A fuzzy approach to risk analysis in information systems
Vicente Cestero, Eloy
Jiménez Martín, Antonio
Mateos Caballero, Alfonso
Computer Science
Assets are interrelated in risk analysis methodologies for information systems promoted by international standards. This means that an attack on one asset can be propagated through the network and threaten an organization's most valuable assets. It is necessary to valuate all assets, the direct and indirect asset dependencies, as well as the probability of threats and the resulting asset degradation. These methodologies do not, however, consider uncertain valuations and use precise values on different scales, usually percentages. Linguistic terms are used by the experts to represent assets values, dependencies and frequency and asset degradation associated with possible threats. Computations are based on the trapezoidal fuzzy numbers associated with these linguistic terms.
ICORES 2013: proceedings of the 2nd International Conference on Operations Research and Enterprise Systems | Proceedings of the 2nd International Conference on Operations Research and Enterprise Systems | 16-18 Feb 2013 | Barcelona, España
