{"title":"Information security risk assessment based on two stages decision model with grey synthetic measure","authors":"Hongsheng Luo, Yongjun Shen, Guidong Zhang, Liangliang Huang","doi":"10.1109/ICSESS.2015.7339176","DOIUrl":null,"url":null,"abstract":"To solve the fuzziness and uncertainty from many aspects on information security risk assessment, this paper proposes the information security risk assessment approach based on two stages decision model with grey synthetic measure. Firstly, the assessment criteria weights are determined by means of the combination of Delphi method and the adjacent criterion comparison method, and the grades of assessment results are determined; secondly, unity grey clustering coefficients or decision coefficients with synthetic measure are computed by grey clustering theory; at last, the grey classes of objects are determined and objects are squenced by risk values. Through case study, this method solves the uncertainty in parameter values and other factors, reduces the subjectivity of assessment process, and provides a new thought to information security risk assessment.","PeriodicalId":335871,"journal":{"name":"2015 6th IEEE International Conference on Software Engineering and Service Science (ICSESS)","volume":"25 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2015-11-30","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"7","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2015 6th IEEE International Conference on Software Engineering and Service Science (ICSESS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICSESS.2015.7339176","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 7
Abstract
To solve the fuzziness and uncertainty from many aspects on information security risk assessment, this paper proposes the information security risk assessment approach based on two stages decision model with grey synthetic measure. Firstly, the assessment criteria weights are determined by means of the combination of Delphi method and the adjacent criterion comparison method, and the grades of assessment results are determined; secondly, unity grey clustering coefficients or decision coefficients with synthetic measure are computed by grey clustering theory; at last, the grey classes of objects are determined and objects are squenced by risk values. Through case study, this method solves the uncertainty in parameter values and other factors, reduces the subjectivity of assessment process, and provides a new thought to information security risk assessment.