Title :
A Multi-criteria Evaluation Method of Information Security Controls
Author :
Lv, Jun-Jie ; Zhou, Yong-Sheng ; Wang, Yuan Zhuo
Author_Institution :
Bus. Sch., Beijing Technol. & Bus. Univ., Beijing, China
Abstract :
Information management plays an increasingly important role in enterprises with the constant improvement of computer and communications technology. It is known that enterprises have diverse security requirements when implement information security, such as cost, effectiveness, environment, commitment to law and ethic and etc. In this paper, an information security risk management method is proposed to ranking available risk controls quantitatively with the help of PROMETHEE methodology and GAIA plane considering the criteria concerned. Given the preference function, the criteria values and criteria weights of decision-makers, "leaving flow" "entering flow" and "net flow" of each preparation program is calculated to compare advantages and disadvantages of control measurements, then the complete sequence is obtained. The sensitivity analysis and validation are conducted further. Finally, an example is given to illustrate the application of the proposed method. The major contribution of this work is to make available a control ranking model, considering multiple criteria analysis and the interests of different decision makers, for a security control plan to be carried out.
Keywords :
information management; security of data; GAIA plane; PROMETHEE methodology; communications technology; computer communications; control ranking model; different decision makers; entering flow; information management; information security controls; leaving flow; multicriteria evaluation method; multiple criteria analysis; net flow; risk controls; security control plan; security requirements; sensitivity analysis; Computers; Economics; Information security; Investments; Risk management; Sensitivity analysis; GAIA module; Information security; PROMETHEE; multi-criteria;
Conference_Titel :
Computational Sciences and Optimization (CSO), 2011 Fourth International Joint Conference on
Conference_Location :
Yunnan
Print_ISBN :
978-1-4244-9712-6
Electronic_ISBN :
978-0-7695-4335-2
DOI :
10.1109/CSO.2011.43