IRMA-International.org: Creator of Knowledge
Information Resources Management Association
Advancing the Concepts & Practices of Information Resources Management in Modern Organizations

A Weighted Monte Carlo Simulation Approach to Risk Assessment of Information Security Management System

A Weighted Monte Carlo Simulation Approach to Risk Assessment of Information Security Management System
View Sample PDF
Author(s): Seyed Mojtaba Hosseini Bamakan (School of Economics and Management, Key Laboratory of Big Data Mining and Knowledge Management, University of Chinese Academy of Sciences, Beijing, China)and Mohammad Dehghanimohammadabadi (Department of Mechanical and Industrial Engineering, Northeastern University, Boston, MA, USA)
Copyright: 2015
Volume: 11
Issue: 4
Pages: 16
Source title: International Journal of Enterprise Information Systems (IJEIS)
Editor(s)-in-Chief: Gianluigi Viscusi (Linköping University, Sweden)
DOI: 10.4018/IJEIS.2015100103

Purchase

View A Weighted Monte Carlo Simulation Approach to Risk Assessment of Information Security Management System on the publisher's website for pricing and purchasing information.

Abstract

In recent decades, information has become a critical asset to various organizations, hence identifying and preventing the loss of information are becoming competitive advantages for firms. Many international standards have been developed to help organizations to maintain their competitiveness by applying risk assessment and information security management system and keep risk level as low as possible. This study aims to propose a new quantitative risk analysis and assessment methodology which is based on AHP and Monte Carlo simulation. In this method, AHP is used to create favorable weights for Confidentiality, Integrity and Availability (CIA) as security characteristic of any information asset. To deal with the uncertain nature of vulnerabilities and threats, Monte Carlo simulation is utilized to handle the stochastic nature of risk assessment by taking into account multiple judges' opinions. The proposed methodology is suitable for organizations that require risk analysis to implement ISO/IEC 27001 standard.

Related Content

Yujong Hwang, Hui Lin, Donghee Shin. © 2023. 17 pages.
Yin Xu, Sam Dzever, Guoqin Zhao. © 2023. 23 pages.
Mohamed Abdalla Nour. © 2023. 29 pages.
Godwin Banafo Akrong, Yunfei Shao, Ebenezer Owusu. © 2022. 41 pages.
Yigal David, Elad Harison. © 2022. 20 pages.
Mohmed Y. Mohmed Al-Sabaawi, Bassam A. Alyouzbaky. © 2022. 22 pages.
Normalini Md Kassim, Wan Normila Mohamad, Nor Hazlina Hashim. © 2022. 21 pages.
Body Bottom