Subjectivity Reduction of Qualitative Approach in Information Security Risk Analysis

Message:
Article Type:
Research/Original Article (دارای رتبه معتبر)
Abstract:

Qualitative information security risk assessments are somewhat subjective and the high degree of subjectivity associated with the perception of risk means that management is often skeptical of risk analysis results, and is unwilling to make important decisions based on that. Besides, the process of information security risk assessment is quite complex and rife with uncertainty and without taken into account the uncertainty of information security risk assessment the results can be misleading. Therefore, in this paper, the Fuzzy Multi Criteria Group Decision Making (FMCGDM) model is proposed to address the above-mentioned problems. The focus group method used to identify risk parameters and the Delphi method is used to construct a hierarchy for risk parameters. The findings of this research would be useful for the information security department to become more capable in analyzing the InfoSec risks and reducing the consequences of subjective assessment. A case study involving an actual information security risk management project was presented to illustrate the use of the proposed model. Computational results demonstrated the efficiency and effectiveness of the presented model that can assist InfoSec risk analyst to better evaluate InfoSec risk.

Language:
English
Published:
Journal of System Management, Volume:8 Issue: 1, Winter 2022
Pages:
145 to 166
magiran.com/p2459957  
دانلود و مطالعه متن این مقاله با یکی از روشهای زیر امکان پذیر است:
اشتراک شخصی
با عضویت و پرداخت آنلاین حق اشتراک یک‌ساله به مبلغ 1,390,000ريال می‌توانید 70 عنوان مطلب دانلود کنید!
اشتراک سازمانی
به کتابخانه دانشگاه یا محل کار خود پیشنهاد کنید تا اشتراک سازمانی این پایگاه را برای دسترسی نامحدود همه کاربران به متن مطالب تهیه نمایند!
توجه!
  • حق عضویت دریافتی صرف حمایت از نشریات عضو و نگهداری، تکمیل و توسعه مگیران می‌شود.
  • پرداخت حق اشتراک و دانلود مقالات اجازه بازنشر آن در سایر رسانه‌های چاپی و دیجیتال را به کاربر نمی‌دهد.
In order to view content subscription is required

Personal subscription
Subscribe magiran.com for 70 € euros via PayPal and download 70 articles during a year.
Organization subscription
Please contact us to subscribe your university or library for unlimited access!