From Lemons to Peaches: Improving Security ROI through Security Chaos Engineering

Kelly Shortridge
DOI: https://doi.org/10.1109/SecDev53368.2022.00021
2023-07-08
Abstract:Traditional information security presents a poor ROI: payoffs only manifest when attacks are successfully prevented. In a reality where attacks are inevitable, subpar returns are therefore inevitable. The emerging paradigm of Security Chaos Engineering offers a more remunerative and reliable ROI by minimizing attack impacts and generating valuable evidence to inform continuous improvement of system design and operation.
Cryptography and Security,Software Engineering
What problem does this paper attempt to address?