An Information Systems Security Risk Assessment Model Under the Dempster-Shafer Theory of Belief Functions

نویسندگان

  • Lili Sun
  • Rajendra P. Srivastava
  • Theodore J. Mock
چکیده

This study develops an alternative methodology for the risk analysis of information systems security (ISS). an evidential reasoning approach under the Dempster-Shafer theory of belief functions. The approach has the following important dimensions. First, the evidential reasoning approach provides a rigorous, structured manner to incorporate relevant ISS risk factors, related countermeasures, and their interrelationships when estimating ISS risk. Second, the methodology employs lhe belief function definition of risk—that is, ISS risk is the plausibility of ISS failures. The proposed approach has other appealing features, such as facilitating costbenefit analyses to help promote efficient ISS risk management. The paper elaborates the theoretical concepts and provides operational guidance for implementing the method. The method is illustrated using a hypothetical example from the perspective of management and a real-world example from the perspective of external assurance providers. Sensitivity analyses are performed to evaluate the impact of important parameters on the model's results.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

An Information Systems Security Risk Assessment Model under Dempster-Shafer Theory of Belief Functions

This study develops an alternative methodology for the risk analysis of information systems security (ISS), an evidential reasoning approach under the Dempster-Shafer theory of belief functions. The approach has the following important dimensions. First, the evidential reasoning approach provides a rigorous, structured manner to incorporate relevant ISS risk factors, related counter measures an...

متن کامل

belief function and the transferable belief model

Beliefs are the result of uncertainty. Sometimes uncertainty is because of a random process and sometimes the result of lack of information. In the past, the only solution in situations of uncertainty has been the probability theory. But the past few decades, various theories of other variables and systems are put forward for the systems with no adequate and accurate information. One of these a...

متن کامل

Risk and Reliability Formulas for Systems Security Under Dempster-Shafer Theory of Belief Functions

This paper develops comprehensive formulas for assessing the risk and reliability of “Systems Security” under Dempster-Shafer theory of belief functions using the Trust Services framework as proposed by American Institute of Certified Public Accountants (AICPA) and Canadian Institute of Chartered Accountants (CICA). In addition, we discuss how these formulas can be used for planning and evaluat...

متن کامل

A novel risk-based analysis for the production system under epistemic uncertainty

Risk analysis of production system, while the actual and appropriate data is not available, will cause wrong system parameters prediction and wrong decision making. In uncertainty condition, there are no appropriate measures for decision making. In epistemic uncertainty, we are confronted by the lack of data. Therefore, in calculating the system risk, we encounter vagueness that we have to use ...

متن کامل

Designing a Home Security System using Sensor Data Fusion with DST and DSMT Methods

Today due to the importance and necessity of implementing security systems in homes and other buildings, systems with higher certainty, lower cost and with sensor fusion methods are more attractive, as an applicable and high performance methods for the researchers. In this paper, the application of Dempster-Shafer evidential theory and also the newer, more general one Dezert-Smarandache theory ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • J. of Management Information Systems

دوره 22  شماره 

صفحات  -

تاریخ انتشار 2006