The Information Security Risk Estimation Engine: A Tool for Possibility Based Risk Assessment

Risk analysis methods help evaluate the costs of information security controls in relation to their benefits. Despite dramatic changes in the constellation of information security risks, the basic approach to these risk calculation methods remains unchanged. The fundamental mathematics underlying th...

Full description

Bibliographic Details
Main Authors: Baskerville, Richard, Kim, J., Stucke, C., Sainsbury, R.
Other Authors: H. Raghav Rao
Format: Conference Paper
Published: IFIP 2013
Online Access:http://hdl.handle.net/20.500.11937/3995
_version_ 1848744389251170304
author Baskerville, Richard
Kim, J.
Stucke, C.
Sainsbury, R.
author2 H. Raghav Rao
author_facet H. Raghav Rao
Baskerville, Richard
Kim, J.
Stucke, C.
Sainsbury, R.
author_sort Baskerville, Richard
building Curtin Institutional Repository
collection Online Access
description Risk analysis methods help evaluate the costs of information security controls in relation to their benefits. Despite dramatic changes in the constellation of information security risks, the basic approach to these risk calculation methods remains unchanged. The fundamental mathematics underlying these methods is anchored to probability theory. Probability has the advantage of being widely known and conceptually simple. But it has a disadvantage in its grounding on expert estimates of frequency data because such data is often publicly unavailable. This paper proposes the use of possibility theory as an alternative grounding for information security risk calculations. Possibility theory assumes the data grounding will be estimations. The estimations include expert evaluations of both possibility and likelihood of risks. Using a design science research approach, we use possibility theory as the kernel theory in developing and evaluating a practical possibility-based risk estimation prototype. The results offer an expanded grounding to improve information security risk analysis through the use of a broader portfolio of distinct methodologies anchored to alternative mathematical theories of evidence.
first_indexed 2025-11-14T06:00:41Z
format Conference Paper
id curtin-20.500.11937-3995
institution Curtin University Malaysia
institution_category Local University
last_indexed 2025-11-14T06:00:41Z
publishDate 2013
publisher IFIP
recordtype eprints
repository_type Digital Repository
spelling curtin-20.500.11937-39952017-01-30T10:35:44Z The Information Security Risk Estimation Engine: A Tool for Possibility Based Risk Assessment Baskerville, Richard Kim, J. Stucke, C. Sainsbury, R. H. Raghav Rao Risk analysis methods help evaluate the costs of information security controls in relation to their benefits. Despite dramatic changes in the constellation of information security risks, the basic approach to these risk calculation methods remains unchanged. The fundamental mathematics underlying these methods is anchored to probability theory. Probability has the advantage of being widely known and conceptually simple. But it has a disadvantage in its grounding on expert estimates of frequency data because such data is often publicly unavailable. This paper proposes the use of possibility theory as an alternative grounding for information security risk calculations. Possibility theory assumes the data grounding will be estimations. The estimations include expert evaluations of both possibility and likelihood of risks. Using a design science research approach, we use possibility theory as the kernel theory in developing and evaluating a practical possibility-based risk estimation prototype. The results offer an expanded grounding to improve information security risk analysis through the use of a broader portfolio of distinct methodologies anchored to alternative mathematical theories of evidence. 2013 Conference Paper http://hdl.handle.net/20.500.11937/3995 IFIP restricted
spellingShingle Baskerville, Richard
Kim, J.
Stucke, C.
Sainsbury, R.
The Information Security Risk Estimation Engine: A Tool for Possibility Based Risk Assessment
title The Information Security Risk Estimation Engine: A Tool for Possibility Based Risk Assessment
title_full The Information Security Risk Estimation Engine: A Tool for Possibility Based Risk Assessment
title_fullStr The Information Security Risk Estimation Engine: A Tool for Possibility Based Risk Assessment
title_full_unstemmed The Information Security Risk Estimation Engine: A Tool for Possibility Based Risk Assessment
title_short The Information Security Risk Estimation Engine: A Tool for Possibility Based Risk Assessment
title_sort information security risk estimation engine: a tool for possibility based risk assessment
url http://hdl.handle.net/20.500.11937/3995