Cyber-Risk Management: Technical and Insurance Controls for Enterprise-Level Security

Traditional approaches to security architecture and design have attempted to achieve the goal of the elimination of risk factors - the complete prevention of system compromise through technical and procedural means. Insurance- based solutions to risk long ago admitted that a complete elimination of...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Veröffentlicht in:Information systems security 2002-09, Vol.11 (4), p.33-49
Hauptverfasser: Siegel, Carol A., Sagalow, Ty R., Serritella, Paul
Format: Artikel
Sprache:eng
Schlagworte:
Online-Zugang:Volltext
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:Traditional approaches to security architecture and design have attempted to achieve the goal of the elimination of risk factors - the complete prevention of system compromise through technical and procedural means. Insurance- based solutions to risk long ago admitted that a complete elimination of risk is impossible and, instead, have focused more on reducing the impact of harm through financial avenues, providing policies that indemnify the policy holder in the event of harm.
ISSN:1065-898X
1934-869X
DOI:10.1201/1086/43322.11.4.20020901/38843.5