Cargando…
Prioritization of Information Security Controls through Fuzzy AHP for Cloud Computing Networks and Wireless Sensor Networks
With the advent of cloud computing and wireless sensor networks, the number of cyberattacks has rapidly increased. Therefore, the proportionate security of networks has become a challenge for organizations. Information security advisors of organizations face difficult and complex decisions in the ev...
Autores principales: | , , , , , , , , |
---|---|
Formato: | Online Artículo Texto |
Lenguaje: | English |
Publicado: |
MDPI
2020
|
Materias: | |
Acceso en línea: | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7085684/ https://www.ncbi.nlm.nih.gov/pubmed/32121185 http://dx.doi.org/10.3390/s20051310 |
_version_ | 1783508988666576896 |
---|---|
author | Tariq, Muhammad Imran Ahmed, Shakeel Memon, Nisar Ahmed Tayyaba, Shahzadi Ashraf, Muhammad Waseem Nazir, Mohsin Hussain, Akhtar Balas, Valentina Emilia Balas, Marius M. |
author_facet | Tariq, Muhammad Imran Ahmed, Shakeel Memon, Nisar Ahmed Tayyaba, Shahzadi Ashraf, Muhammad Waseem Nazir, Mohsin Hussain, Akhtar Balas, Valentina Emilia Balas, Marius M. |
author_sort | Tariq, Muhammad Imran |
collection | PubMed |
description | With the advent of cloud computing and wireless sensor networks, the number of cyberattacks has rapidly increased. Therefore, the proportionate security of networks has become a challenge for organizations. Information security advisors of organizations face difficult and complex decisions in the evaluation and selection of information security controls that permit the defense of their resources and assets. Information security controls must be selected based on an appropriate level of security. However, their selection needs intensive investigation regarding vulnerabilities, risks, and threats prevailing in the organization as well as consideration of the implementation, mitigation, and budgetary constraints of the organization. The goal of this paper was to improve the information security control analysis method by proposing a formalized approach, i.e., fuzzy Analytical Hierarchy Process (AHP). This approach was used to prioritize and select the most relevant set of information security controls to satisfy the information security requirements of an organization. We argue that the prioritization of the information security controls using fuzzy AHP leads to an efficient and cost-effective assessment and evaluation of information security controls for an organization in order to select the most appropriate ones. The proposed formalized approach and prioritization processes are based on International Organization for Standardization and the International Electrotechnical Commission (ISO/IEC) 27001:2013. But in practice, organizations may apply this approach to any information security baseline manual. |
format | Online Article Text |
id | pubmed-7085684 |
institution | National Center for Biotechnology Information |
language | English |
publishDate | 2020 |
publisher | MDPI |
record_format | MEDLINE/PubMed |
spelling | pubmed-70856842020-04-21 Prioritization of Information Security Controls through Fuzzy AHP for Cloud Computing Networks and Wireless Sensor Networks Tariq, Muhammad Imran Ahmed, Shakeel Memon, Nisar Ahmed Tayyaba, Shahzadi Ashraf, Muhammad Waseem Nazir, Mohsin Hussain, Akhtar Balas, Valentina Emilia Balas, Marius M. Sensors (Basel) Article With the advent of cloud computing and wireless sensor networks, the number of cyberattacks has rapidly increased. Therefore, the proportionate security of networks has become a challenge for organizations. Information security advisors of organizations face difficult and complex decisions in the evaluation and selection of information security controls that permit the defense of their resources and assets. Information security controls must be selected based on an appropriate level of security. However, their selection needs intensive investigation regarding vulnerabilities, risks, and threats prevailing in the organization as well as consideration of the implementation, mitigation, and budgetary constraints of the organization. The goal of this paper was to improve the information security control analysis method by proposing a formalized approach, i.e., fuzzy Analytical Hierarchy Process (AHP). This approach was used to prioritize and select the most relevant set of information security controls to satisfy the information security requirements of an organization. We argue that the prioritization of the information security controls using fuzzy AHP leads to an efficient and cost-effective assessment and evaluation of information security controls for an organization in order to select the most appropriate ones. The proposed formalized approach and prioritization processes are based on International Organization for Standardization and the International Electrotechnical Commission (ISO/IEC) 27001:2013. But in practice, organizations may apply this approach to any information security baseline manual. MDPI 2020-02-28 /pmc/articles/PMC7085684/ /pubmed/32121185 http://dx.doi.org/10.3390/s20051310 Text en © 2020 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/). |
spellingShingle | Article Tariq, Muhammad Imran Ahmed, Shakeel Memon, Nisar Ahmed Tayyaba, Shahzadi Ashraf, Muhammad Waseem Nazir, Mohsin Hussain, Akhtar Balas, Valentina Emilia Balas, Marius M. Prioritization of Information Security Controls through Fuzzy AHP for Cloud Computing Networks and Wireless Sensor Networks |
title | Prioritization of Information Security Controls through Fuzzy AHP for Cloud Computing Networks and Wireless Sensor Networks |
title_full | Prioritization of Information Security Controls through Fuzzy AHP for Cloud Computing Networks and Wireless Sensor Networks |
title_fullStr | Prioritization of Information Security Controls through Fuzzy AHP for Cloud Computing Networks and Wireless Sensor Networks |
title_full_unstemmed | Prioritization of Information Security Controls through Fuzzy AHP for Cloud Computing Networks and Wireless Sensor Networks |
title_short | Prioritization of Information Security Controls through Fuzzy AHP for Cloud Computing Networks and Wireless Sensor Networks |
title_sort | prioritization of information security controls through fuzzy ahp for cloud computing networks and wireless sensor networks |
topic | Article |
url | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7085684/ https://www.ncbi.nlm.nih.gov/pubmed/32121185 http://dx.doi.org/10.3390/s20051310 |
work_keys_str_mv | AT tariqmuhammadimran prioritizationofinformationsecuritycontrolsthroughfuzzyahpforcloudcomputingnetworksandwirelesssensornetworks AT ahmedshakeel prioritizationofinformationsecuritycontrolsthroughfuzzyahpforcloudcomputingnetworksandwirelesssensornetworks AT memonnisarahmed prioritizationofinformationsecuritycontrolsthroughfuzzyahpforcloudcomputingnetworksandwirelesssensornetworks AT tayyabashahzadi prioritizationofinformationsecuritycontrolsthroughfuzzyahpforcloudcomputingnetworksandwirelesssensornetworks AT ashrafmuhammadwaseem prioritizationofinformationsecuritycontrolsthroughfuzzyahpforcloudcomputingnetworksandwirelesssensornetworks AT nazirmohsin prioritizationofinformationsecuritycontrolsthroughfuzzyahpforcloudcomputingnetworksandwirelesssensornetworks AT hussainakhtar prioritizationofinformationsecuritycontrolsthroughfuzzyahpforcloudcomputingnetworksandwirelesssensornetworks AT balasvalentinaemilia prioritizationofinformationsecuritycontrolsthroughfuzzyahpforcloudcomputingnetworksandwirelesssensornetworks AT balasmariusm prioritizationofinformationsecuritycontrolsthroughfuzzyahpforcloudcomputingnetworksandwirelesssensornetworks |