USING FAULT TREE ANALYSIS WITH COBIT 5 RISK SCENARIOS

被引:0
|
作者
Modi, Shivani [1 ]
Butakov, Sergey [1 ]
Zavarsky, Pavol [1 ]
机构
[1] Concordia Univ Edmonton, Edmonton, AB, Canada
来源
2018 5TH INTERNATIONAL CONFERENCE ON CONTROL, DECISION AND INFORMATION TECHNOLOGIES (CODIT) | 2018年
关键词
IT governance; IT management; Processes; COBIT; 5; framework; Risk Scenarios; Fault Tree Analysis;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Information System Audit and Control Association (ISACA) proposed a preliminary idea on applying fault tree analysis to look at the root reasons for the IT risks outlined in COBIT 5 Risk Scenarios. So far, there was no prescriptive procedure/ methodology, which could be used to build the fault tree. This research looked into various methodologies for building the fault tree and proposed a new methodology, which could be used for analysis of risks outlined in COBIT 5 Risk Scenarios document. The methodology has been developed specific to COBIT 5 processes to build the fault tree, which, in turn, can help to outline the common factors that lead to failure of the processes subsequently leading to a risk. Fault tree analysis, could help to improve processes and suggest potential mitigation strategy to improve management/governance of IT. The paper also includes a sample of using the proposed methodology on one of the risk scenarios in order to calculate minimal cut set of IT management practices that organization needs to focus on to address specific risks.
引用
收藏
页码:385 / 390
页数:6
相关论文
共 50 条
  • [21] Simplified IT Risk Management Maturity Audit System based on "COBIT 5 for Risk"
    Berrada, Hasnaa
    Boutahar, Jaouad
    El Houssaini, Souhail El Ghazi
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (08) : 641 - 652
  • [22] Information Technology Governance Audit Using the COBIT 5 Framework at XYZ University
    Tangka, George Morris William
    Liem, Andrew Tanny
    Mambu, Joe Yuan
    PROCEEDINGS OF ICORIS 2020: 2020 THE 2ND INTERNATIONAL CONFERENCE ON CYBERNETICS AND INTELLIGENT SYSTEM (ICORIS), 2020, : 151 - 155
  • [23] A new risk assessment method based on belief rule base and fault tree analysis
    Zhu, Hai-Long
    Liu, Shan-Shan
    Qu, Yuan-Yuan
    Han, Xiao-Xia
    He, Wei
    Cao, You
    PROCEEDINGS OF THE INSTITUTION OF MECHANICAL ENGINEERS PART O-JOURNAL OF RISK AND RELIABILITY, 2022, 236 (03) : 420 - 438
  • [24] Risk Assessment in Bridge Construction Projects Using Fault Tree and Event Tree Analysis Methods Based on Fuzzy Logic
    Abdollahzadeh, Gholamreza
    Rastgoo, Sima
    ASCE-ASME JOURNAL OF RISK AND UNCERTAINTY IN ENGINEERING SYSTEMS PART B-MECHANICAL ENGINEERING, 2015, 1 (03):
  • [25] Phased mission modelling using fault tree analysis
    La Band, RA
    Andrews, JD
    PROCEEDINGS OF THE INSTITUTION OF MECHANICAL ENGINEERS PART E-JOURNAL OF PROCESS MECHANICAL ENGINEERING, 2004, 218 (E2) : 83 - 91
  • [26] Fault tree analysis of embedded systems using SystemC
    Zarandi, HR
    Miremadi, SG
    ANNUAL RELIABILITY AND MAINTAINABILITY SYMPOSIUM, 2005 PROCEEDINGS, 2005, : 77 - 81
  • [27] Integrating COBIT 5 PAM and TIPA for ITIL Using an Ontology Matching System
    Almeida, Rafael
    Goncalves, Paloma Andrade
    Percheiro, Ines
    da Silva, Miguel Mira
    Pardo Calvache, Cesar Jesus
    INTERNATIONAL JOURNAL OF HUMAN CAPITAL AND INFORMATION TECHNOLOGY PROFESSIONALS, 2020, 11 (03) : 74 - 93
  • [28] Analysis of Capability Level in Dealing with IT Business Transformation Competition using Cobit Framework 5 (Case Study at Airasia Indonesia)
    Pratiwi, Aditya Niken
    Suharjito
    Sukmandhani, Arief Agus
    PROCEEDINGS OF 2020 INTERNATIONAL CONFERENCE ON INFORMATION MANAGEMENT AND TECHNOLOGY (ICIMTECH), 2020, : 609 - 614
  • [29] A NEW FAULT TREE ANALYSIS METHOD: FUZZY DYNAMIC FAULT TREE ANALYSIS
    Li, Yan-Feng
    Huang, Hong-Zhong
    Liu, Yu
    Xiao, Ningcong
    Li, Haiqing
    EKSPLOATACJA I NIEZAWODNOSC-MAINTENANCE AND RELIABILITY, 2012, 14 (03): : 208 - 214
  • [30] A Method of Fault Diagnosis for Flight Control System Using Fault Tree Analysis
    Zhang Jingkai
    Zhang Weiguo
    Liu Xiaoxiong
    ISTM/2009: 8TH INTERNATIONAL SYMPOSIUM ON TEST AND MEASUREMENT, VOLS 1-6, 2009, : 1663 - 1666