Title :
On Clustering of Risk Mitigation Controls
Author_Institution :
Dept. of Bus. Inf., Daito Bunka Univ., Tokyo, Japan
Abstract :
In the Information Technology Communication Society, information and its related systems in any organization are exposed to various kinds of risks. The organizations should prepare countermeasures against exposed risks in order to protect their assets and secure their activities´ continuity. Risk evaluation and management systems are effective methods for that purpose, and they usually have several sorts of importance, such as construction of secure information system, ascent of personnel´s consciousness on the information security, etc. On the final stage of a risk management system, after the risk evaluation was done and some serious risks were clarified, the system usually goes on the process of choosing effective and available mitigation controls against each of risks. For that purpose, a database of mitigation controls with values properly related to a type of clarified risk should be set up beforehand. In this paper, we propose a method for giving a kind of property vector to each mitigation control and how to apply fuzzy c-mean clustering to set up the database.
Keywords :
fuzzy set theory; information systems; pattern clustering; risk management; security of data; database; fuzzy c-mean clustering; information security; organization; risk evaluation; risk management; risk mitigation; secure information system; Information systems; Information security; fuzzy clustering; mitigation control;
Conference_Titel :
Network-Based Information Systems (NBiS), 2011 14th International Conference on
Conference_Location :
Tirana
Print_ISBN :
978-1-4577-0789-6
Electronic_ISBN :
2157-0418
DOI :
10.1109/NBiS.2011.31