Information Security Risk Assessment Model Based on Computing with Words

Loading...
Thumbnail Image

Authors

Tymchuk, Oleg
Iepik, Maryna
Sivyakov, Artyom

Advisor

Referee

Mark

Journal Title

Journal ISSN

Volume Title

Publisher

Institute of Automation and Computer Science, Brno University of Technology

ORCID

Altmetrics

Abstract

The basis for company IT infrastructure security is information security risks assessment of IT services. The increased complexity, connectivity and rapid changes occurring in IT services make it impossible to apply traditional models of quantitative/qualitative risk assessment. Existing quantitative assessment models are time-consuming, at the same time, qualitative assessment models do not take into account the subjective expert assessments and the uncertainty of risk factors. This paper presents the new information security risk assessment model for IT services based on computing with words. The model methodology is based on OWASP risk rating methodology for web applications. To evaluate risk factors, it is proposed to use dictionary consisting of 16/32 granular terms (words). Problems of uncertainty in perceptual assessments of risk factors are taken into account using methods of the theory of discrete interval type-2 fuzzy sets and systems.

Description

Citation

Mendel. 2017 vol. 23, č. 1, s. 119-124. ISSN 1803-3814
https://mendel-journal.org/index.php/mendel/article/view/62

Document type

Peer-reviewed

Document version

Published version

Date of access to the full text

Language of document

en

Study field

Comittee

Date of acceptance

Defence

Result of defence

Collections

Endorsement

Review

Supplemented By

Referenced By

Citace PRO