...
首页> 外文期刊>Information systems and e-business management >Ranking information security controls by using fuzzy analytic hierarchy process
【24h】

Ranking information security controls by using fuzzy analytic hierarchy process

机译:使用模糊层次分析法对信息安全控制进行排名

获取原文
获取原文并翻译 | 示例

摘要

Information security can be achieved by implementing a set of appropriate controls. However, identifying and selecting the most effective information security controls in organizations have been major challenges for years. Although many studies have been done to address these challenges, there is still lack of research to rank these controls. In this study, a fuzzy Analytic Hierarchy Process was used to prioritize and select effective managerial domains and control objectives in information security controls. In this research, the process of implementing ISO 27001 Information Security in National Iranian Oil Products Distribution Company was selected. According to results, the access control, information systems acquisition, development and maintenance have the highest priorities among the information security controls in managerial domains. On the other hand, the business continuity management and asset management have the lowest priorities among the studied information security controls. Furthermore, it was found that among 39 control objectives, the user access management and third party service delivery management have the highest and lowest priorities, respectively.
机译:可以通过实施一组适当的控件来实现信息安全。但是,多年来,确定和选择组织中最有效的信息安全控制已成为主要挑战。尽管已经进行了许多研究来应对这些挑战,但是仍然缺乏研究对这些控制进行排名。在这项研究中,使用模糊的层次分析法对信息安全控制中的有效管理域和控制目标进行优先级排序和选择。在这项研究中,选择了在伊朗国家石油产品经销公司中实施ISO 27001信息安全的过程。根据结果​​,访问控制,信息系统的获取,开发和维护在管理领域的信息安全控制中具有最高优先级。另一方面,在研究的信息安全控制中,业务连续性管理和资产管理的优先级最低。此外,发现在39个控制目标中,用户访问管理和第三方服务交付管理分别具有最高和最低优先级。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号