Value at Risk: A Methodology for Information Security Risk Assessment
- Topics:
- Enterprise Risk Management
- Source:
- Purdue University
FREE Registration is required
Overview: This paper presents Value at Risk (VAR), a new methodology for Information Security Risk Assessment. VAR summarizes the worst loss due to a security breach over a target horizon, with a given level of confidence. More formally, VAR describes the quantile of the projected distribution of losses over a given time period. Most of the tools that are used for ISEC risk assessment are qualitative in nature and are not grounded in theory. VAR is a useful tool in the hands of an ISEC expert as it provides a theoretically based, quantitative measure of information security risk.
(Is this item miscategorized? Does it need more tags? Let us know.)
Format: PDF | Size: 155KB | Date: Aug 2001 | Pages: 15




