Applying Fuzzy Expert System to Information Security Risk Assessment - A Case Study on an Attendance System

被引:0
|
作者
Chang, Li-Yun [1 ]
Lee, Zne-Jung [2 ]
机构
[1] Huafan Univ, Dept Mech Engn, Hfu Taipei, Taiwan
[2] Huafan Univ, Dept Mangement Informat Syst, Taipei, Taiwan
关键词
ISO; 27001; Information Security; Risk Assessment; Fuzzy Expert System;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
As computer becomes popular and internet advances rapidly, information application systems are used extensively in organizations. Various information application systems such as attendance systems, accounting systems, and statistical systems have already replaced manual operations. In such a drastic change, the information security issue encountered by organizations becomes increasingly significant. This study adopts an attendance system of a governmental organization to explore the information security issue. The risk assessment of the attendance system mainly focuses on the assessments of confidentiality, integrity and availability. Weak points of the attendance system and threats to the outside are also included in the scope of consideration. This study adopts the ISO/IEC 27001 information security management system standard and ISO/IEC27005:2008 Information technology Security techniques - Information security risk management to explore the risk assessment method of the attendance system and establish a set of fuzzy expert systems to measure the value at risk. In the meantime, a recommended acceptable value at risk is provided for facilitating and assisting decision makers through practical aspects and fuzzy expert systems and used as a reference for selecting an acceptable value at risk.
引用
收藏
页码:346 / 351
页数:6
相关论文
共 50 条
  • [21] A Novel Security Risk Assessment Model for Information System
    Lv, Huiying
    2ND IEEE INTERNATIONAL CONFERENCE ON ADVANCED COMPUTER CONTROL (ICACC 2010), VOL. 4, 2010, : 282 - 287
  • [22] Security risk assessment: Applying the concepts of fuzzy logic
    Bajpai, Shailendra
    Sachdeva, Anish
    Gupta, J. P.
    JOURNAL OF HAZARDOUS MATERIALS, 2010, 173 (1-3) : 258 - 264
  • [23] Electric power information system security risk assessment based on fuzzy rating multilevel analysis
    Wang, Chen
    2013 2ND INTERNATIONAL SYMPOSIUM ON INSTRUMENTATION AND MEASUREMENT, SENSOR NETWORK AND AUTOMATION (IMSNA), 2013, : 771 - 774
  • [24] MEDEX: Applying fuzzy logic to a meteorological expert system
    Kuciauskas, AP
    Brody, LR
    Hadjimichael, M
    Bankert, RL
    Tag, PM
    Peak, JE
    FIRST CONFERENCE ON ARTIFICIAL INTELLIGENCE, 1998, : 68 - 74
  • [25] Information Security Risk Assessment for the Malaysian Aeronautical Information Management System
    Alwi, Alfian
    Ariffin, Khairul Akram Zainol
    PROCEEDINGS OF THE 2018 CYBER RESILIENCE CONFERENCE (CRC), 2018,
  • [26] Fuzzy Logic Driven Expert System for the Assessment of Software Projects Risk
    Ibraigheeth, Mohammad Ahmad
    Fadzli, Syed Abdullah
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2019, 10 (02) : 153 - 158
  • [27] Expert System for Assessing the Efficiency of Information Security
    Erulanova, Aizhan
    Soltan, Gulzhan
    Baidildina, Aizhan
    Amangeldina, Marzhan
    Aset, Askhat
    2020 7TH INTERNATIONAL CONFERENCE ON ELECTRICAL AND ELECTRONICS ENGINEERING (ICEEE 2020), 2020, : 355 - 359
  • [28] Information system security assessment
    Mrazik, Frantisek
    Kollar, Jan
    2008 6TH INTERNATIONAL SYMPOSIUM ON APPLIED MACHINE INTELLIGENCE AND INFORMATICS, 2008, : 234 - 236
  • [29] Researches on a Fuzzy Synthetic Assessment Model of the Information System Security Risks
    Zhu Wenhui
    Guo Junqiang
    Dai Feng
    2009 INTERNATIONAL FORUM ON INFORMATION TECHNOLOGY AND APPLICATIONS, VOL 2, PROCEEDINGS, 2009, : 347 - +
  • [30] the Discussion of Information System Security Risk Assessment Course Teaching
    Pan Ping
    Yang Ping
    NATIONAL TEACHING SEMINAR ON CRYPTOGRAPHY AND INFORMATION SECURITY (2010NTS-CIS), PROCEEDINGS, 2010, : 139 - 142