101. Developing an Information Security Risk Taxonomy and an Assessment Model using Fuzzy Petri Nets
- Author
-
S. Vijayakumar Bharathi and Dhanya Pramod
- Subjects
Information Systems and Management ,business.industry ,Computer science ,Strategy and Management ,02 engineering and technology ,Information security ,Computer Science Applications ,020204 information systems ,Taxonomy (general) ,0202 electrical engineering, electronic engineering, information engineering ,020201 artificial intelligence & image processing ,Software engineering ,business ,Fuzzy petri nets ,Information Systems - Abstract
In the digital era, organization-wide information security risk assessment has gained importance because it can impact businesses in many ways. In this article, the authors propose a model to assess the information security risk using Fuzzy Petri Nets (FPN). Deeply rooted in the OCTAVE framework, this research presents a taxonomy of risk practice areas and risk factors. The authors apply the constituents of the taxonomy to risk assessment through a well-defined FPN model. The primary motive of the article is to extend the usability of FPNs to newer and less explored domains like audit and evaluation of information security risks. The unique contribution of this article is the definition and development of a comprehensive and measurable model of risk assessment and quantification. The model can also serve as a tool to capture the risk perception of the respondents for validating the criticality of risk and facilitate the top management to invest in information security control eco-system judiciously.
- Published
- 2018
- Full Text
- View/download PDF