Abstract

In this paper, a probabilistic estimation model for information systems security (ISS) risk analysis based on evidential reasoning approach is presented. The modeling process consists of four phases: specification of the model structure, estimation of evidence strength, computation of beliefs on assertions, and ISS risk monitoring and analysis. Using the changes of strength of evidences obtained in the organization's information systems, the model can continually estimate the probability of risk, and identify the sources of risk. The significance of the work is that the model provides objective and visible support for ISS risk analysis. Keywords-information systems security; risk analysis; probabilistic estimation; evidential reasoning

Full Text
Paper version not known

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call

Disclaimer: All third-party content on this website/platform is and will remain the property of their respective owners and is provided on "as is" basis without any warranties, express or implied. Use of third-party content does not indicate any affiliation, sponsorship with or endorsement by them. Any references to third-party content is to identify the corresponding services and shall be considered fair use under The CopyrightLaw.