애스크로AIPublic Preview
← 학술논문 검색
학술논문대한안전경영과학회지2012.09 발행KCI 피인용 2

정보보안 예산 수립에서 퍼지 AHP의 적용을 통한 위험 비용 분석

Cost Risk Analysis for Preparing Budgets of Information Security using Fuzzy AHP

류시욱(한중대학교); 허덕규(한중대학교)

14권 3호, 119~126쪽

초록

Recently, the breakdown of online banking servers and the leakage of customer information give rise to much concern about the security of information systems in financial and banking companies in Korea. The enforcement of security for information system becomes much more important issue than earlier. However, the security reinforcement of information system is restricted by a budget. In addition, the activities' cost to secure information system from threatening are under uncertain circumstances and should be established by a human decision maker who is basically uncertain and vague. Thus, making the budget for information system is exposed to any extent of the risk for these reasons. First, we introduce brief fuzzy set theory and fuzzy AHP (Analytic Hierarchy Process) methodology. Then, the cost elements that comprise yearly budget are presented and the priorities among the cost elements are calculated by fuzzy AHP. The cost elements that are exposed to risk are evaluated from the both perspectives of the risk impact and risk occurrence possibility which are expressed as linguistic terms. To get information on the risk profiles—pessimistic, most likely, and optimistic—for each cost element, the evaluation is accomplished and the result is presented. At last, the budget ranges—minimum, mode, maximum—for each cost element are estimated with the consideration of the risk profiles.

Abstract

Recently, the breakdown of online banking servers and the leakage of customer information give rise to much concern about the security of information systems in financial and banking companies in Korea. The enforcement of security for information system becomes much more important issue than earlier. However, the security reinforcement of information system is restricted by a budget. In addition, the activities' cost to secure information system from threatening are under uncertain circumstances and should be established by a human decision maker who is basically uncertain and vague. Thus, making the budget for information system is exposed to any extent of the risk for these reasons. First, we introduce brief fuzzy set theory and fuzzy AHP (Analytic Hierarchy Process) methodology. Then, the cost elements that comprise yearly budget are presented and the priorities among the cost elements are calculated by fuzzy AHP. The cost elements that are exposed to risk are evaluated from the both perspectives of the risk impact and risk occurrence possibility which are expressed as linguistic terms. To get information on the risk profiles—pessimistic, most likely, and optimistic—for each cost element, the evaluation is accomplished and the result is presented. At last, the budget ranges—minimum, mode, maximum—for each cost element are estimated with the consideration of the risk profiles.

발행기관:
대한안전경영과학회
분류:
안전공학

AI 법률 상담

이 논문의 주제에 대해 더 알고 싶으신가요?

460만+ 법률 자료에서 관련 판례·법령·해석례를 찾아 답변합니다

AI 상담 시작
정보보안 예산 수립에서 퍼지 AHP의 적용을 통한 위험 비용 분석 | 대한안전경영과학회지 2012 | AskLaw | 애스크로 AI