A multiple attribute decision making for improving information security control assessment

Information security control assessment provides a comprehensive control analysis approach to assist an organization in measuring the effectiveness of its current and planned security controls.ISO/IEC 27005 is a risk management framework that can manage and treat risks in organizations.However, ISO...

وصف كامل

محفوظ في:
التفاصيل البيبلوغرافية
المؤلفون الرئيسيون: Al-Safwani, Nadher, Hassan, Suhaidi, Katuk, Norliza
التنسيق: مقال
اللغة:English
منشور في: Foundation of Computer Science 2014
الموضوعات:
الوصول للمادة أونلاين:http://repo.uum.edu.my/12243/1/pxc.pdf
http://repo.uum.edu.my/12243/
http://dx.doi.org/10.5120/15482-4222
الوسوم: إضافة وسم
لا توجد وسوم, كن أول من يضع وسما على هذه التسجيلة!
الوصف
الملخص:Information security control assessment provides a comprehensive control analysis approach to assist an organization in measuring the effectiveness of its current and planned security controls.ISO/IEC 27005 is a risk management framework that can manage and treat risks in organizations.However, ISO/IEC 27005 does not define a clear guideline on how to select and prioritize information security control despite the need for an efficient security analysis method.The ISO 27005 framework mostly depends on subjective judgment and qualitative approaches for security control analysis.This paper aims to improve the ISC analysis method by proposing the concept of multiple attribute decision making to provide clear guidelines in solving these issues.Order performance by similarity to ideal solution (TOPSIS) method was utilized to determine the critical vulnerable controls on the basis of different evaluation criteria.We argue that evaluating ISC by using TOPSIS leads to a cost-effective analysis and an efficient assessment in terms of testing and selecting ISCs in organizations.