Integrating Modern Portfolio Theory into Information Security Control Selection Optimisation

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Risk management and optimised security control selection in information technology, particularly information security, is crucial for identifying and mitigating organisational threats. Information security control selection and planning are challenging due to limited resources such as funding, time and staffing. This research article is an academic exposition in which a quantitative method of evaluating cyber security risk and utilizing principles of Modern Portfolio Theory (MPT) to optimize the allocation of resources and funding to select security controls to mitigate an organization's specific security risk and in addition reduce and organisations attack surface as the identified Return on Investment (ROI). This article details and illustrates a novel model that uses quantitative risk evaluation methods such as Monte Carlo simulations as opposed to the widely used qualitative methods in the aim to provide organisations with empirical data to make informed decisions, using Modern Portfolio Theory (MPT), when selecting and managing a portfolio of security controls such as Anti-DDOS solutions, Endpoint Detection and Response (EDR) and Cloud Access Security Broker (CASB) solutions.

Original languageEnglish
Title of host publication2nd International Conference on IT Innovations and Knowledge Discovery, ITIKD 2024
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9798350355468
DOIs
Publication statusPublished - 2025
Event2nd International Conference on IT Innovations and Knowledge Discovery, ITIKD 2024 - Manama, Bahrain
Duration: 13 Apr 202515 Apr 2025

Publication series

Name2nd International Conference on IT Innovations and Knowledge Discovery, ITIKD 2024

Conference

Conference2nd International Conference on IT Innovations and Knowledge Discovery, ITIKD 2024
Country/TerritoryBahrain
CityManama
Period13/04/2515/04/25

Keywords

  • Cyber Security
  • Defence in Depth
  • Information Security Attacks
  • Modern Portfolio Theory
  • Risk
  • Risk Management

ASJC Scopus subject areas

  • Artificial Intelligence
  • Computer Science Applications
  • Information Systems
  • Decision Sciences (miscellaneous)
  • Safety, Risk, Reliability and Quality

Fingerprint

Dive into the research topics of 'Integrating Modern Portfolio Theory into Information Security Control Selection Optimisation'. Together they form a unique fingerprint.

Cite this