Information security management measurement model based on AHP

Yang Yi-xian · Journal of Liaoning Technical University · 2008

n view of the problem about how to build an appropriate risk model to measure and estimate the risk of information system.a method of measurement modeling combined qualitative analysis with quantitative computation is proposed.From the point of practice view of information security management measurement(ISMM),the model,factors,indices,means and implementation flow are also given in detail.With the implementation process of ISMM,measurement factors and indices for the concrete application of information system can be determined by system structure of ISO27002 and the analytic hierarchy process(AHP).According to the different requirements of hierarchy protection,measurement model is used to estimate the security condition of information system and decision rules are introduced to realize the overall evaluation of security management.This method is applied into information security management test and evaluation,which provides a new method for information system risk measurement.

Read the paper · More papers on PaperTik