정보보호를 위한 다속성 위협지수 - 시뮬레이션과 AHP 접근방법
Multi-Attribute Threat Index for Information Security:Simulation and AHP Approach
- 한국IT서비스학회
- 한국IT서비스학회지
- 한국IT서비스학회지 제7권 제1호
-
2008.03117 - 130 (14 pages)
- 54
Multi-attribute risk assessments provide a useful framework for systematic quantitative risk assessment that the security manager can use to prioritize security requirements and threats. In the first step, the security managers identify the four significant outcome attributes(lost revenue, lost productivity, lost customer, and recovery cost). Next, the security manager estimates the frequency and severity(three points estimates for outcome attribute values) for each threat and rank the outcome attributes according to AHP(Analytic Hierarchy Process). Finally, we generate the threat index by using multi-attribute function and make sensitivity analysis with simulation package(Crystal Ball). In this paper, we show how multi-attribute risk analysis techniques from the field of security risk management can be used by security managers to prioritize their organization’s threats and their security requirements, eventually they can derive threat index. This threat index can help security managers to decide whether their security investment is consistent with the expected risks. In addition, sensitivity analysis allows the security manager to explore the estimates to understand how they affect the selection.
Abstract<BR>1. 서론<BR>2. 기존 연구<BR>3. 연구모형<BR>4. 분석절차<BR>5. 사례연구<BR>6. 결론<BR>참고문헌<BR>저자소개<BR>
(0)
(0)