DocumentCode
686328
Title
Applying fuzzy expert system to information security risk Assessment - A case study on an attendance system
Author
Li-Yun Chang ; Zne-Jung Lee
Author_Institution
Dept. of Mechatron. Eng., Huafan Univ., Taipei, Taiwan
fYear
2013
fDate
6-8 Dec. 2013
Firstpage
346
Lastpage
351
Abstract
As computer becomes popular and internet advances rapidly, information application systems are used extensively in organizations. Various information application systems such as attendance systems, accounting systems, and statistical systems have already replaced manual operations. In such a drastic change, the information security issue encountered by organizations becomes increasingly significant. This study adopts an attendance system of a governmental organization to explore the information security issue. The risk assessment of the attendance system mainly focuses on the assessments of confidentiality, integrity and availability. Weak points of the attendance system and threats to the outside are also included in the scope of consideration. This study adopts the ISO/IEC 27001 information security management system standard and ISO/IEC27005:2008 Information technology - Security techniques - Information security risk management to explore the risk assessment method of the attendance system and establish a set of fuzzy expert systems to measure the value at risk. In the meantime, a recommended acceptable value at risk is provided for facilitating and assisting decision makers through practical aspects and fuzzy expert systems and used as a reference for selecting an acceptable value at risk.
Keywords
IEC standards; ISO standards; data integrity; expert systems; fuzzy set theory; government data processing; risk management; security of data; ISO/IEC 27001 information security management system standard; ISO/IEC27005:2008 Information technology security techniques; accounting systems; data availability; data confidentiality; data integrity; fuzzy expert system; governmental organization attendance system; information application systems; information security risk assessment; statistical systems; Artificial neural networks; Hardware; ISO; ISO standards; Internet; Security; Software; Fuzzy Expert System; ISO 27001; Information Security; Risk Assessment;
fLanguage
English
Publisher
ieee
Conference_Titel
Fuzzy Theory and Its Applications (iFUZZY), 2013 International Conference on
Conference_Location
Taipei
Type
conf
DOI
10.1109/iFuzzy.2013.6825462
Filename
6825462
Link To Document