IDEAS home Printed from https://ideas.repec.org/p/dar/wpaper/46351.html
   My bibliography  Save this paper

Quantifying Risks in Service Networks: Using Probability Distributions for the Evaluation of Optimal Security Levels

Author

Listed:
  • Ackermann, Tobias
  • Buxmann, Peter

Abstract

The increasing costs and frequency of security incidents require organizations to apply proper IT risk management. At the same time, the expanding usage of Service-oriented Architectures fosters software systems composed of cross-linked services. Therefore, it is important to develop risk management methods for these composite systems. In this paper, we present a straightforward model that can be used to quantify the risks related to service networks. Based on the probability distribution of the costs which are related to risks, it is possible to make proper investment choices using individual risk preferences. The attractiveness of investment alternatives and different levels of security can be measured with various characteristics like the expected value of the costs, the Value-at-Risk or more complex utility functions. Through performance evaluations we show that our model can be used to calculate the costs’ probability density function for large scale networks in a very efficient way. Furthermore, we demonstrate the application of the model and the algorithms with the help of a concrete application scenario. As a result, we improve IT risk management by proposing a model which supports decision makers in comparing alternative service scenarios and alternative security investments in order to find the optimal level of IT security.

Suggested Citation

  • Ackermann, Tobias & Buxmann, Peter, 2010. "Quantifying Risks in Service Networks: Using Probability Distributions for the Evaluation of Optimal Security Levels," Publications of Darmstadt Technical University, Institute for Business Studies (BWL) 46351, Darmstadt Technical University, Department of Business Administration, Economics and Law, Institute for Business Studies (BWL).
  • Handle: RePEc:dar:wpaper:46351
    Note: for complete metadata visit http://tubiblio.ulb.tu-darmstadt.de/46351/
    as

    Download full text from publisher

    File URL: http://aisel.aisnet.org/amcis2010/284/
    Download Restriction: no
    ---><---

    Citations

    Citations are extracted by the CitEc Project, subscribe to its RSS feed for this item.
    as


    Cited by:

    1. Björn Häckel & Florian Hänsch & Michael Hertel & Jochen Übelhör, 2019. "Assessing IT availability risks in smart factory networks," Business Research, Springer;German Academic Association for Business Research, vol. 12(2), pages 523-558, December.

    More about this item

    Statistics

    Access and download statistics

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:dar:wpaper:46351. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    We have no bibliographic references for this item. You can help adding them by using this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: Dekanatssekretariat (email available below). General contact details of provider: https://edirc.repec.org/data/ivthdde.html .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.