Risk model development for information security in organization environment based on business perspectives

被引:0
|
作者
Ibnugraha, Prajna Deshanta [1 ]
Nugroho, Lukito Edi [2 ]
Santosa, Paulus Insap [2 ]
机构
[1] Telkom Univ, Sch Appl Sci, Bandung, Indonesia
[2] Univ Gadjah Mada, Dept Elect Engn & Informat Technol, Yogyakarta, Indonesia
关键词
Information security; Risk model; Text mining; Categorical clustering;
D O I
10.1007/s10207-020-00495-7
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Digital information plays an essential role in supporting organizational business. However, incidents of sensitive information leakage often happen in organization environment. Therefore, risk analysis needs to be performed to recognize the impact of information security threat in organization. In order to carry out those risk analyses, risk model is needed to map risk of information security threat. The selection of proper risk model provides proper result related to risk analysis. The proper risk model must have objectivity and appropriate context. However, most of the existing risk models focus on the technical approach and use expert judgment as a weighting method. Meanwhile, organizations use business perspectives to determine decisions. Therefore, this study has the objective to fill the needs of organizations by developing a new risk model. The proposed risk model focuses on business aspects involvement and reducing subjective methods. The proposed risk model also uses three processes to result output, i.e., adaptable classification data, data measurement and cross-label analysis. Test mining and categorical clustering are involved to handle those three processes. Testing of the proposed model is carried out to define ability and limitation of model by involving 30 targets. The result states that the proposed model has advantages in objectivity, context approach and detailed output, while the limited scope of work becomes weakness of these models.
引用
收藏
页码:113 / 126
页数:14
相关论文
共 50 条
  • [41] A Synthesized Risk Evaluation Model of Information Security
    Zhao Jinhui
    Wen Chao
    Qian Xu
    Zhang Juncai
    [J]. 2009 INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE AND COMPUTATIONAL INTELLIGENCE, VOL I, PROCEEDINGS, 2009, : 305 - 308
  • [42] Risk Evaluation Process Model of Information Security
    Liu Jing
    [J]. 2009 INTERNATIONAL CONFERENCE ON MEASURING TECHNOLOGY AND MECHATRONICS AUTOMATION, VOL II, 2009, : 321 - 324
  • [43] A new information security risk evaluation model
    Lin, Zheng-Kui
    [J]. ICIC Express Letters, Part B: Applications, 2012, 3 (05): : 1179 - 1184
  • [44] Information security risk analysis model using information entropy
    Information Security Center, State Key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications, Beijing 100876, China
    不详
    [J]. Beijing Youdian Daxue Xuebao, 2008, 2 (50-53):
  • [45] Development of Environment for Logical Process Safety Management Based on the Business Process Model
    Shimada, Yukiyasu
    [J]. JOURNAL OF CHEMICAL ENGINEERING OF JAPAN, 2012, 45 (04) : 245 - 257
  • [46] Simulation model development in information security education
    Kennesaw State University, 1000 Chastain Road, Kennesaw, GA 30144-5591, United States
    [J]. Proc. Inf. Secur. Curric. Dev. Annu. Conf., InfoSecCD, (21-26):
  • [47] A Markov-Based Model for Information Security Risk Assessment in Healthcare MANETs
    Saini Das
    Arunabha Mukhopadhyay
    Debashis Saha
    Samir Sadhukhan
    [J]. Information Systems Frontiers, 2019, 21 : 959 - 977
  • [48] Development of a business relevant information security management system using the Balanced Scorecard and the EFQM Excellence Model
    Pirnea, Ionela Carmen
    Hohan, Andrei Ioan
    Olaru, Marieta
    [J]. INNOVATION VISION 2020: FROM REGIONAL DEVELOPMENT SUSTAINABILITY TO GLOBAL ECONOMIC GROWTH, VOL I-VI, 2015, : 1208 - 1218
  • [49] Development of a Business Relevant Information Security Management System Using the Balanced Scorecard and the EFQM Excellence Model
    Pirnea, Ionela Carmen
    Hohan, Andrei Ioan
    Olaru, Marieta
    [J]. INNOVATION VISION 2020: FROM REGIONAL DEVELOPMENT SUSTAINABILITY TO GLOBAL ECONOMIC GROWTH, VOL I-VI, 2015, : 1075 - 1084
  • [50] Threat Scenario Dependency-Based Model of Information Security Risk Analysis
    Rahmad, Basuki
    Supangkat, Suhono H.
    Sembiring, Jaka
    Surendro, Kridanto
    [J]. INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2010, 10 (08): : 93 - 102