assessment, grappling with how to obtain distributions of both probability and consequence for the risks. N.N. Taleb’s concepts of the Black Swan and the Four Quadrants provides the foundation for our approach and classification. We apply these concepts to determine where it is appropriate to apply quantitative methods, and where we should exert caution in our predictions. Our primary contribution is a treatise on different types of risk calculations, and a classification of information security threats within the Four Quadrants.nb_NO
dc.language.isoengnb_NO
dc.publisherSpringernb_NO
dc.relation.ispartofRisks and Security of Internet and Systems: 10th International Conference, CRiSIS 2015, Mytilene, Lesbos Island, Greece, July 20-22, 2015, Revised Selected Papers
dc.titleQuantitative Risk, Statistical Methods and the Four Quadrants for Information Securitynb_NO
dc.typeChapternb_NO
dc.description.versionacceptedVersionnb_NO
dc.source.pagenumber127-143nb_NO
dc.identifier.doi10.1007/978-3-319-31811-0_8
dc.identifier.cristin1349956
dc.description.localcodeThis is a post-peer-review, pre-copyedit version of an article published in [International Conference on Risks and Security of Internet and Systems]. The final authenticated version is available online at: https://link.springer.com/chapter/10.1007%2F978-3-319-31811-0_8nb_NO
cristin.unitcode194,18,21,80
cristin.unitnameNorwegian Information Security Lab
cristin.ispublishedtrue
cristin.fulltextoriginal
cristin.qualitycode1


Tilhørende fil(er)

Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel