Security risk factors: ANP model for risk management decision making

Helena Brozova, Jan Rydval, Libor Sup, Moufida Sadok, Peter Bednar

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Information is a valuable asset supporting management decisions and business operations within the enterprise. Consequently, securing the company critical information assets from sophisticated insider threats and outsider attacks is essential to ensure business continuity and compliance with regulatory frameworks. Security risk management is the process that identifies threats and vulnerabilities of an enterprise information system, evaluates the likelihood of their occurrence and estimates their potential business impact. It is a continuous process that allows cost effectiveness of implemented security controls and provides a dynamic set of tools to monitor the security level of the information system. Given the uncertainty and complexity of security risks analyses, the identification of risk factors as well as the estimation of their business impact require tools for assessment of risk with multi-value scales according to different stakeholders' point of view. Therefore, the purpose of this paper is to model risk factors using semantic network to develop the decision network and the Analytical Network Process (ANP) to evaluate factors of complex problems taking into consideration quantitative and qualitative data. As a decision support technique ANP also measures the dependency among risk factors related to the elicitation of individual judgement.
Original languageEnglish
Title of host publication33rd International Conference on Mathematical Methods in Economics MME 2015: Conference Proceedings
EditorsDavid Martinčík, Jarmilla Ircingová , Petr Janeček
Place of PublicationCheb
PublisherUniversity of West Bohemia
Pages74-79
Number of pages6
ISBN (Print)9788026105398
Publication statusPublished - 11 Sept 2015
Event33rd International Conference on Mathematical Methods in Economics - Cheb, Czech Republic
Duration: 9 Sept 201511 Sept 2015

Conference

Conference33rd International Conference on Mathematical Methods in Economics
Country/TerritoryCzech Republic
CityCheb
Period9/09/1511/09/15

Keywords

  • information security
  • risk factors
  • semantic networks
  • analytical network process
  • multi-criteria decision making

Fingerprint

Dive into the research topics of 'Security risk factors: ANP model for risk management decision making'. Together they form a unique fingerprint.

Cite this