Economic Models and Approaches in Information Security for Computer Networks
Nicolas Sklavos, Panagiotis Souras
Abstract
Nicolas Sklavos, Panagiotis Souras
Abstract
Security is one of the most important issues in computer networks. A common view of networks security is based on technical measures. Cryptographic models, firewalls and intrusion detection models are implemented in every information framework of an organization. Although deployment of such technologies may reduce security vulnerabilities and losses from security breaches, it is not clear to organizations how much they must invest in information security. In this article, common approaches of economics in information security are introduced. From the perspective of an organization, security is an investment to be estimated as cost-saving due to reduced losses from security breaches. Besides that, any new ventures that are profitable for the organization and would not be implemented without security countermeasures need to be considered. Any organization should follow a riskmanagement strategy according to their needs. Organizations that over-protect their information infrastructure will have spent too much on information security. Respectively, those who under-protect their information infrastructure will suffer grater losses caused by security breaches.
OpenAlex reports 30 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Security is one of the most important issues in computer networks. A common view of networks security is based on technical measures. Cryptographic models, firewalls and intrusion detection models are implemented in every information framework of an organization. Although deployment of such technologies may reduce security vulnerabilities and losses from security breaches, it is not clear to organizations how much they must invest in information security. In this article, common approaches of economics in information security are introduced. From the perspective of an organization, security is an investment to be estimated as cost-saving due to reduced losses from security breaches. Besides that, any new ventures that are profitable for the organization and would not be implemented without security countermeasures need to be considered. Any organization should follow a riskmanagement strategy according to their needs. Organizations that over-protect their information infrastructure will have spent too much on information security. Respectively, those who under-protect their information infrastructure will suffer grater losses caused by security breaches.
Key concepts: Computer security, Information security management, Security information and event management, Computer science, Information security, Security service, Security convergence, Computer security model