DocumentCode
2343949
Title
A Multi-criteria Evaluation Method of Information Security Controls
Author
Lv, Jun-Jie ; Zhou, Yong-Sheng ; Wang, Yuan Zhuo
Author_Institution
Bus. Sch., Beijing Technol. & Bus. Univ., Beijing, China
fYear
2011
fDate
15-19 April 2011
Firstpage
190
Lastpage
194
Abstract
Information management plays an increasingly important role in enterprises with the constant improvement of computer and communications technology. It is known that enterprises have diverse security requirements when implement information security, such as cost, effectiveness, environment, commitment to law and ethic and etc. In this paper, an information security risk management method is proposed to ranking available risk controls quantitatively with the help of PROMETHEE methodology and GAIA plane considering the criteria concerned. Given the preference function, the criteria values and criteria weights of decision-makers, "leaving flow" "entering flow" and "net flow" of each preparation program is calculated to compare advantages and disadvantages of control measurements, then the complete sequence is obtained. The sensitivity analysis and validation are conducted further. Finally, an example is given to illustrate the application of the proposed method. The major contribution of this work is to make available a control ranking model, considering multiple criteria analysis and the interests of different decision makers, for a security control plan to be carried out.
Keywords
information management; security of data; GAIA plane; PROMETHEE methodology; communications technology; computer communications; control ranking model; different decision makers; entering flow; information management; information security controls; leaving flow; multicriteria evaluation method; multiple criteria analysis; net flow; risk controls; security control plan; security requirements; sensitivity analysis; Computers; Economics; Information security; Investments; Risk management; Sensitivity analysis; GAIA module; Information security; PROMETHEE; multi-criteria;
fLanguage
English
Publisher
ieee
Conference_Titel
Computational Sciences and Optimization (CSO), 2011 Fourth International Joint Conference on
Conference_Location
Yunnan
Print_ISBN
978-1-4244-9712-6
Electronic_ISBN
978-0-7695-4335-2
Type
conf
DOI
10.1109/CSO.2011.43
Filename
5957640
Link To Document