USING FAULT TREE ANALYSIS WITH COBIT 5 RISK SCENARIOS

被引:0
|
作者
Modi, Shivani [1 ]
Butakov, Sergey [1 ]
Zavarsky, Pavol [1 ]
机构
[1] Concordia Univ Edmonton, Edmonton, AB, Canada
来源
2018 5TH INTERNATIONAL CONFERENCE ON CONTROL, DECISION AND INFORMATION TECHNOLOGIES (CODIT) | 2018年
关键词
IT governance; IT management; Processes; COBIT; 5; framework; Risk Scenarios; Fault Tree Analysis;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Information System Audit and Control Association (ISACA) proposed a preliminary idea on applying fault tree analysis to look at the root reasons for the IT risks outlined in COBIT 5 Risk Scenarios. So far, there was no prescriptive procedure/ methodology, which could be used to build the fault tree. This research looked into various methodologies for building the fault tree and proposed a new methodology, which could be used for analysis of risks outlined in COBIT 5 Risk Scenarios document. The methodology has been developed specific to COBIT 5 processes to build the fault tree, which, in turn, can help to outline the common factors that lead to failure of the processes subsequently leading to a risk. Fault tree analysis, could help to improve processes and suggest potential mitigation strategy to improve management/governance of IT. The paper also includes a sample of using the proposed methodology on one of the risk scenarios in order to calculate minimal cut set of IT management practices that organization needs to focus on to address specific risks.
引用
收藏
页码:385 / 390
页数:6
相关论文
共 50 条
  • [41] Analysis of the impact of a pandemic on the control of the process safety risk in major hazards industries using a Fault Tree Analysis approach
    Ashraf, Atif Mohammed
    Imran, Wafa
    Vechot, Luc
    JOURNAL OF LOSS PREVENTION IN THE PROCESS INDUSTRIES, 2022, 74
  • [42] Risk response budget allocation based on fault tree analysis and optimization
    Guan, Xin
    Servranckx, Tom
    Vanhoucke, Mario
    ANNALS OF OPERATIONS RESEARCH, 2024, 337 (02) : 523 - 564
  • [43] FALL RISK ASSESSMENT OF BRIDGE CONSTRUCTION USING BAYESIAN NETWORK TRANSFERRING FROM FAULT TREE ANALYSIS
    Chen, Tung-Tsan
    Wang, Chih-Hui
    JOURNAL OF CIVIL ENGINEERING AND MANAGEMENT, 2017, 23 (02) : 273 - 282
  • [44] Risk identification and analysis of subway foundation pit by using fault tree analysis method based on WBS-RBS
    Zhou Hong-bo
    Gao Wen-jie
    Cai Lai-bing
    Zhang Hui
    ROCK AND SOIL MECHANICS, 2009, 30 (09) : 2703 - 2707
  • [45] A fault tree analysis strategy using binary decision diagrams
    Reay, KA
    Andrews, JD
    RELIABILITY ENGINEERING & SYSTEM SAFETY, 2002, 78 (01) : 45 - 56
  • [46] Crane failure analysis using fault tree and fuzzy logic
    Wong, C.
    Hadipriono, F. C.
    Duane, J. W.
    Larew, R. E.
    Barker, D. H.
    Proceedings of The Seventh International Conference on the Application of Artificial Intelligence to Civil and Structural Engineering, 2003, : 57 - 58
  • [47] Probabilistic Transformer Fault Tree Analysis Using Bayesian Networks
    Cheim, Luiz
    Lin, Lan
    Dagnino, Aldo
    2014 IEEE PES T&D CONFERENCE AND EXPOSITION, 2014,
  • [48] A Fast and Efficient Fault Tree Analysis Using Approximate Computing
    Hashemi, Salar
    Hajisadeghi, Amir M.
    Zarandi, Hamid R.
    Pourmozafari, Saadat
    2019 15TH EUROPEAN DEPENDABLE COMPUTING CONFERENCE (EDCC 2019), 2019, : 39 - 46
  • [49] Development of IT Risk Management Framework Using COBIT 4.1, Implementation In IT Governance For Support Business Strategy
    Suroso, Jarot S.
    Rahadi, Bayu
    PROCEEDINGS OF 2017 INTERNATIONAL CONFERENCE ON EDUCATION AND MULTIMEDIA TECHNOLOGY (ICEMT 2017), 2017, : 92 - 96
  • [50] Risk Analysis of Equipment Failure through Failure Mode and Effect Analysis and Fault Tree Analysis
    Anand S. Relkar
    Journal of Failure Analysis and Prevention, 2021, 21 : 793 - 805