Developing Cost And Risk Assessment Tool For Hybrid Approach In Information Security Risk Analysis

Identifying potential information security risk is a challenging task which is due to modernization and new technologies which introduce possible threats to various type of digital system. Many studies proved that the current risk analysis tools are not able to analyze the threats well. It is a must...

Full description

Saved in:
Bibliographic Details
Main Author: Mohd Zabawi, Ahmed Yaser
Format: Thesis
Language:English
English
Published: 2019
Subjects:
Online Access:http://eprints.utem.edu.my/id/eprint/24697/1/Developing%20Cost%20And%20Risk%20Assessment%20Tool%20For%20Hybrid%20Approach%20In%20Information%20Security%20Risk%20Analysis.pdf
http://eprints.utem.edu.my/id/eprint/24697/2/Developing%20Cost%20And%20Risk%20Assessment%20Tool%20For%20Hybrid%20Approach%20In%20Information%20Security%20Risk%20Analysis.pdf
http://eprints.utem.edu.my/id/eprint/24697/
https://plh.utem.edu.my/cgi-bin/koha/opac-detail.pl?biblionumber=116960
Tags: Add Tag
No Tags, Be the first to tag this record!
id my.utem.eprints.24697
record_format eprints
spelling my.utem.eprints.246972021-10-05T11:52:28Z http://eprints.utem.edu.my/id/eprint/24697/ Developing Cost And Risk Assessment Tool For Hybrid Approach In Information Security Risk Analysis Mohd Zabawi, Ahmed Yaser QA Mathematics QA76 Computer software Identifying potential information security risk is a challenging task which is due to modernization and new technologies which introduce possible threats to various type of digital system. Many studies proved that the current risk analysis tools are not able to analyze the threats well. It is a must for an organization to choose the suitable methods for better analysis. There are four key elements that need to be considered which are security threats, business impact, security measures and their cost. There are many existing risk analysis tools that were developed such as ISRAM and CORAS that have same purpose, which is to reduce the risk of causing a threat, however these tools used different approach to analyses the risk. The main focus of this study is to develop a new risk analysis tool based on hybrid approach and compare it with the existing tool. The proposed risk analysis tool is known as Cost and Risk Assessment tool (CARA) aims to trace the threats by combining both qualitative and quantitative methods, where both of these methods have their respective advantages for analyzing the information. CARA used Monte Carlo method where it applied probability theory in cost estimation. The results from the study show that the qualitative information could increase the dimension of risk factors and produce better accuracy in the analysis. 2019 Thesis NonPeerReviewed text en http://eprints.utem.edu.my/id/eprint/24697/1/Developing%20Cost%20And%20Risk%20Assessment%20Tool%20For%20Hybrid%20Approach%20In%20Information%20Security%20Risk%20Analysis.pdf text en http://eprints.utem.edu.my/id/eprint/24697/2/Developing%20Cost%20And%20Risk%20Assessment%20Tool%20For%20Hybrid%20Approach%20In%20Information%20Security%20Risk%20Analysis.pdf Mohd Zabawi, Ahmed Yaser (2019) Developing Cost And Risk Assessment Tool For Hybrid Approach In Information Security Risk Analysis. Masters thesis, Universiti Teknikal Malaysia Melaka. https://plh.utem.edu.my/cgi-bin/koha/opac-detail.pl?biblionumber=116960
institution Universiti Teknikal Malaysia Melaka
building UTEM Library
collection Institutional Repository
continent Asia
country Malaysia
content_provider Universiti Teknikal Malaysia Melaka
content_source UTEM Institutional Repository
url_provider http://eprints.utem.edu.my/
language English
English
topic QA Mathematics
QA76 Computer software
spellingShingle QA Mathematics
QA76 Computer software
Mohd Zabawi, Ahmed Yaser
Developing Cost And Risk Assessment Tool For Hybrid Approach In Information Security Risk Analysis
description Identifying potential information security risk is a challenging task which is due to modernization and new technologies which introduce possible threats to various type of digital system. Many studies proved that the current risk analysis tools are not able to analyze the threats well. It is a must for an organization to choose the suitable methods for better analysis. There are four key elements that need to be considered which are security threats, business impact, security measures and their cost. There are many existing risk analysis tools that were developed such as ISRAM and CORAS that have same purpose, which is to reduce the risk of causing a threat, however these tools used different approach to analyses the risk. The main focus of this study is to develop a new risk analysis tool based on hybrid approach and compare it with the existing tool. The proposed risk analysis tool is known as Cost and Risk Assessment tool (CARA) aims to trace the threats by combining both qualitative and quantitative methods, where both of these methods have their respective advantages for analyzing the information. CARA used Monte Carlo method where it applied probability theory in cost estimation. The results from the study show that the qualitative information could increase the dimension of risk factors and produce better accuracy in the analysis.
format Thesis
author Mohd Zabawi, Ahmed Yaser
author_facet Mohd Zabawi, Ahmed Yaser
author_sort Mohd Zabawi, Ahmed Yaser
title Developing Cost And Risk Assessment Tool For Hybrid Approach In Information Security Risk Analysis
title_short Developing Cost And Risk Assessment Tool For Hybrid Approach In Information Security Risk Analysis
title_full Developing Cost And Risk Assessment Tool For Hybrid Approach In Information Security Risk Analysis
title_fullStr Developing Cost And Risk Assessment Tool For Hybrid Approach In Information Security Risk Analysis
title_full_unstemmed Developing Cost And Risk Assessment Tool For Hybrid Approach In Information Security Risk Analysis
title_sort developing cost and risk assessment tool for hybrid approach in information security risk analysis
publishDate 2019
url http://eprints.utem.edu.my/id/eprint/24697/1/Developing%20Cost%20And%20Risk%20Assessment%20Tool%20For%20Hybrid%20Approach%20In%20Information%20Security%20Risk%20Analysis.pdf
http://eprints.utem.edu.my/id/eprint/24697/2/Developing%20Cost%20And%20Risk%20Assessment%20Tool%20For%20Hybrid%20Approach%20In%20Information%20Security%20Risk%20Analysis.pdf
http://eprints.utem.edu.my/id/eprint/24697/
https://plh.utem.edu.my/cgi-bin/koha/opac-detail.pl?biblionumber=116960
_version_ 1713203454298554368
score 13.211869