Risk model development for information security in organization environment based on business perspectives

被引:0
|
作者
Ibnugraha, Prajna Deshanta [1 ]
Nugroho, Lukito Edi [2 ]
Santosa, Paulus Insap [2 ]
机构
[1] Telkom Univ, Sch Appl Sci, Bandung, Indonesia
[2] Univ Gadjah Mada, Dept Elect Engn & Informat Technol, Yogyakarta, Indonesia
关键词
Information security; Risk model; Text mining; Categorical clustering;
D O I
10.1007/s10207-020-00495-7
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Digital information plays an essential role in supporting organizational business. However, incidents of sensitive information leakage often happen in organization environment. Therefore, risk analysis needs to be performed to recognize the impact of information security threat in organization. In order to carry out those risk analyses, risk model is needed to map risk of information security threat. The selection of proper risk model provides proper result related to risk analysis. The proper risk model must have objectivity and appropriate context. However, most of the existing risk models focus on the technical approach and use expert judgment as a weighting method. Meanwhile, organizations use business perspectives to determine decisions. Therefore, this study has the objective to fill the needs of organizations by developing a new risk model. The proposed risk model focuses on business aspects involvement and reducing subjective methods. The proposed risk model also uses three processes to result output, i.e., adaptable classification data, data measurement and cross-label analysis. Test mining and categorical clustering are involved to handle those three processes. Testing of the proposed model is carried out to define ability and limitation of model by involving 30 targets. The result states that the proposed model has advantages in objectivity, context approach and detailed output, while the limited scope of work becomes weakness of these models.
引用
收藏
页码:113 / 126
页数:14
相关论文
共 50 条
  • [1] Risk model development for information security in organization environment based on business perspectives
    Prajna Deshanta Ibnugraha
    Lukito Edi Nugroho
    Paulus Insap Santosa
    [J]. International Journal of Information Security, 2021, 20 : 113 - 126
  • [2] MANAGEMENT AND BUSINESS MODEL RISK PROFILE IN SECURITY SYSTEMS DEVELOPMENT
    Panevski, Valeri
    [J]. COMPTES RENDUS DE L ACADEMIE BULGARE DES SCIENCES, 2024, 77 (04): : 569 - 575
  • [3] An Application Security Model Based on Business Process in Information System
    Xu, Peng
    Chen, Meirong
    Feng, Lifang
    Wu, Guanfeng
    Ma, Fangli
    Wang, Danchen
    [J]. 2017 12TH INTERNATIONAL CONFERENCE ON INTELLIGENT SYSTEMS AND KNOWLEDGE ENGINEERING (IEEE ISKE), 2017,
  • [4] An information systems security risk assessment model under uncertain environment
    Feng, Nan
    Li, Minqiang
    [J]. APPLIED SOFT COMPUTING, 2011, 11 (07) : 4332 - 4340
  • [5] A dynamic risk model for information technology security in a critical infrastructure environment
    Saunders, JH
    [J]. RISK-BASED DECISIONMAKING IN WATER RESOURCES X, 2003, : 23 - 39
  • [6] Model Based Security Policy Assessment for E-Business Environment
    Chu, Wang
    Feng, Yanli
    [J]. PROCEEDINGS OF INTERNATIONAL SYMPOSIUM ON COMPUTER SCIENCE AND COMPUTATIONAL TECHNOLOGY (ISCSCT 2009), 2009, : 88 - 93
  • [7] Information security risk analysis model based on entropy
    Tang, Y. L.
    Xu, G. A.
    Niu, Y. X.
    Yang, Y. X.
    [J]. 2008 PROCEEDINGS OF INFORMATION TECHNOLOGY AND ENVIRONMENTAL SYSTEM SCIENCES: ITESS 2008, VOL 4, 2008, : 1146 - 1150
  • [8] An Environment-Specific Prioritization Model for Information-Security Vulnerabilities Based on Risk Factor Analysis
    Reyes, Jorge
    Fuertes, Walter
    Arevalo, Paco
    Macas, Mayra
    [J]. ELECTRONICS, 2022, 11 (09)
  • [9] Security Model Based on Network Business Security
    Wu Kehe
    Zhang Tong
    Li Wei
    Ma Gang
    [J]. PROCEEDINGS OF THE 2009 INTERNATIONAL CONFERENCE ON COMPUTER TECHNOLOGY AND DEVELOPMENT, VOL 1, 2009, : 577 - 580
  • [10] Holistic information security management in multi-organization environment
    Wiander, Tirno
    Savola, Reijo
    Karppinen, Kaarina
    Rapeli, Mikko
    [J]. 2006 IEEE INTERNATIONAL SYMPOSIUM ON INDUSTRIAL ELECTRONICS, VOLS 1-7, 2006, : 2942 - 2947