Factor identification and computation in the assessment of information security risks for digital libraries

Author:

Huang Shuiqing,Han Zhengbiao,Yang Bo1,Ren Ni2

Affiliation:

1. Nanjing Agricultural University, China

2. Nanjing Agricultural University, Jiangsu Academy of Agricultural Sciences, China

Abstract

This study proposes an objective methodology for identifying and computing the factors relevant to the assessment of information security risks for digital libraries that is also compliant with the ISO 27000 and the GB/T 20984 standards. By introducing a fuzzy comprehensive assessment method and an expert investigation method to the dimensions of assets and threats, this study proposes a model for computing the value of assets and the severity of threats. In the dimension of vulnerabilities, a vulnerability computation model based on the multi-channel weighted average method is proposed. By considering the digital library of a typical public library in China as the object of assessment, this study acquires assessment data by using a combination of a questionnaire survey, an on-site survey and vulnerability scanning. Research findings consisted of the following: (1) the digital library identified a total of 3111 information security risk items; (2) according to the assessment results attained using a combination of the factor identification and computational methodologies proposed here in conjunction with the multiplicative method specified in GB/T 20984, the high-risk (or higher risk) items accounted for 0.9% of all risky items, which is consistent with the status quo in information security risks faced by digital libraries. The analysis showed that the proposed methodology is more scientific than the currently prevailing direct value assignment method.

Funder

national social science fund project of China

Publisher

SAGE Publications

Subject

Library and Information Sciences

Cited by 6 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. Data Security Mechanism of Digital Library Based on Blockchain;2023 International Conference on Ambient Intelligence, Knowledge Informatics and Industrial Electronics (AIKIIE);2023-11-02

2. An exploratory prioritization of factors affecting current state of information security in Pakistani university libraries;International Journal of Information Management Data Insights;2021-11

3. Assessing the Components of Information Security in Accessing & Use of Digital Libraries;Iranian Journal of Information Processing and Management;2021-09-01

4. Digital library evaluation measures in academic settings: Perspectives from scholars and practitioners;Journal of Librarianship and Information Science;2020-06-24

5. Construction of information network vulnerability threat assessment model for CPS risk assessment;Computer Communications;2020-04

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3