首页> 外文期刊>International journal of dependable and trustworthy information systems >Evaluation of Information Security Controls in Organizations by Grey Relational Analysis
【24h】

Evaluation of Information Security Controls in Organizations by Grey Relational Analysis

机译:基于灰色关联分析的组织信息安全控制评价

获取原文
获取原文并翻译 | 示例
       

摘要

In an era where dependence of information systems is significantly high, the threat of incidents related to information security that could jeopardize the information held by is becoming critical. Alarming facts within the literature point to inadequacies in information security practices, particularly the evaluation and prioritiza-tion of information security controls in organizations. Research efforts have resulted in various methodologies developed to deal with the ISC assessment problem. A closer look at these traditional methodologies highlights various weaknesses that can prevent effective assessments of information security controls in organizations. This research proposes a novel approach using Grey Relational Analysis to quantify the importance of each information security control taking into account organizations 'goals and objectives. Through a case study, the approach is proven successful in providing a way for measuring the quality of information security controls based on multiple application-specific criteria.
机译:在当今信息系统高度依赖的时代,与信息安全相关的事件可能会危害所保存信息的威胁正变得至关重要。文献中令人震惊的事实表明信息安全实践的不足,尤其是组织中信息安全控制的评估和优先级。研究工作已导致开发出各种方法来处理ISC评估问题。仔细研究这些传统方法会发现各种弱点,这些弱点可能会阻止对组织中的信息安全控制进行有效的评估。这项研究提出了一种使用灰色关联分析的新方法,该方法考虑了组织的目标和目标来量化每种信息安全控制的重要性。通过案例研究,该方法被证明是成功的,它提供了一种基于多个特定于应用程序的标准来衡量信息安全控制质量的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号