Please use this identifier to cite or link to this item: https://hdl.handle.net/20.500.14365/3573
Title: A causal model for information security risk assessment
Authors: Kondakçı, Süleyman
Keywords: Risk modeling
Security analysis
Test methods and tools
Uncertainty inference
Analysis approach
Causal model
Causal relationships
Decision-making systems
Information security risk assessment
IT products
Probabilistic approaches
Qualitative method
Research topics
Risk modeling
Security analysis
Security assessment
Security certification
Security management
Software development projects
Test and evaluation
Test method
Uncertainty inference
Information systems
Quality control
Risk analysis
Risk assessment
Risk management
Risk perception
Security systems
Software design
Uncertainty analysis
Security of data
Abstract: This paper presents a probabilistic approach to encode causal relationships among various threat sources and victim systems in order to facilitate quantitative and relational security assessment of information systems. In addition to providing a simple risk analysis approach compared to qualitative methods, it is unique in that it makes no a priori assumptions regarding the test domain. Therefore, it applies equally well to a variety of information systems, software development projects, IT products, and other decision making systems. The entire framework proposes a unique concept to analyse dependence and causality within a network of interdependent assets. Security risk management is mostly considered by security certification authorities, test and evaluation facilities, and some organizations such as CC, CCITT, and ISACA. In order to invent new methods that can facilitate security management, we need to consider risk assessment as a major research topic for evaluation facilities. © 2010 IEEE.
Description: 2010 6th International Conference on Information Assurance and Security, IAS 2010 -- 23 August 2010 through 25 August 2010 -- Atlanta, GA -- 82434
URI: https://doi.org/10.1109/ISIAS.2010.5604039
https://hdl.handle.net/20.500.14365/3573
ISBN: 9.78142E+12
Appears in Collections:Scopus İndeksli Yayınlar Koleksiyonu / Scopus Indexed Publications Collection

Files in This Item:
File SizeFormat 
2665.pdf
  Restricted Access
394.4 kBAdobe PDFView/Open    Request a copy
Show full item record



CORE Recommender

SCOPUSTM   
Citations

13
checked on Nov 20, 2024

Page view(s)

64
checked on Nov 18, 2024

Download(s)

6
checked on Nov 18, 2024

Google ScholarTM

Check




Altmetric


Items in GCRIS Repository are protected by copyright, with all rights reserved, unless otherwise indicated.