Dear All
I would like to let you know that we have a paper under evaluation of
"Computers & Security" acknowledging SPARTA. The title and abstract are
the following (the pre-print is attached):
Title: Optimisation of cyber insurance coverage with selection of cost
effective security controls.
Abstract: Nowadays, cyber threats are considered among the most
dangerous risks by top
management of enterprises. One way to deal with these risks is to insure
them,
but cyber insurance is still quite expensive. The insurance fee can be
reduced if
organisations improve their cyber security protection, i.e., reducing
the insured
risk. In other words, organisations need an investment strategy to
decide the
optimal amount of investments into cyber insurance and self-protection.
In this work, we propose an approach to help a risk-averse organisation to
distribute its cyber security investments in a cost-efficient way. What
makes
our approach unique is that next to defining the amount of investments in
cyber insurance and self-protection, our proposal also explicitly
defines how
these investments should be spent by selecting the most cost-ecffiient
security
controls. Moreover, we provide an exact algorithm for the control selection
problem considering several threats at the same time and compare this
algorithm
with other approximate algorithmic solutions.
--
___________
best regard,
Artsiom Yautsiukhin
Show replies by date