USING FAULT TREE ANALYSIS WITH COBIT 5 RISK SCENARIOS

被引:0
|
作者
Modi, Shivani [1 ]
Butakov, Sergey [1 ]
Zavarsky, Pavol [1 ]
机构
[1] Concordia Univ Edmonton, Edmonton, AB, Canada
来源
2018 5TH INTERNATIONAL CONFERENCE ON CONTROL, DECISION AND INFORMATION TECHNOLOGIES (CODIT) | 2018年
关键词
IT governance; IT management; Processes; COBIT; 5; framework; Risk Scenarios; Fault Tree Analysis;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Information System Audit and Control Association (ISACA) proposed a preliminary idea on applying fault tree analysis to look at the root reasons for the IT risks outlined in COBIT 5 Risk Scenarios. So far, there was no prescriptive procedure/ methodology, which could be used to build the fault tree. This research looked into various methodologies for building the fault tree and proposed a new methodology, which could be used for analysis of risks outlined in COBIT 5 Risk Scenarios document. The methodology has been developed specific to COBIT 5 processes to build the fault tree, which, in turn, can help to outline the common factors that lead to failure of the processes subsequently leading to a risk. Fault tree analysis, could help to improve processes and suggest potential mitigation strategy to improve management/governance of IT. The paper also includes a sample of using the proposed methodology on one of the risk scenarios in order to calculate minimal cut set of IT management practices that organization needs to focus on to address specific risks.
引用
收藏
页码:385 / 390
页数:6
相关论文
共 50 条
  • [31] A new fault tree analysis method: Fuzzy dynamic fault tree analysis
    Nowa metoda analizy drzewa uszkodzeń: Rozmyta analiza dynamicznego drzewa uszkodzeń
    Huang, H.-Z. (hzhuang@uestc.edu.cn), 2012, Polish Academy of Sciences Branch Lublin (14)
  • [32] Risk Management Framework With COBIT 5 And Risk Management Framework for Cloud Computing Integration
    Khrisna, Akbar
    Harlili
    2014 INTERNATIONAL CONFERENCE OF ADVANCED INFORMATICS: CONCEPT, THEORY AND APPLICATION (ICAICTA), 2014, : 103 - 108
  • [33] A Safety Analysis Method Using Fault Tree Analysis and Petri Nets
    Reza, Hassan
    Pimple, Malvika
    Krishna, Varun
    Hilde, Jared
    PROCEEDINGS OF THE 2009 SIXTH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY: NEW GENERATIONS, VOLS 1-3, 2009, : 1089 - 1094
  • [34] Assessing IT Governance Processes Using a COBIT5 Model
    Cadete, Goncalo Rodrigues
    da Silva, Miguel Mira
    INFORMATION SYSTEMS, EMCIS 2017, 2017, 299 : 447 - 460
  • [35] Risk management of financial holding company based on fault tree analysis
    Wen Yuechun
    Wang Jingting
    PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON RISK MANAGEMENT & GLOBAL E-BUSINESS, VOLS I AND II, 2009, : 370 - 374
  • [36] Risk Analysis for Train Collisions Using Fault Tree Analysis: Case Study of the Hanoi Urban Mass Rapid Transit
    Thi Hoai An Nguyen
    Jochen Trinckauf
    Tuan Anh Luong
    Thanh Tung Truong
    Urban Rail Transit, 2022, 8 : 246 - 266
  • [37] Assesing Manipulation Risk in TV Commercials Based On Fault Tree Analysis
    Lup, Patricia S.
    Prostean, Gabriela I.
    VISION 2020: SUSTAINABLE ECONOMIC DEVELOPMENT AND APPLICATION OF INNOVATION MANAGEMENT, 2018, : 5722 - 5732
  • [38] Fault Tree Analysis-based Risk Quantification of Smart Homes
    Wongvises, Chanoksuda
    Khurat, Assadarat
    Fall, Doudou
    Kashihara, Shigeru
    2017 2ND INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY (INCIT), 2017, : 213 - 218
  • [39] Risk Analysis for Train Collisions Using Fault Tree Analysis: Case Study of the Hanoi Urban Mass Rapid Transit
    Thi Hoai An Nguyen
    Trinckauf, Jochen
    Tuan Anh Luong
    Thanh Tung Truong
    URBAN RAIL TRANSIT, 2022, 8 (3-4) : 246 - 266
  • [40] Oil and gas leakage risk analysis of underground storage caverns in bedded salt rock using fault tree analysis
    Jing Wen-jun
    Yang Chun-he
    Chen Feng
    Ji Wen-dong
    Xu Yu-long
    ROCK AND SOIL MECHANICS, 2012, 33 (06) : 1869 - 1875