ISSEC: A Socio-technical Decision Support System for Information Security Planning

نویسندگان

  • Brian D. Fritz
  • Omar F. El-Gayar
چکیده

The traditional notion of information security, rooted in a solidly technical foundation, has within the past decade seen wide criticism within academia much of which has originated from the social sciences community as being narrow and technology-centric instead of holistic and organizational in its focus. As information security awareness encompasses an ever-greater scope of organizational dynamics, it becomes necessary for us to develop design methodologies and ultimately, systems, capable of dealing practically with the complex and multifaceted nature of the decision-making of information systems security which is entailed by the emerging notions of a new paradigm for security. To this end, we present an architecture which implements a web-based multi-user decision support system (DSS) driven by an operational security model within a qualitative multi-criteria framework that utilizes AHP as its inference engine. The system is then demonstrated in action, by addressing a multi-criteria security control selection decision.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Product Development Decision Support System Customer-Based

Quality Function Deployment (QFD) has been traditionally used as a planning tool primarily for product development and quality improvement. In this context, many people have used QFD for making decisions on how to prioritize critical product areas from a customer perspective. However, it is the position of the author that the QFD process can be viewed as a decision support system that would enc...

متن کامل

A Conceptual Model of Virtual Bank I.S. Security Meta-Policy from a Network Perspective

Despite a continued scholarly conversation on Information Systems Security (ISsec) policies and governance, a perspective that examines these issues at the organisational level has been generally neglected. This is of concern as managing ISsec is multi-level in nature for many organisations ranging from the individual level, such as BYOD (Bring Your Own Device) policies, to the strategic level,...

متن کامل

توسعه سامانه پشتیبانی تصمیم در راستای مدیریت مشارکتی و جامع آبخیز چهل چای استان گلستان

  Watershed is a complex and dynamic system and is considered to be a planning and management unit. It is important to consider all technical, social, economic, physical, ecological and administrative dimensions in the process of planning and management of watersheds. Given the fact that there are complex interactions among these dimensions, implementing integrated watershed assessment and mana...

متن کامل

Authorization models for secure information sharing: a survey and research agenda

This article presents a survey of authorization models and considers their 'fitness-for-purpose' in facilitating information sharing. Network-supported information sharing is an important technical capability that underpins collaboration in support of dynamic and unpredictable activities such as emergency response, national security, infrastructure protection, supply chain integration and emerg...

متن کامل

Potential site selection in ecotourism planning using spatial decision support tool

Northern areas of Pakistan have blessed with extremely beautiful natural landscapes, waterfalls, glaciated mountains, biodiversity rich valleys and forests and have extraordinary potential for ecotourism. Study is designed to propose potential sites for ecotourism in Kohistan, which is a least developed but biodiversity rich area of Pakistan.  Poor planning and mismanagement of tourism practice...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2005