Application of Fuzzy Logic in the Process of Information Security Risk Assessment

被引:0
作者
Kokles, Mojmir [1 ]
Filanova, Jana [1 ]
Korcek, Frantisek [1 ]
机构
[1] Univ Econ Bratislava, Fac Business Management, Dept Informat Management, Bratislava, Slovakia
来源
INNOVATION MANAGEMENT AND EDUCATION EXCELLENCE VISION 2020: FROM REGIONAL DEVELOPMENT SUSTAINABILITY TO GLOBAL ECONOMIC GROWTH, VOLS I - VI | 2016年
关键词
Risk assessment; fuzzy logic; information security; threat;
D O I
暂无
中图分类号
C [社会科学总论];
学科分类号
03 ; 0303 ;
摘要
Risk assessment is a demanding process of information security risk management. Organizations often do not employ sufficiently experienced and qualified employees in handling information security risks. This paper focuses on a fuzzy logic application in the process of information security risk assessment based on a matrix method of the ISO/IEC 27005 standard and regulations according to the Cyber Security Regulation No. 316/2014 introduced in the Czech Republic. The method and the regulations are combined to form a risk assessment matrix which is processed in the QtFuzzyLite software. The result is a fuzzy logic system designed for organizations that need to simplify and specify risk assessment where likelihood of threat occurrence, threat consequence value and asset vulnerability level are vague and difficult to estimate. These variables directly affect the information security risk value. The paper discusses the possibility of utilizing the fuzzy logic system as a decision support tool in Slovak organizations.
引用
收藏
页码:1078 / 1088
页数:11
相关论文
共 31 条
[1]  
Ahmad A., 2013, P 11 AUSTR INF SEC M, DOI [10.4225/75/57b56667cd8-5, DOI 10.4225/75/57B56667CD8-5]
[2]  
Al Amro S, 2012, STUD COMPUT INTELL, V394, P35
[3]   Information Security Management in Saudi Arabian Organizations [J].
Alsaif, Maryam ;
Aljaafari, Nura ;
Khan, Abdul Raouf .
10TH INTERNATIONAL CONFERENCE ON FUTURE NETWORKS AND COMMUNICATIONS (FNC 2015) / THE 12TH INTERNATIONAL CONFERENCE ON MOBILE SYSTEMS AND PERVASIVE COMPUTING (MOBISPC 2015) AFFILIATED WORKSHOPS, 2015, 56 :213-216
[4]  
[Anonymous], 2013, Global Journal of Flexible Systems Management, DOI [DOI 10.1007/S40171-013-0047-4, 10.1007/s40171-013-0047-4]
[5]  
[Anonymous], 2011, ADV DECISION MAKING
[6]  
[Anonymous], 270052011 ISOIEC
[7]  
[Anonymous], 2013, FUZZYLITE FUZZY LOGI
[8]   Fuzzy Assessment of Health Information System Users' Security Awareness [J].
Aydin, Ozlem Muge ;
Chouseinoglou, Oumout .
JOURNAL OF MEDICAL SYSTEMS, 2013, 37 (06)
[9]  
Benova M., 2015, MAN INF BEZP MAL STR, P14
[10]  
Bolek V., 2015, MAN INF BEZP MAL STR, P22