Modelling of Fuzzy Expert System for an Assessment of Security Information Management System UIS (University Information System)

被引:5
|
作者
Sikman, Ljilja [1 ]
Latinovic, Tihomir [1 ]
Sarajlic, Nermin [2 ]
机构
[1] Univ Banja Luka, Banja Luka, Bosnia & Herceg
[2] Univ Tuzla, Tuzla, Bosnia & Herceg
来源
TEHNICKI VJESNIK-TECHNICAL GAZETTE | 2022年 / 29卷 / 01期
关键词
fuzzy; expert systems; ISO; IEC; 27001; ISMS (information security management system); risk; LOGIC;
D O I
10.17559/TV-20200721154801
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Several methodologies based on the international standard ISO/IEC 27001 have been developed for modelling information security management systems within higher education. This paper transformed the ISO/IEC 27001 standard into a questionnaire, which was sent digitally to about 100 universities in Bosnia and Herzegovina, and to the EU, Norway and the USA. The questions are arranged by levels, and the levels have their numerical weights, derived from individual questions in the levels themselves. Otherwise, the questions are asked with Yes or No and thus are reduced to binary variables. The rules necessary for the functioning of the system have been calculated. The fuzzy logic method represents a new approach to the problems of managing complex systems, which is very difficult to describe with a certain mathematical model, as well as in systems with a large number of inputs and outputs where there are unclear interactions. Risk assessment is a major part of the ISMS process. Traditional risk calculation models are based on the application of probability and classical set theory. Here, we have converted the risk assessment into a system rating of 5 to 10 numerically or from five to ten descriptively. We perform fuzzy optimization by finding the values of the input parameters of a complex simulated system, which results in the desired output. We use the fuzzy logic controller to execute fuzzy inference rules from the fuzzy rule database in determining congestion parameters, obtaining warning information and appropriate action. Simulating the situation of an advanced system that evaluates the protection quality of such a system with fuzzy logic, we use MATLAB. The paper combines the original Visual Basic programming language and MATLAB's Fuzzy Toolbox, to solve the complex problem of assessing compliance with the ISO/IEC 27001 standard, as one of the main standards for information systems security modelling. University information systems were used, but it is also applicable to all other information systems. The evaluation has been done for several universities and it has been proven that the system evaluates correctly, but these universities must not be publicly named. There was no such approach in the use of fuzzy logic and on such systems, and that is the originality of this work.
引用
收藏
页码:60 / 65
页数:6
相关论文
共 50 条
  • [41] Fuzzy Rule-Based Expert System for Assessment Severity of Asthma
    Maryam Zolnoori
    Mohammad Hossein Fazel Zarandi
    Mostafa Moin
    Shahram Teimorian
    Journal of Medical Systems, 2012, 36 : 1707 - 1717
  • [42] Risk Analysis of Information System Security Based on the Evidence Distance
    LingHu, Jinhua
    Pan, Ping
    Du, Yaoyao
    PROCEEDINGS OF THE 11TH INTERNATIONAL CONFERENCE ON MODELLING, IDENTIFICATION AND CONTROL (ICMIC2019), 2020, 582 : 347 - 358
  • [43] Modelling of FMS control policy: AIS-based fuzzy expert system
    Prakash A.
    Deshmukh S.G.
    International Journal of Industrial and Systems Engineering, 2011, 8 (01) : 38 - 60
  • [44] A pattern-based method for establishing a cloud-specific information security management system: Establishing information security management systems for clouds considering security, privacy, and legal compliance
    Beckers K.
    Côté I.
    Faßbender S.
    Heisel M.
    Hofbauer S.
    Requirements Engineering, 2013, 18 (4) : 343 - 395
  • [45] A pattern-based method for establishing a cloud-specific information security management system
    Beckers, Kristian
    Cote, Isabelle
    Fassbender, Stephan
    Heisel, Maritta
    Hofbauer, Stefan
    REQUIREMENTS ENGINEERING, 2013, 18 (04) : 343 - 395
  • [46] Research on and application of IEC 61850 modelling and CIM extension for protection relay information management system
    Hu S.
    Li L.
    Qi Z.
    Lin Q.
    Dai X.
    Xiong H.
    Dianli Xitong Zidonghua/Automation of Electric Power Systems, 2016, 40 (06): : 119 - 125
  • [47] A semantic fuzzy expert system for a fuzzy balanced scorecard
    Bobillo, Fernando
    Delgado, Miguel
    Gomez-Romero, Juan
    Lopez, Enrique
    EXPERT SYSTEMS WITH APPLICATIONS, 2009, 36 (01) : 423 - 433
  • [48] A process-based quality management information system
    Chin, S
    Kim, K
    Kim, YS
    AUTOMATION IN CONSTRUCTION, 2004, 13 (02) : 241 - 259
  • [49] Health Information System for the Comprehensive Management of a Sleep Clinic
    Acosta, Edgar Daniel
    Rivas-Echeverria, Francklin
    Gonzalez, Solange
    Rivas-Echeverria, Carlos
    PROCEEDINGS OF THE 8TH WSEAS INTERNATIONAL CONFERENCE ON APPLIED COMPUTER AND APPLIED COMPUTATIONAL SCIENCE: APPLIED COMPUTER AND APPLIED COMPUTATIONAL SCIENCE, 2009, : 61 - +
  • [50] Transformer condition analyzing expert system using fuzzy neural system
    Nemeth, Balint
    Laboncz, Szilvia
    Kiss, Istvan
    Csepes, Gusztav
    CONFERENCE RECORD OF THE 2010 IEEE INTERNATIONAL SYMPOSIUM ON ELECTRICAL INSULATION (ISEI), 2010,