A Novel Approach for Optimizing Governance, Risk management and Compliance for Enterprise Information security using DEMATEL and FoM

被引:9
|
作者
Ramalingam, Dharmalingam [1 ]
Arun, Shivasankarappa [2 ]
Anbazhagan, Neelamegam [3 ]
机构
[1] Majan Univ Coll, Fac Informat Technol, Muscat, Oman
[2] Middle East Coll, Dept Planning & Dev, Muscat, Oman
[3] Alagappa Univ, Dept Math, Karaikkudi, Tamil Nadu, India
关键词
IT-GRC optimization; Mathematical model for Optimizing IT-GRC; DEMATEL method for IT-GRC optimization; DEMATEL and FoM method for IT-GRC optimization; a Hybrid method for IT-GRC optimization; ANP;
D O I
10.1016/j.procs.2018.07.197
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Information technology Governance, Risk management and Compliance (IT-GRC) are critical in the contemporary business environment since most of the business processes rely on information technology. However, studies indicate that off-the-shelf IT-GRC products are unsuitable for measuring the effectiveness and efficiency of IT-GRC controls. This article proposes a novel approach of measuring effectiveness and efficiency of IT-GRC controls by using the Decision Making Trial and Evaluation Laboratory (DEMATEL) methodology and arriving at the Figure of Merit (FoM) to find the optimal value of effectiveness and efficiency. The proposed method quantifies the input values by calculating the relative influence and cause of the controls. The efficiency and effectiveness are analysed based on the key metrics such as performance, the strength of security controls, ease of use and cost. The proposed method has been applied to various scenarios with varying controls for evaluation and then the optimal value (Figure of Merit) is found by an iterative method. This method can be extended to any type of IT security control standards and frameworks such as ISO 27001, COBIT 5, ITIL and PCI-DSS. (C) 2018 The Authors. Published by Elsevier Ltd.
引用
收藏
页码:365 / 370
页数:6
相关论文
共 50 条
  • [31] An integrated conceptual model for information system security risk management supported by enterprise architecture management
    Mayer, Nicolas
    Aubert, Jocelyn
    Grandry, Eric
    Feltus, Christophe
    Goettelmann, Elio
    Wieringa, Roel
    SOFTWARE AND SYSTEMS MODELING, 2019, 18 (03): : 2285 - 2312
  • [32] An integrated conceptual model for information system security risk management supported by enterprise architecture management
    Nicolas Mayer
    Jocelyn Aubert
    Eric Grandry
    Christophe Feltus
    Elio Goettelmann
    Roel Wieringa
    Software & Systems Modeling, 2019, 18 : 2285 - 2312
  • [33] AN EMPIRICAL STUDY INTO INFORMATION SECURITY GOVERNANCE FOCUS AREAS AND THEIR EFFECTS ON RISK MANAGEMENT
    Yaokumah, Winfred
    Brown, Steven
    2014 ANNUAL GLOBAL ONLINE CONFERENCE ON INFORMATION AND COMPUTER TECHNOLOGY, 2014, : 42 - 49
  • [34] Patterns for Understanding Control Requirements for Information Systems for Governance, Risk Management, and Compliance (GRC IS)
    Wiesche, Manuel
    Berwing, Carolin
    Schermann, Michael
    Krcmar, Helmut
    ADVANCED INFORMATION SYSTEMS ENGINEERING WORKSHOPS, 2011, 83 : 208 - +
  • [35] Method Engineering Approach to the Adoption of Information Technology Governance, Risk and Compliance in Swiss Hospitals
    Krey, Mike
    Furnell, Steven
    Harriehausen, Bettina
    Knoll, Matthias
    PROCEEDINGS OF THE 6TH EUROPEAN CONFERENCE ON INFORMATION MANAGEMENT AND EVALUATION, 2012, : 408 - 417
  • [36] INFORMATION SECURITY RISK MANAGEMENT: AN INTELLIGENCE- DRIVEN APPROACH
    Webb, Jeb
    Maynard, Sean
    Ahmad, Atif
    Shanks, Graeme
    AUSTRALASIAN JOURNAL OF INFORMATION SYSTEMS, 2014, 18 (03) : 391 - 404
  • [37] Anchor: A novel approach to cardiovascular health by optimizing risk management
    Courtney-Cox, Krista
    McInerney, Michele
    Humphrey, Jacklynn
    Cox, Jafna
    CANADIAN JOURNAL OF CARDIOLOGY, 2007, 23 : 319C - 320C
  • [38] Enterprise Financial Risk Identification and Information Security Management and Control in Big Data Environment
    Wei, Ran
    Yao, Sheng
    MOBILE INFORMATION SYSTEMS, 2021, 2021
  • [39] Compliance Risk Assessment Measures of Financial Information Security using System Dynamics
    Kim, Ae Chan
    Lee, Su Mi
    Lee, Dong Hoon
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2012, 6 (04): : 191 - 200
  • [40] An Integrated Conceptual Model for Information System Security Risk Management and Enterprise Architecture Management Based on TOGAF
    Mayer, Nicolas
    Aubert, Jocelyn
    Grandry, Eric
    Feltus, Christophe
    PRACTICE OF ENTERPRISE MODELING, POEM 2016, 2016, 267 : 353 - 361