MULTI OBJECTIVE ANALYSIS ON INFWORMATION SECURITY RISK MANAGEMENT

Ritsuko Kawasaki · 2013

Management is required to understand all information security risks within an organization and to make decisions on which information security risks should be treated in what level by allocating how much amount of cost. However, such decision-making is not usually easy, because various controls for risk treatment must be selected and applied in suitable levels to the risks in order to appropriately maintain information security in an organization. Owing to the situation above, this paper provides a model which supports management decision-making. Multi-objective optimization method is applied to the model, because treating the selected risks includes multiple objectives depending on the characteristics of the risks. Organizations usually have an upper limit of cost for risk treatment and a lower limit of values of risks which can be accepted, thus, total cost, risk treatment and risk acceptance level are adapted in the model as parameters of constraints. Management is able to find one of the optimal solutions by using this model with adjusting the levels of risks, costs for risk treatment and a risk acceptance level.

Read the paper · More papers on PaperTik