• DocumentCode
    2967705
  • Title

    Evaluation of information security related risks of an organization: the application of the multicriteria decision-making method

  • Author

    Bao-Chyuan Guan ; Lo, Chi-Chun ; Ping Wang ; Jaw-Shi Hwang

  • Author_Institution
    Inf. Manage. Center, Chung Shan Inst. of Sci. & Technol., Lung-Tan, Taiwan
  • fYear
    2003
  • fDate
    14-16 Oct. 2003
  • Firstpage
    168
  • Lastpage
    175
  • Abstract
    In the wake of the fast popularization of information and the rise of electronic commerce, information security is gaining much attention. How to perform the evaluation of the value of assets, how to perform the analysis of the risks associated with assets, and how to protect information assets from sabotage, theft and tamper are important topics in the study of the management of information security. We address the aspects of confidentiality, integrity and availability of information and apply the Analytic Hierarchy Process (AHP) to consolidate expert´s opinions on information risks, in order to construct an integrated framework for risk analysis. The BS7799 standard and the risk level matrix (RLM) are used accordingly to evaluate the effectiveness of and to categorize the risk management measures and to create a complete model for the assessment of information assets related risks. Finally, the research results are verified by a case study. The results can be used by organizations as references for information security planning and management process improvements.
  • Keywords
    decision making; electronic commerce; information management; organisational aspects; risk analysis; security of data; Analytic Hierarchy Process; BS7799 standard; electronic commerce; information assets; information security; information security related risk assessment; management process improvements; multicriteria decision-making; risk analysis; risk level matrix; risk management measures; Asset management; Decision making; Electronic commerce; Information analysis; Information security; Performance analysis; Performance evaluation; Protection; Risk analysis; Risk management;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security Technology, 2003. Proceedings. IEEE 37th Annual 2003 International Carnahan Conference on
  • Print_ISBN
    0-7803-7882-2
  • Type

    conf

  • DOI
    10.1109/CCST.2003.1297555
  • Filename
    1297555