Research on the risk assessment of information system based on grey fuzzy evaluation theory
Hua Jiang, Zhenxing Cui · 2009
As the most valuable resource, information has become a key factor in deciding the levels of national productivity and economic growth. But there are lots of risks in the implementation. Risk assessment is an effective approach to evaluate security state of information system. In this paper a model of information system risk assessment based on its characters of incompleteness and ambiguity is presented. Using fuzzy mathematics, grey system theory and meta-synthesis methods from qualitative to quantitative methods, this model measures the risk grades by gray fuzzy algorithm. And then, with the help of the sorting matrix, the risk grades can be rectified. Finally, the study of a case shows that the model is effective to assess the risk of information system. This method provides an effective way to help managers take specific measures to reduce risks and achieve success as soon as possible.