Information security risk assessment model based on computing with words

Ескіз

Дата

2017

DOI

10.13164/mendel.2017.1.119

item.page.thesis.degree.name

item.page.thesis.degree.level

item.page.thesis.degree.discipline

item.page.thesis.degree.department

item.page.thesis.degree.grantor

item.page.thesis.degree.advisor

item.page.thesis.degree.committeeMember

Назва журналу

Номер ISSN

Назва тому

Видавець

Brno University of Technology

Анотація

The basis for company IT infrastructure security is information security risks assessment of IT services. The increased complexity, connectivity and rapid changes occurring in IT services make it impossible to apply traditional models of quantitative/qualitative risk assessment. Existing quantitative assessment models are time-consuming, at the same time, qualitative assessment models do not take into account the subjective expert assessments and the uncertainty of risk factors. This paper presents the new information security risk assessment model for IT services based on computing with words. The model methodology is based on OWASP risk rating methodology for web applications. To evaluate risk factors, it is proposed to use dictionary consisting of 16/32 granular terms (words). Problems of uncertainty in perceptual assessments of risk factors are taken into account using methods of the theory of discrete interval type-2 fuzzy sets and systems. © 2017 Brno University of Technology. All rights reserved.

Опис

Ключові слова

сomputing with words, discrete interval type-2 fuzzy set, information security, IT service, risk, risk assessment, risk factor

Бібліографічний опис

Tymchuk O. Information security risk assessment model based on computing with words / O.Tymchuk, M. Iepik, A. Sivyakov// Mendel.- 2017.-V.23,Is.1.-Pp.119-124

item.page.endorsement

item.page.review

item.page.supplemented

item.page.referenced