Security risk factors: ANP model for risk management decision making

被引:0
|
作者
Brozova, Helena [1 ]
Rydval, Jan [1 ]
Sup, Libor [1 ]
Sadok, Moufida [2 ,3 ]
Bednar, Peter [3 ,4 ]
机构
[1] Czech Univ Life Sci, Fac Agr Econ & Management, Dept Syst Engn, Prague, Czech Republic
[2] Higher Inst Technol Studies Commun, Tunis, Tunisia
[3] Univ Portsmouth, Sch Comp, Portsmouth, Hants, England
[4] Lund Univ, Dept Informat, Lund, Sweden
关键词
Information security; Risk factors; Semantic networks; Analytical network process; Multi-criteria decision making;
D O I
暂无
中图分类号
F [经济];
学科分类号
02 ;
摘要
Information is a valuable asset supporting management decisions and business operations within the enterprise. Consequently, securing the company critical information assets from sophisticated insider threats and outsider attacks is essential to ensure business continuity and compliance with regulatory frameworks. Security risk management is the process that identifies threats and vulnerabilities of an enterprise information system, evaluates the likelihood of their occurrence and estimates their potential business impact. It is a continuous process that allows cost effectiveness of implemented security controls and provides a dynamic set of tools to monitor the security level of the information system. Given the uncertainty and complexity of security risks analyses, the identification of risk factors as well as the estimation of their business impact require tools for assessment of risk with multi-value scales according to different stakeholders' point of view. Therefore, the purpose of this paper is to model risk factors using semantic network to develop the decision network and the Analytical Network Process (ANP) to evaluate factors of complex problems taking into consideration quantitative and qualitative data. As a decision support technique ANP also measures the dependency among risk factors related to the elicitation of individual judgement.
引用
收藏
页码:74 / 79
页数:6
相关论文
共 50 条
  • [1] A Security-by-Design Decision-Making Model for Risk Management in Autonomous Vehicles
    Abdel-Basset, Mohamed
    Gamal, Abduallah
    Moustafa, Nour
    Abdel-Monem, Ahmed
    El-Saber, Nissreen
    [J]. IEEE ACCESS, 2021, 9 : 107657 - 107679
  • [2] A decision model based security risk management approach
    Bhattacharya, Somak
    Ghosh, S. K.
    [J]. IMECS 2008: INTERNATIONAL MULTICONFERENCE OF ENGINEERS AND COMPUTER SCIENTISTS, VOLS I AND II, 2008, : 1194 - 1199
  • [3] A Model to Support Risk Management Decision-Making
    Tchangani, Ayeley P.
    [J]. STUDIES IN INFORMATICS AND CONTROL, 2011, 20 (03): : 209 - 220
  • [4] Decision making and risk management
    Lavell, A
    [J]. FURTHERING CO-OPERATION IN SCIENCE AND TECHNOLOGY FOR CARIBBEAN DEVELOPMENT, 1998, : 212 - 227
  • [5] Coping with systems risk: Security planning models for management decision making
    Straub, DW
    Welke, RJ
    [J]. MIS QUARTERLY, 1998, 22 (04) : 441 - 469
  • [6] RISK ASSESSMENT AND RISK MANAGEMENT - KEY FACTORS IN FOOD SAFETY DECISION-MAKING
    HUDSON, CB
    [J]. FOOD AUSTRALIA, 1991, 43 (09): : S10 - S12
  • [7] Risk Management and Risk Avoidance in Agency Decision Making
    Eckerd, Adam
    [J]. PUBLIC ADMINISTRATION REVIEW, 2014, 74 (05) : 616 - U197
  • [8] Airspace Congestion Risk Management Decision Making Model and Methodology
    Tian, W.
    Yin, J. N.
    Ma, Y. Y.
    [J]. INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND ENVIRONMENTAL ENGINEERING (CSEE 2015), 2015, : 825 - 831
  • [9] A distributed decision making model for risk management of virtual enterprise
    Huang, Min
    Lu, Fu-Qiang
    Ching, Wai-Ki
    Siu, Tak Kuen
    [J]. EXPERT SYSTEMS WITH APPLICATIONS, 2011, 38 (10) : 13208 - 13215
  • [10] Decision-making model incorporating risk behavior under project risk management
    Li, Qi-Ming
    Shen, Li-Yin
    [J]. Xitong Gongcheng Lilun yu Shijian/System Engineering Theory and Practice, 2001, 21 (10):