Information security risk analysis model considering costs and factors relevance

Zhao Gan · Shenyang Gongye Daxue xuebao · 2015

Aiming at the information security risk assessment,a risk analysis model considering relevance among risk factors and controls with costs was proposed. Compared with the present research results,the proposed method not only fully considers the interrelation between the threats and vulnerabilities,but also concentrates on the influence of controls on such risk factors as threats and vulnerabilities,and simultaneously pays attention to the costs of risk treatment controls,which provides more objective and accurate method for risk assessment and effective strategy for control selection and optimization. The results of case analysis showthat the proposed risk analysis model based on multi-objective decision making can effectively quantize the interrelations among the risk assessment factors,provide the objective and accurate priority orders for control optimization according to the efficiency and rational costs of the controls,improve the accuracy of risk assessment,and thus provide the scientific decision making evidence for the information security risk management.

Read the paper · More papers on PaperTik