首页> 外文会议>Intelligent Systems Design and Applications, 2009. ISDA '09 >Method to Select Effective Risk Mitigation Controls Using Fuzzy Outranking
【24h】

Method to Select Effective Risk Mitigation Controls Using Fuzzy Outranking

机译:基于模糊排序的有效风险缓解控制选择方法

获取原文

摘要

In an information-oriented society, the security of information related assets in organizations is one of chief concerns and the importance of security evaluation system to grasp their security level is increasing. We also consider that the magnitude of risk to information assets is highly dependent on the scales, forms, treat etc. of the organization, and should be evaluated by reflecting these characteristics. Standing on this concept, we adopted OCTAVESM as the basic information system and already proposed two fuzzy-based methods integrated in it. One is to determine the set of critical assets using fuzzy decision making methodology by multi-participants. The other is to calculate the degree of risks along with the given threat path as a crisp value using fuzzy inference mechanism and so on. In this paper, we propose a system for selecting some mitigation controls considered to be more effective than others as an application of fuzzy outranking.
机译:在信息社会中,组织中与信息有关的资产的安全性是主要关注的问题之一,安全评估系统对于掌握其安全性的重要性正在日益提高。我们还认为,对信息资产的风险大小在很大程度上取决于组织的规模,形式,待遇等,因此应通过反映这些特征来进行评估。站在这个概念上,我们采用OCTAVESM作为基本信息系统,并已经提出了两种基于模糊的集成方法。一种是由多参与者使用模糊决策方法确定关键资产的集合。另一种方法是使用模糊推理机制等将风险程度与给定的威胁路径一起计算为清晰的值。在本文中,我们提出了一种用于选择一些缓解控制系统的系统,该系统被认为比模糊控制更有效。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号