Issue No.05 - September/October (2007 vol.5)
pp: 57-60
Jonathan Caulkins , Carnegie Mellon University
Eric D. Hough , Space and Naval Warfare Systems Center San Diego
Nancy R. Mead , Software Engineering Institute
Hassan Osman , Ernst & Young
As a software engineer or client, how much of your budget should you spend on software security mitigation for the applications and networks on which you depend? The authors introduce a novel way to optimize a combination of security countermeasures under fixed resources.
software engineering, requirements engineering, risk management, integer programming
Jonathan Caulkins, Eric D. Hough, Nancy R. Mead, Hassan Osman, "Optimizing Investments in Security Countermeasures: A Practical Tool for Fixed Budgets", IEEE Security & Privacy, vol.5, no. 5, pp. 57-60, September/October 2007, doi:10.1109/MSP.2007.117
