Possible risks analysis engine: A prototype tool for managing IT security safeguards acquisition

被引:0
|
作者
Sainsbury, Robert [1 ]
Baskerville, Richard [1 ]
机构
[1] Georgia State Univ, Atlanta, GA 30303 USA
关键词
risk management; risk analysis;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Risk analysis provides a cost-benefit analysis of information security controls and safeguards in economic terms. Despite serious flaws in its fundamentals, approaches to calculating risk have changed little over the past decades. The publicly available frequency data that does exist is generally incompatible and unusable. Theories of mathematical evidence indicate that probability theory is inappropriate where frequency data is unavailable. While alternative theoretical frameworks have been suggested, practical vehicles for the use of such frameworks have yet to materialize. This paper reports on design science research that employs fuzzy sets and possibility theory as kernel theories to develop and demonstrate a prototype of such a practical vehicle. This vehicle opens avenues for testing and operating risk analysis methodologies based on alternative mathematical theories of evidence.
引用
下载
收藏
页码:195 / 203
页数:9
相关论文
共 1 条