CYCROct 11, 2013

Multicriteria Evaluation and Sensitivity Analysis on Information Security

arXiv:1310.3312v133 citations
Originality Synthesis-oriented
AI Analysis

This addresses the problem of information security evaluation for managers, but it appears incremental as it builds on existing AHP methods with a ternary adaptation.

The study tackled the lack of well-defined models for information security evaluation at management levels by proposing a decision analysis model based on Ternary Analytic Hierarchy Process (T-AHP) to aid managers in strategic evaluations, and found that sensitivity analysis showed significant consistency in the final evaluations.

Information security plays a significant role in recent information society. Increasing number and impact of cyber attacks on information assets have resulted the increasing awareness among managers that attack on information is actually attack on organization itself. Unfortunately, particular model for information security evaluation for management levels is still not well defined. In this study, decision analysis based on Ternary Analytic Hierarchy Process (T-AHP) is proposed as a novel model to aid managers who responsible in making strategic evaluation related to information security issues. In addition, sensitivity analysis is applied to extend our analysis by using several "what-if" scenarios in order to measure the consistency of the final evaluation. Finally, we conclude that the final evaluation made by managers has a significant consistency shown by sensitivity analysis results.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes