ebook img

SPAN : a decision support system for security plan analysis. PDF

90 Pages·1.3 MB·en_US
Save to my drive
Quick download
Download
Most books are stored in the elastic cloud where traffic is expensive. For this reason, we have a limit on daily download.

Preview SPAN : a decision support system for security plan analysis.

NAVAL POSTGRADUATE SCHOOL Monterey, California THESIS SPAN: A DECISION SUPPORT SYSTEM FOR SECURITY PLAN ANALYSIS by Stephen H. Ramsey September, 1991 Thesis Advisor: Moshe Zviran Approved for public release; distribution is unlimited T260662 Unclassified SECURITYCLASSIFICATIONOF THISPAGE REPORT DOCUMENTATION PAGE 1a REPORTSECURITYCLASSIFICATION 1b RESTRICTIVE MARKINGS UNCLASSIFIED 2a SECURITYCLASSIFICATIONAUTHORITY 3 DISTRIBUTION/AVAILABILITYOF REPORT Approvedfor publicrelease;distributionisunlimited. 2b DECLASSIFICATION/DOWNGRADINGSCHEDULE 4 PERFORMINGORGANIZATION REPORT NUMBER(S) 5 MONITORINGORGANIZATION REPORT NUMBER(S) 6a NAMEOF PERFORMINGORGANIZATION 6b OFFICESYMBOL 7a NAMEOFMONITORINGORGANIZATION NavalPostgraduateSchool (Ifapplicable) Naval PostgraduateSchool AS 6c ADDRESS(C/ty,State,andZIPCode) 7b ADDRESS(City,State,andZIPCode) Monterey,CA 93943 5000 Monterey,CA 93943-5000 8a NAMEOF FUNDING/SPONSORING 8b OFFICESYMBOL 9 PROCUREMENTINSTRUMENTIDENTIFICATIONNUMBER ORGANIZATION (Ifapplicable) 8c ADDRESS(Gty,State,andZIPCode) 10 SOURCEOFFUNDINGNUMBERS ProgramElementNo ProiectNo TaskNo WorkUnitAo^sion Number 11 TITLE (IncludeSecurityClassification) SPAN:ADECISIONSUPPORTSYSTEMFORSECURITY PLANANALYSIS 12 PERSONALAUTHOR(S) Ramsey,StephenH. 13a TYPEOFREPORT 13b TIME COVERED 14 DATEOF REPORT(year,month,day) 15 PAGECOUNT Master'sThesis From To September, 1991 80 16 SUPPLEMENTARYNOTATION Theviewsexpressed inthisthesisarethoseoftheauthoranddonotreflecttheofficialpolicyorpositionoftheDepartmentofDefenseortheU.S. Government. 17 COSATICODES 18 SUBJECTTERMS(continueonreverseifnecessaryandidentifybyblocknumber) FIELD GROUP SUBGROUP DecisionSupport,ComputerSecurity SecurityPlan , 19 ABSTRACT(continueonreverseifnecessaryandidentifybyblocknumber) Computerbasedinformationsystemsprovidecountlessopportunitiestoimproveanorganization'sfunctioningandenhanceitsproductsor services. Theyalsoexposeorganizationstosignificantrisksastheybecomeincreasinglydependentoninformationresources. Tominimizethe riskstoanorganization'sinformationsystems,anInformationSystems(IS)securityplanmustbeformulated. ADecisionSupportSystem(DSS) canprovidemanagerswithconsistentandconsiseguidanceforthedevelopementandguidanceofanISsecurityplan. SPAN,aDecisionSupport SystemforSecurityPlanAnalysishasbeendevelopedtoprovideISmanagerswithinformationnecessarytomakeinformedISsecurityplan decisions. ThisthesiswilladdresshowSPANcanbeappliedforsecurityplananalysisresultinginbetterandmoreinformedsecurityplan decisions. 20 DISTRIBUTION/AVAILABILITYOFABSTRACT 21 ABSTRACTSECURITYCLASSIFICATION Q Q . UNCLASSIFIED/UNLIMITED SAME ASREPORT J DTICUSERS Unclassified 22a NAMEOF RESPONSIBLE INDIVIDUAL 22b TELEPHONE (IncludeAreacode) 22c OFFICESYMBOL Zviran,Moshe 646-2489 AS/Zv DD FORM 1473,84 MAR 83APReditionmaybeused untilexhausted SECURITYCLASSIFICATIONOFTHISPAGE Allothereditionsareobsolete Unclassified Approved for public release: distribution is unlimited. SPAN: A Decision Support System for Security Plan Analysis by Stephen H. Ramsey Lieutenant, United States Navy B.S., University of Illinois, 1983 Submitted in partial fulfillment of the requirements for the degree of MASTER OF SCIENCE IN INFORMATION SYSTEMS from the NAVAL POSTGRADUATE SCHOOL September 1991 f David R. Whipple, Chairman Department of Administrative Sciences 11 ABSTRACT Computer-based information systems provide countless opportunities to improve an organization's functioning and enhance its products or services. They also expose organizations to significant risks as they become increasingly dependent on information resources. To minimize the risks to an organization's information systems, an Information System (IS) security plan must be formulated. A Decision Support System (DSS) can provide managers with consistent and concise guidance for the development and analysis of an IS security plan. SPAN, a Decision Support System for Security Plan Analysis has been developed to provide IS managers with information necessary to make informed IS security plan decisions. This thesis will address how SPAN can be applied for security plan analysis resulting in better and more informed security plan decisions. in &.I TABLE OF CONTENTS INTRODUCTION I. 1 II. ISSUES IN IS SECURITY PLANNING 2 DECISION SUPPORT AND SECURITY PLANNING III. 5 A. The Benefits of Decision Support 5 B. Existing Packages 6 SPAN DEVELOPMENT IV. 10 A. Requirements 10 B. Software Selection 11 SPAN OVERVIEW V. 13 A. System Requirements 13 B. Design Overview 13 C. Sequence of Operations 14 D. Control Mechanisms 16 E. Strengths and Weaknesses 22 F. Future Development 22 VII. CONCLUSIONS 23 APPENDIX A 24 A. About SPAN 24 B. Using SPAN 32 iv

See more

The list of books you might like

Most books are stored in the elastic cloud where traffic is expensive. For this reason, we have a limit on daily download.