An Information System Security Evaluation Model Based on AHP and GRAP

Xu Cuihua, Jiajun Lin · 2009

This paper presents an information system security evaluation model referring to Common criteria (CC). Analytic Hierarchy Process (AHP) and Grey Relational Analytic Process (GRAP) are applied to this model which combines the qualitative evaluation with the quantitative decision. AHP is used to obtain the indices' weights with respect to the final goal of the security evaluation. GRAP is adapted to analyze evaluation data to implement a quantitative integration evaluation. At last, a test case is given to illustrate the application and the effectiveness of this model.

Read the paper · More papers on PaperTik