首页> 美国卫生研究院文献>Sensors (Basel Switzerland) >Prioritization of Information Security Controls through Fuzzy AHP for Cloud Computing Networks and Wireless Sensor Networks
【2h】

Prioritization of Information Security Controls through Fuzzy AHP for Cloud Computing Networks and Wireless Sensor Networks

机译:通过模糊AHP为云计算网络和无线传感器网络确定信息安全控制的优先级

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

With the advent of cloud computing and wireless sensor networks, the number of cyberattacks has rapidly increased. Therefore, the proportionate security of networks has become a challenge for organizations. Information security advisors of organizations face difficult and complex decisions in the evaluation and selection of information security controls that permit the defense of their resources and assets. Information security controls must be selected based on an appropriate level of security. However, their selection needs intensive investigation regarding vulnerabilities, risks, and threats prevailing in the organization as well as consideration of the implementation, mitigation, and budgetary constraints of the organization. The goal of this paper was to improve the information security control analysis method by proposing a formalized approach, i.e., fuzzy Analytical Hierarchy Process (AHP). This approach was used to prioritize and select the most relevant set of information security controls to satisfy the information security requirements of an organization. We argue that the prioritization of the information security controls using fuzzy AHP leads to an efficient and cost-effective assessment and evaluation of information security controls for an organization in order to select the most appropriate ones. The proposed formalized approach and prioritization processes are based on International Organization for Standardization and the International Electrotechnical Commission (ISO/IEC) 27001:2013. But in practice, organizations may apply this approach to any information security baseline manual.
机译:随着云计算和无线传感器网络的出现,网络攻击的数量迅速增加。因此,网络的成比例的安全性已成为组织的挑战。组织的信息安全顾问在评估和选择允许保护其资源和资产的信息安全控制方面面临困难而复杂的决策。必须基于适当的安全级别来选择信息安全控件。但是,他们的选择需要对组织中普遍存在的漏洞,风险和威胁以及组织的实施,缓解和预算限制进行深入调查。本文的目的是通过提出一种形式化的方法,即模糊层次分析法(AHP),来改进信息安全控制分析方法。此方法用于确定优先级并选择最相关的信息安全控制集,以满足组织的信息安全要求。我们认为,使用模糊层次分析法对信息安全控制进行优先排序会导致对组织的信息安全控制进行有效,经济高效的评估和评估,从而选择最合适的控制方法。提议的形式化方法和优先级排序过程基于国际标准化组织和国际电工委员会(ISO / IEC)27001:2013。但是实际上,组织可以将此方法应用于任何信息安全基准手册。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号