Performance Modelling and Evaluation of Enterprise Information Security Technologies

Date

2014-09-11

Advisors

Journal Title

Journal ISSN

ISSN

Volume Title

Publisher

IEEE

Type

Conference

Peer reviewed

Abstract

By providing effective access control mechanisms, enterprise information security technologies have been proven successful in protecting the confidentiality of sensitive information in business organizations. However, such security mechanisms typically reduce the work productivity of the staff, by making them spend time working on non-project related tasks. Therefore, organizations have to invest a signification amount of capital in the information security technologies, and then to continue incurring additional costs. In this study, we investigate the performance of administrators in an information help desk, and the non-productive time (NPT) in an organization, resulting from the implementation of information security technologies. An approximate analytical solution is discussed first, and the loss of staff member productivity is quantified using non-productive time. Stochastic Petri nets are then used to provide simulation results. The presented study can help information security managers to make investment decisions, and to take actions toward reducing the cost of information security technologies, so that a balance is kept between information security expense, resource drain and effectiveness of security technologies.

Description

The file attached to this record is the author's final peer reviewed version. The Publisher's final version can be found by following the DOI link.

Keywords

Non-productive Time, Queuing Theory, Stochastic Petri Nets, Security Investment Decision, Information Security Technology

Citation

Zeng, W., Koutney, M., van Moorsel, A. (2014) Performance Modelling and Evaluation of Enterprise Information Security Technologies. 2014 IEEE International Conference on Computer and Information Technology, Xi'an, China, September 2014.

Rights

Research Institute