完整後設資料紀錄
DC 欄位語言
dc.contributor.authorLo, Chi-Chunen_US
dc.contributor.authorChen, Wan-Jiaen_US
dc.date.accessioned2014-12-08T15:20:55Z-
dc.date.available2014-12-08T15:20:55Z-
dc.date.issued2012-01-01en_US
dc.identifier.issn0957-4174en_US
dc.identifier.urihttp://dx.doi.org/10.1016/j.eswa.2011.07.015en_US
dc.identifier.urihttp://hdl.handle.net/11536/14893-
dc.description.abstractRisk assessment is the core process of information security risk management. Organizations use risk assessment to determine the risks within an information system and provide sufficient means to reduce these risks. In this paper, a hybrid procedure for evaluating risk levels of information security under various security controls is proposed. First, this procedure applies the Decision Making Trial and Evaluation Laboratory (DEMATEL) approach to construct interrelations among security control areas. Secondly, likelihood ratings are obtained through the Analytic Network Process (ANP) method: as a result, the proposed procedure can detect the interdependences and feedback between security control families and function in real world situations. Lastly, the Fuzzy Linguistic Quantifiers-guided Maximum Entropy Order-Weighted averaging (FLQ-MEOWA) operator is used to aggregate impact values assessed by experts, applied to diminish the influence of extreme evaluations such as personal views and drastic perspectives. A real world application in a branch office of the health insurance institute in Taiwan was examined to verify the proposed procedure. By analyzing the acquired data, we confirm the proposed procedure certainly detects the influential factors among security control areas. This procedure also evaluates risk levels more accurately by coping with the interdependencies among security control families and determines the information systems safeguards required for better security, therefore enabling organizations to accomplish their missions. Crown Copyright (C) 2011 Published by Elsevier Ltd. All rights reserved.en_US
dc.language.isoen_USen_US
dc.subjectInformation securityen_US
dc.subjectRisk assessmenten_US
dc.subjectDecision Making Trial and Evaluation Laboratory (DEMATEL)en_US
dc.subjectAnalytic Network Process (ANP)en_US
dc.subjectOrder Weighted Averaging (OWA) operatoren_US
dc.subjectFuzzy linguistic quantifiersen_US
dc.subjectMaximum entropy methoden_US
dc.titleA hybrid information security risk assessment procedure considering interdependences between controlsen_US
dc.typeArticleen_US
dc.identifier.doi10.1016/j.eswa.2011.07.015en_US
dc.identifier.journalEXPERT SYSTEMS WITH APPLICATIONSen_US
dc.citation.volume39en_US
dc.citation.issue1en_US
dc.citation.spage247en_US
dc.citation.epage257en_US
dc.contributor.department資訊管理與財務金融系 註:原資管所+財金所zh_TW
dc.contributor.departmentDepartment of Information Management and Financeen_US
dc.identifier.wosnumberWOS:000296214900029-
dc.citation.woscount6-
顯示於類別:期刊論文


文件中的檔案:

  1. 000296214900029.pdf

若為 zip 檔案,請下載檔案解壓縮後,用瀏覽器開啟資料夾中的 index.html 瀏覽全文。