A Study on Information Security Investment by the Analytic Hierarchy Process

AHP를 이용한 정보보호투자 의사결정에 대한 연구

  • 공희경 (충북대학교 경영정보학과) ;
  • 전효정 (충북대학교 경영정보학과) ;
  • 김태성 (충북대학교 경영정보학과, BK21 사업팀)
  • Published : 2008.03.31

Abstract

Recently organizations identify information security as one of essential means for gaining competitive advantage. However, they do not actively increase investment in this area because they consider spending for information security as a cost rather than an investment. This is because organizations don't have a clear understanding of information security objectives which can be achieved through investment, and they don't have criteria for alternatives which can be considered in information security investment decision-making. In this paper we propose to model the decision-making process of information security investment by the AHP (Analytic Hierarchy Process). The results will show that availability is the most important criterion for the decision of information security alternatives, and intrusion detection is the most important information security alternative. We hope that the results of this paper provide a guideline for clear decision-making in information security investment.

Keywords