Andersen Consulting/CERIAS PFIRES Project Header

PFIRES: Project Description

Problem
The tremendous growth in e-commerce has increased the risks companies face.

Risks include:
• exposure to theft and fraud
• loss of competitive advantage
• loss of privacy and confidentiality
• denial of service
• regulatory requirements
• material effect on financial statements

Because the internet is rapidly changing, today's security policies may become tomorrow's security weaknesses. A risk assessment process must be established for use in contemplating solutions in e-commerce. Moreover, new solutions must be systematically implemented in order to maintain information security.

Solution
This project will deliver a framework which will help organizations develop and maintain a policy for managing e-commerce risk. This framework will answer such questions as:

• How do organizations determine risk?
• How are risk acceptance and risk shifting decisions made?
• How are these decisions transformed into practice and policy?
• How is the process monitored for effectiveness and change?

Using this framework, organizations will develop their own information security policies and safe methods of change. The project, which will include an implementation package, will be available via the internet and in print.

Participants
This project makes possible the very first partnership between industry and cross-discipline academia. The team consists of members of the GTIS security group of Andersen Consulting and faculty and students of Purdue University's Center for Education and Research in Information Assurance and Security (CERIAS). Dr. Eugene Spafford, a visionary in the information security field, is among the Purdue participants. Furthermore, the project will be reviewed by a team of industry representatives.

Timeline
timeline.gif

Contact
Please direct all comments ands questions to:

Sharon K. Dietz, Andersen Consulting
Andra Short, Purdue University

PFIRES Project Plan

PFIRES Calendar

Status Reports

E-Commerce Information Security Policy Life Cycle

Detailed Objectives For the Research Phase

Available Research Resources

Contacts and Mailing List Info



This page last updated 7/9/99 by Bob Garrett