• DocumentCode
    233141
  • Title

    A New Security and Privacy Risk Assessment Model for Information System Considering Influence Relation of Risk Elements

  • Author

    Wu Tianshui ; Zhao Gang

  • Author_Institution
    Sch. of Inf. Manage., Beijing Inf. Sci. & Technol. Univ., Beijing, China
  • fYear
    2014
  • fDate
    8-10 Nov. 2014
  • Firstpage
    233
  • Lastpage
    238
  • Abstract
    Considering the influence relations among risk assessment elements and the uncertainty generated in the security and privacy risk assessment process, this paper proposes a new security and privacy risk assessment model for information system which is based on DEMATEL-ANP combined with grey system theory. On the basis of risk assessment standard process, this model utilizes the DEMATEL method to identify risk assessment elements and evaluate comprehensive influence relations. Further, the model combines with ANP to solve the weight distribution ratio of the subordinate element of each evaluation elements. Finally the paper uses grey system theory to obtain grey evaluation matrix, and computes final security and privacy risk level. Examples simulation demonstrates that it is an effective method for information system on security and privacy risk assessment, which the model not only weighs up the association influence among the various evaluation factors in practical evaluation system, reduces the subjective evaluation, but also can effectively mitigate the uncertainty of expert evaluation.
  • Keywords
    data privacy; decision making; grey systems; information systems; risk management; security of data; DEMATEL-ANP; analytic network process; decision making trial-and-evaluation laboratory; final security; grey evaluation matrix; grey system theory; information system; privacy risk assessment model; privacy risk level; security risk assessment model; weight distribution ratio; Computational modeling; Indexes; Information security; Privacy; Risk management; analytic network process (ANP); decision making trial and evaluation laboratory (DEMATEL); grey system theory; risk assessment; security and privacy;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Broadband and Wireless Computing, Communication and Applications (BWCCA), 2014 Ninth International Conference on
  • Conference_Location
    Guangdong
  • Print_ISBN
    978-1-4799-4174-2
  • Type

    conf

  • DOI
    10.1109/BWCCA.2014.76
  • Filename
    7016074