Considerations on the selection and prioritization of information security solutions

This paper provides a set of guidelines that can be used for prescribing a methodology or a detailed process for selecting and prioritizing security projects or solutions. It is based on the idea that costs of security solutions should be justified by their contribution to ensuring adequate protecti...

Full description

Bibliographic Details
Main Author: Maria Cristina RĂDULESCU
Format: Article
Language:English
Published: Chamber of Financial Auditors of Romania 2016-05-01
Series:Audit Financiar
Subjects:
Online Access: http://revista.cafr.ro/temp/Article_9477.pdf
Description
Summary:This paper provides a set of guidelines that can be used for prescribing a methodology or a detailed process for selecting and prioritizing security projects or solutions. It is based on the idea that costs of security solutions should be justified by their contribution to ensuring adequate protection of information resources in the organization which implements them. The article reviews general issues of security risks and costs, arguing the need for explicit consideration of information resources security requirements in order to validate decisions concerning security projects implementation. In such an approach, security requirements of information resources are used as a reference system to quantify the benefits and limitations of security solutions defined as alternative or complementary responses to certain security risks as their implementation faces budget constraints.
ISSN:1844-8801