USING FAULT TREE ANALYSIS WITH COBIT 5 RISK SCENARIOS

被引:0
|
作者
Modi, Shivani [1 ]
Butakov, Sergey [1 ]
Zavarsky, Pavol [1 ]
机构
[1] Concordia Univ Edmonton, Edmonton, AB, Canada
来源
2018 5TH INTERNATIONAL CONFERENCE ON CONTROL, DECISION AND INFORMATION TECHNOLOGIES (CODIT) | 2018年
关键词
IT governance; IT management; Processes; COBIT; 5; framework; Risk Scenarios; Fault Tree Analysis;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Information System Audit and Control Association (ISACA) proposed a preliminary idea on applying fault tree analysis to look at the root reasons for the IT risks outlined in COBIT 5 Risk Scenarios. So far, there was no prescriptive procedure/ methodology, which could be used to build the fault tree. This research looked into various methodologies for building the fault tree and proposed a new methodology, which could be used for analysis of risks outlined in COBIT 5 Risk Scenarios document. The methodology has been developed specific to COBIT 5 processes to build the fault tree, which, in turn, can help to outline the common factors that lead to failure of the processes subsequently leading to a risk. Fault tree analysis, could help to improve processes and suggest potential mitigation strategy to improve management/governance of IT. The paper also includes a sample of using the proposed methodology on one of the risk scenarios in order to calculate minimal cut set of IT management practices that organization needs to focus on to address specific risks.
引用
收藏
页码:385 / 390
页数:6
相关论文
共 50 条
  • [1] IT Risk Management in the enterprise using CobiT 5
    Kozina, Melita
    CENTRAL EUROPEAN CONFERENCE ON INFORMATION AND INTELLIGENT SYSTEMS (CECIIS 2021), 2021, : 249 - 256
  • [2] Disaster Management in India - An Analysis using COBIT 5 Principles
    Mohanan, Chippi
    Menon, Vivek
    PROCEEDINGS OF THE SIXTH IEEE GLOBAL HUMANITARIAN TECHNOLOGY CONFERENCE GHTC 2016, 2016, : 209 - 212
  • [3] THE GOVERNANCE MEASUREMENT OF INFORMATION SYSTEM USING FRAMEWORK COBIT 5 IN AUTOMOTIVE COMPANY
    Harefa, Kalvin Rahmat Putra
    Legowo, Nilo
    2017 1ST INTERNATIONAL CONFERENCE ON APPLIED COMPUTER AND COMMUNICATION TECHNOLOGIES (COMCOM), 2017, : 133 - 138
  • [4] Comprehensive risk assessment of river basins using Fault Tree Analysis
    Gachlou, Mandi
    Roozbahani, Abbas
    Banihabib, Mohammad Ebrahim
    JOURNAL OF HYDROLOGY, 2019, 577
  • [5] Analysis of Information Technology Governance e-KTP using COBIT 5 Framework
    Tridoyo
    Wijaya, Agustinus Fritz
    2017 INTERNATIONAL CONFERENCE ON INNOVATIVE AND CREATIVE INFORMATION TECHNOLOGY (ICITECH), 2017,
  • [6] Using the Cobit 5 for E-health Governance
    Kozina, Melita
    Sekovanic, Ines
    CENTRAL EUROPEAN CONFERENCE ON INFORMATION AND INTELLIGENT SYSTEMS, 2015, 2015, : 203 - 209
  • [7] FAULT TREE ANALYSIS - USING SPREADSHEET
    LIU, MC
    PROCEEDINGS ANNUAL RELIABILITY AND MAINTAINABILITY SYMPOSIUM, 1990, (SYM): : 513 - 516
  • [8] A Code of Practice for Effective Information Security Risk Management Using COBIT 5
    Al-Ahmad, Walid
    Mohammed, Basil
    2015 SECOND INTERNATIONAL CONFERENCE ON INFORMATION SECURITY AND CYBER FORENSICS (INFOSEC), 2015, : 145 - 151
  • [9] Cybersecurity risk analysis model using fault tree analysis and fuzzy decision theory
    Henriques de Gusmao, Ana Paula
    Silva, Maisa Mendonca
    Poleto, Thiago
    Camara e Silva, Lucio
    Cabral Seixas Costa, Ana Paula
    INTERNATIONAL JOURNAL OF INFORMATION MANAGEMENT, 2018, 43 : 248 - 260
  • [10] Risk based facility location by using fault tree analysis in disaster management
    Akgun, Ibrahim
    Gumusbuga, Ferhat
    Tansel, Barbaros
    OMEGA-INTERNATIONAL JOURNAL OF MANAGEMENT SCIENCE, 2015, 52 : 168 - 179