Applying Fuzzy Expert System to Information Security Risk Assessment - A Case Study on an Attendance System

被引:0
|
作者
Chang, Li-Yun [1 ]
Lee, Zne-Jung [2 ]
机构
[1] Huafan Univ, Dept Mech Engn, Hfu Taipei, Taiwan
[2] Huafan Univ, Dept Mangement Informat Syst, Taipei, Taiwan
来源
2013 INTERNATIONAL CONFERENCE ON FUZZY THEORY AND ITS APPLICATIONS (IFUZZY 2013) | 2013年
关键词
ISO; 27001; Information Security; Risk Assessment; Fuzzy Expert System;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
As computer becomes popular and internet advances rapidly, information application systems are used extensively in organizations. Various information application systems such as attendance systems, accounting systems, and statistical systems have already replaced manual operations. In such a drastic change, the information security issue encountered by organizations becomes increasingly significant. This study adopts an attendance system of a governmental organization to explore the information security issue. The risk assessment of the attendance system mainly focuses on the assessments of confidentiality, integrity and availability. Weak points of the attendance system and threats to the outside are also included in the scope of consideration. This study adopts the ISO/IEC 27001 information security management system standard and ISO/IEC27005:2008 Information technology Security techniques - Information security risk management to explore the risk assessment method of the attendance system and establish a set of fuzzy expert systems to measure the value at risk. In the meantime, a recommended acceptable value at risk is provided for facilitating and assisting decision makers through practical aspects and fuzzy expert systems and used as a reference for selecting an acceptable value at risk.
引用
收藏
页码:346 / 351
页数:6
相关论文
共 50 条
  • [41] Risk Assessment of Enterprises Information Security Based on Fuzzy Set and Entropy Weight
    Wang, Yi
    Yuan, Jia-hang
    Zhang, Jian-ye
    Li, Cun-bin
    4TH INTERNATIONAL CONFERENCE ON ECONOMICS AND MANAGEMENT (ICEM), 2017, : 337 - 342
  • [42] Filling the SIEM-system nodes with the technique for calculating objective assessment to improve the reliability of expert evaluation in the technique of the information systems security risk calculation
    Abdenov, A. Z.
    Trushin, V. A.
    2016 DYNAMICS OF SYSTEMS, MECHANISMS AND MACHINES (DYNAMICS), 2016,
  • [43] Information systems security risk assessment on improved fuzzy AHP
    Wu, Xiaoping
    Fu, Yu
    Wang, Jiasheng
    2009 ISECS INTERNATIONAL COLLOQUIUM ON COMPUTING, COMMUNICATION, CONTROL, AND MANAGEMENT, VOL IV, 2009, : 365 - 369
  • [44] Risk Assessment for Information Security Based on Fuzzy Membership Matrix
    Bai, Yan
    Yao, Zhong
    Li, Hong
    Zhang, Yong-Qiang
    NETWORK COMPUTING AND INFORMATION SECURITY, 2012, 345 : 547 - +
  • [45] Expert system with Fuzzy logic for protecting Scientific Information Resources
    Rakhmatullaev, Marat
    Normatov, Sherbek
    2020 IEEE 14TH INTERNATIONAL CONFERENCE ON APPLICATION OF INFORMATION AND COMMUNICATION TECHNOLOGIES (AICT2020), 2020,
  • [46] Compliance Risk Assessment Measures of Financial Information Security using System Dynamics
    Kim, Ae Chan
    Lee, Su Mi
    Lee, Dong Hoon
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2012, 6 (04): : 191 - 200
  • [47] FUZZY-LOGICAL EXPERT SYSTEM FOR ASSESSING THE FINANCIAL SECURITY OF ENTERPRISES
    Myachin, Valentin
    Yudina, Olena
    Myroshnychenko, Oleksandr
    BALTIC JOURNAL OF ECONOMIC STUDIES, 2021, 7 (04) : 123 - 135
  • [48] Hypertension Diagnosis: A Comparative Study using Fuzzy Expert System and Neuro Fuzzy System
    Das, Sujit
    Ghosh, Pijush Kanti
    Kar, Samarjit
    2013 IEEE INTERNATIONAL CONFERENCE ON FUZZY SYSTEMS (FUZZ - IEEE 2013), 2013,
  • [49] A Software Defined Network information security risk assessment based on Pythagorean fuzzy sets
    Deb, Raktim
    Roy, Sudipta
    EXPERT SYSTEMS WITH APPLICATIONS, 2021, 183
  • [50] Maturity Assessment of Business/IT Alignment Using Fuzzy Expert System
    Nadali, Ahmad
    Pourdarab, Sanaz
    Mazloumi, Aliakbar
    Nosratabadi, Hamid Eslami
    DIGITAL ENTERPRISE AND INFORMATION SYSTEMS, 2011, 194 : 724 - +