2017
DOI: 10.1504/ijcis.2017.088235
|View full text |Cite
|
Sign up to set email alerts
|

Towards effective cybersecurity resource allocation: the Monte Carlo predictive modelling approach

Abstract: Organisations invest in technical and procedural capabilities to ensure the confidentiality, integrity and availability of information assets and sustain business continuity at all times. However, given growing productive assets and limited protective security budgets, there is a need for deliberate evaluation of information security investment. Optimal resource allocation to security is often affected by intrinsically uncertain variables and associated factors like technical, economical and psychological; the… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1

Citation Types

0
3
0

Year Published

2021
2021
2025
2025

Publication Types

Select...
5

Relationship

0
5

Authors

Journals

citations
Cited by 6 publications
(3 citation statements)
references
References 12 publications
0
3
0
Order By: Relevance
“…Using the extreme value theory, Wang et al (2008) measured the daily risk of an organizational information system and modeled the probability distribution of the daily losses and the time trends associated with the extreme behaviors of users. Along the same line of thinking, Fagade et al . (2017) explored the use of the Monte Carlo predictive simulation model in the allocation of cybersecurity resources.…”
Section: Literaturementioning
confidence: 87%
“…Using the extreme value theory, Wang et al (2008) measured the daily risk of an organizational information system and modeled the probability distribution of the daily losses and the time trends associated with the extreme behaviors of users. Along the same line of thinking, Fagade et al . (2017) explored the use of the Monte Carlo predictive simulation model in the allocation of cybersecurity resources.…”
Section: Literaturementioning
confidence: 87%
“…In this case, probabilities were used to measure vulnerabilities and countermeasures to calculate risk, demonstrating that traditional risk estimation procedures can lead to over and underestimations. Similarly, Fagade et al (2017) used a predictive simulation model to show that security resources to protect information assets are frequently over-or under-allocated using traditional allocation methods. A more involved approach to security risk assessment is presented in Bamakan and Dehghanimohammadabadi (2016).…”
Section: Monte Carlo Simulationmentioning
confidence: 99%
“…However, there is some advocacy for its use in this discipline also. Fagade et al [47] explore how a quantitative approach enhances cybersecurity resource allocation while others contend that the qualitative methods so widely used today do not work and need to be replaced with a quantitative approach based on Bayesian statistics and MCS [32].…”
Section: Quantitative Risk Assessment As An Alternativementioning
confidence: 99%