Application of Multicriteria Methods for Improvement of Information Security Metrics

Author:

Abdiraman Aliya1,Goranin Nikolaj2ORCID,Balevicius Simas2,Nurusheva Assel1,Tumasonienė Inga3ORCID

Affiliation:

1. Department of Information Security, Faculty of Information Technologies, L.N. Gumilyov Eurasian National University, KZ-010008 Astana, Kazakhstan

2. Department of Information Systems, Faculty of Fundamental Sciences, Vilnius Gediminas Technical University, LT-08412 Vilnius, Lithuania

3. Department of Information Technologies, Faculty of Fundamental Sciences, Vilnius Gediminas Technical University, LT-08412 Vilnius, Lithuania

Abstract

Metrics are a set of numbers that are used to obtain information about the operation of a process or system. In our case, metrics are used to assess the level of information security of information and communication infrastructure facilities. Metrics in the field of information security are used to quantify the possibility of damage due to unauthorized hacking of an information system, which make it possible to assess the cyber sustainability of the system. The purpose of the paper is to improve information security metrics using multicriteria decision–making methods (MCDM). This is achieved by proposing aggregated information security metrics and evaluating the effectiveness of their application. Classical information security metrics consist of one size or one variable. We obtained the total value by adding at least two different metrics and evaluating the weighting factors that determine their importance. This is what we call aggregated or multicriteria metrics of information security. Consequently, MCDM methods are applied to compile aggregated metrics of information security. These are derived from expert judgement and are proposed for the three management domains of the ISO/IEC 27001 information security standard. The proposed methods for improving cyber sustainability metrics are also relevant to information security metrics. Using AHP, WASPAS and Fuzzy TOPSIS methods to solve the problem, the weights of classical metrics are calculated and three aggregated metrics are proposed. As a result, to confirm the fulfilment of the task of improving information security metrics, a verification experiment is conducted, during which aggregated and classical information security metrics are compared. The experiment shows that the use of aggregated metrics can be a more convenient and faster process and higher intelligibility is also achieved.

Publisher

MDPI AG

Subject

Management, Monitoring, Policy and Law,Renewable Energy, Sustainability and the Environment,Geography, Planning and Development,Building and Construction

Reference51 articles.

1. (2015). The Law “On Informatization” of the Republic of Kazakhstan (Standard No. No. 418-V SAM).

2. Information Availability: An Insight into the Most Important Attribute of Information Security;Qadir;J. Inf. Secur.,2016

3. (2016). Information Technology—Security Techniques—Information Security Management—Monitoring, Measurement, Analysis and Evaluation (Standard No. ISO/IEC 27004:2016E).

4. CSKG4APT: A Cybersecurity Knowledge Graph for Advanced Persistent Threat Organization Attribution;Ren;IEEE Trans. Knowl. Data Eng.,2022

5. Turskis, Z., Goranin, N., Nurusheva, A., and Boranbayev, S. (2019). A Fuzzy WASPAS-Based Approach to Determine Critical Information Infrastructures of EU Sustainable Development. Sustainability, 11.

Cited by 2 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. Evaluarea şi analiza unui set de indici de securitate ciberneticǎ utilizând metode multi criteriale;Revista Română de Informatică și Automatică;2024-03-29

2. Research on Network Accounting Information Security based on AES Algorithm;2023 Global Conference on Information Technologies and Communications (GCITC);2023-12-01

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3