Vulnerability Enhancement vs. Loss Mitigation: Optimal Information Security Investment



Full text

Journal of Information System Security
Volume 12, Number 2 (2016)
Pages 7590
ISSN 1551-0123
Bin Mai — University of North Texas, Denton, USA
Shailesh Kulkarni — University of North Texas, Denton, USA
Mohammad Salehan — State Polytechnic University, Pomona, USA
Information Institute Publishing, Washington DC, USA




In this paper, we study information security investment for target asset protection. Most existing studies focus on the investment in information security that impacts the target asset’s vulnerability while assuming that the loss resulting from a successful security breach is irrelevant to the security investment. We recognize the practice of information security investment in mitigating the resultant loss of security breaches and incorporate this important aspect of information security investment decision making in a mathematical modeling framework. We address the simultaneous impacts of security investment on not only the vulnerability of the target system, but also to the potential loss if the attack succeeds. Our results shed significant new light on optimal information security investment, including the conditions under which the information security investment should be focused more on vulnerability enhancement than loss mitigation, or vice versa; how the target asset’s inherent vulnerability and potential loss after successful breach would impact the investment on either aspect, and how total a budget constraint would affect the optimal investment decision.




Information Security, Optimal Investment, Information Systems, Optimization, Vulnerability, Loss Mitigation




