首页    期刊浏览 2024年09月19日 星期四
登录注册

文章基本信息

  • 标题:Statistics Based Information Security Risk Management Methodology
  • 本地全文:下载
  • 作者:Upasna Saluja ; Dato Norbik Bashah Idris
  • 期刊名称:International Journal of Computer Science and Network Security
  • 印刷版ISSN:1738-7906
  • 出版年度:2015
  • 卷号:15
  • 期号:10
  • 页码:117-123
  • 出版社:International Journal of Computer Science and Network Security
  • 摘要:On the one hand organizations are confronted with increasing sophistication, severity and number of threats and on the other hand organizations are getting even more dependent on IT which is rapidly changing with introduction of new technologies such as outsourcing, cloud, mobility and social media. Traditional risk management methodologies are proving ineffective in addressing these risks and in keeping pace with the complexity and dynamically changing IT environment. In such a situation, there is a need for an effective Risk Management methodology that can address diverse kinds of risks and leverage data from within the organization to analyze risks scientifically rather than through primitive and subjective methods based on rudimentary calculations. This paper presents a methodology which addresses these issues. Adapting from Medical and Finance fields, this methodology has generated information security risk indicators for the IT environment. These Risk Indicators are observed over a period of time leading to data driven factual process that inspires greater confidence among stakeholders. Drawing inspiration once again from the fields of medicine and finance, this methodology has conducted risk analysis statistically using second generation statistical technique Structured Equation Modeling (SEM). The methodology provides a prediction model that predicts future risks scientifically. The Relative Risk Benchmark that this methodology has developed improves decision making when organizations need to prioritize risks, by providing a scientifically generated contribution of each risk towards the negative impact that organization faces. The path breaking information security risk management methodology cuts costs by enabling organizations to focus efforts and resources only on the risks that matter. This methodology inspires greater confidence in the results of the risk assessment since risks are assessed scientifically thus removing assessor bias while reducing the dependence of risk assessments on expert judgment.
  • 关键词:Information Security Risk Assessment; Qualitative Risk Assessment; Quantitative; Statistical.
国家哲学社会科学文献中心版权所有