TY - JOUR AB - Organizations’ information infrastructures are exposed to a large variety of threats. The most complex of these threats unfold in stages, as actors exploit multiple attack vectors in a sequence of calculated steps. Deciding how to respond to such serious threats poses a challenge that is of substantial practical relevance to IT security managers. These critical decisions require an understanding of the threat actors—including their various motivations, resources, capabilities, and points of access—as well as detailed knowledge about the complex interplay of attack vectors at their disposal. In practice, however, security decisions are often made in response to acute short-term requirements, which results in inefficient resource allocations and ineffective overall threat mitigation. The decision support methodology introduced in this paper addresses this issue. By anchoring IT security managers’ decisions in an operational model of the organization’s information infrastructure, we provide the means to develop a better understanding of security problems, improve situational awareness, and bridge the gap between strategic security investment and operational implementation decisions. To this end, we combine conceptual modeling of security knowledge with a simulation-based optimization that hardens a modeled infrastructure against simulated attacks, and provide a decision support component for selecting from efficient combinations of security controls. We describe the prototypical implementation of this approach, demonstrate how it can be applied, and discuss the results of an in-depth expert evaluation. DA - 2016 DO - 10.1007/s40070-016-0055-7 KW - IT security analysis KW - multi-objective portfolio selection KW - interactive decision support KW - simulation KW - genetic algorithm LA - eng IS - 1-2 M2 - 85 PY - 2016 SN - 2193-9438 SP - 85-117 T2 - EURO Journal on Decision Processes TI - Selecting security control portfolios: A multi-objective simulation-optimization approach UR - https://nbn-resolving.org/urn:nbn:de:0070-pub-29021018 Y2 - 2024-11-22T03:03:42 ER -