Logo image
Integrating modern portfolio theory into information security control selection optimisation
Dissertation   Open access

Integrating modern portfolio theory into information security control selection optimisation

Muhammad Zaid Abrahams
Doctor of Philosophy (PHD), University of Johannesburg
2025
Handle:
https://hdl.handle.net/10210/520034

Abstract

Risk management and optimised information security control selection in information technology, particularly information security, is crucial for identifying and mitigating organisational threats. Information security control selection and planning are challenging aspects due to limited resources such as funding, time and staffing. This study is an academic exposition in which a quantitative method of evaluating cyber security risk and utilising principles of quantitative risk management and Modern Portfolio Theory (MPT) to optimise the allocation of resources and funding to select information security controls to mitigate an organisation’s specific information security risk and in addition reduce and organisations attack surface and increase risk mitigation, as the identified Return on Investment (ROI) of investment. This study details and illustrates a novel model that uses quantitative risk evaluation methods such as Monte Carlo Simulations as opposed to the commonly used qualitative methods. The aim is to provide organisations with empirical data to make informed decisions, using Modern Portfolio Theory (MPT) when selecting and managing a portfolio of security controls such as Anti-DDOS solutions, Endpoint Detection and Response (EDR), and Cloud Access Security Broker (CASB) solutions.
pdf
Abrahams_Muhammad_Z_PHD_Informatics_20263.36 MBDownloadView
Open Access

Metrics

1 Record Views

Details

Logo image