Applying Fuzzy Expert System to Information Security Risk Assessment - A Case Study on an Attendance System

被引:0
|
作者
Chang, Li-Yun [1 ]
Lee, Zne-Jung [2 ]
机构
[1] Huafan Univ, Dept Mech Engn, Hfu Taipei, Taiwan
[2] Huafan Univ, Dept Mangement Informat Syst, Taipei, Taiwan
来源
2013 INTERNATIONAL CONFERENCE ON FUZZY THEORY AND ITS APPLICATIONS (IFUZZY 2013) | 2013年
关键词
ISO; 27001; Information Security; Risk Assessment; Fuzzy Expert System;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
As computer becomes popular and internet advances rapidly, information application systems are used extensively in organizations. Various information application systems such as attendance systems, accounting systems, and statistical systems have already replaced manual operations. In such a drastic change, the information security issue encountered by organizations becomes increasingly significant. This study adopts an attendance system of a governmental organization to explore the information security issue. The risk assessment of the attendance system mainly focuses on the assessments of confidentiality, integrity and availability. Weak points of the attendance system and threats to the outside are also included in the scope of consideration. This study adopts the ISO/IEC 27001 information security management system standard and ISO/IEC27005:2008 Information technology Security techniques - Information security risk management to explore the risk assessment method of the attendance system and establish a set of fuzzy expert systems to measure the value at risk. In the meantime, a recommended acceptable value at risk is provided for facilitating and assisting decision makers through practical aspects and fuzzy expert systems and used as a reference for selecting an acceptable value at risk.
引用
收藏
页码:346 / 351
页数:6
相关论文
共 50 条
  • [31] Expert and fuzzy systems application for information security risks assessment of information and telecommunication systems
    Kushch, S. M.
    Shutovskyi, V. O.
    VISNYK NTUU KPI SERIIA-RADIOTEKHNIKA RADIOAPARATOBUDUVANNIA, 2012, (50): : 114 - 120
  • [32] Credit Risk Assessment of Bank Customers using DEMATEL and Fuzzy Expert System
    Nosratabadi, Hamid Eslami
    Pourdarab, Sanaz
    Nadali, Ahmad
    ECONOMICS AND FINANCE RESEARCH, 2011, 4 : 255 - +
  • [33] Information Security Assessment On Court Tracking Information System: A Case Study from Mataram District Court
    Auliani, Aishananda S.
    Candiwan
    2021 IEEE 12TH ANNUAL UBIQUITOUS COMPUTING, ELECTRONICS & MOBILE COMMUNICATION CONFERENCE (UEMCON), 2021, : 226 - 230
  • [34] Risk assessment of Information Security Management System inGovernment Organizations in Iran
    Fayez, Samane
    Nazeri, HodaHosseinZade
    BagherKiaroodi, Mohammad
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON COMPUTER, NETWORKS AND COMMUNICATION ENGINEERING (ICCNCE 2013), 2013, 30 : 77 - 79
  • [35] Research on the Quantitative Methods of Classified Information System Security Risk Assessment
    Zhang, Kang
    Shao, Liping
    LISS 2014, 2015, : 571 - 575
  • [36] Risk-based test case prioritization using a fuzzy expert system
    Hettiarachchi, Charitha
    Do, Hyunsook
    Choi, Byoungju
    INFORMATION AND SOFTWARE TECHNOLOGY, 2016, 69 : 1 - 15
  • [37] A Case Study on Risk Management of Enterprise Information Security
    Huang, Rengen
    Zhu, Zhen
    2015 2nd International Conference on Creative Education (ICCE 2015), Pt 2, 2015, 11 : 201 - 208
  • [38] Risk Assessment Model of Information Security for Transportation Industry System Based on Risk Matrix
    Zhao Xiangmo
    Dai Ming
    Ren Shuai
    Li Luyao
    Duan Zongtao
    APPLIED MATHEMATICS & INFORMATION SCIENCES, 2014, 8 (03): : 1301 - 1306
  • [39] Research on Risk Assessment of Information System Based on Fuzzy Neural Network
    Zhu, Guangliang
    Wang, Yuanbao
    PROCEEDINGS OF THE INTERNATIONAL ACADEMIC CONFERENCE ON FRONTIERS IN SOCIAL SCIENCES AND MANAGEMENT INNOVATION (IAFSM 2018), 2018, 62 : 50 - 55
  • [40] Information System Security Risk Assessment Based on IDAV Multi-Criteria Decision Model
    Yang, Jinning
    Han, Jiazhen
    Zhang, Xiuyan
    PROCEEDINGS OF 2018 12TH IEEE INTERNATIONAL CONFERENCE ON ANTI-COUNTERFEITING, SECURITY, AND IDENTIFICATION (ASID), 2018, : 121 - 127