Cargando…

Prioritization of Information Security Controls through Fuzzy AHP for Cloud Computing Networks and Wireless Sensor Networks

With the advent of cloud computing and wireless sensor networks, the number of cyberattacks has rapidly increased. Therefore, the proportionate security of networks has become a challenge for organizations. Information security advisors of organizations face difficult and complex decisions in the ev...

Descripción completa

Detalles Bibliográficos
Autores principales: Tariq, Muhammad Imran, Ahmed, Shakeel, Memon, Nisar Ahmed, Tayyaba, Shahzadi, Ashraf, Muhammad Waseem, Nazir, Mohsin, Hussain, Akhtar, Balas, Valentina Emilia, Balas, Marius M.
Formato: Online Artículo Texto
Lenguaje:English
Publicado: MDPI 2020
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7085684/
https://www.ncbi.nlm.nih.gov/pubmed/32121185
http://dx.doi.org/10.3390/s20051310
_version_ 1783508988666576896
author Tariq, Muhammad Imran
Ahmed, Shakeel
Memon, Nisar Ahmed
Tayyaba, Shahzadi
Ashraf, Muhammad Waseem
Nazir, Mohsin
Hussain, Akhtar
Balas, Valentina Emilia
Balas, Marius M.
author_facet Tariq, Muhammad Imran
Ahmed, Shakeel
Memon, Nisar Ahmed
Tayyaba, Shahzadi
Ashraf, Muhammad Waseem
Nazir, Mohsin
Hussain, Akhtar
Balas, Valentina Emilia
Balas, Marius M.
author_sort Tariq, Muhammad Imran
collection PubMed
description With the advent of cloud computing and wireless sensor networks, the number of cyberattacks has rapidly increased. Therefore, the proportionate security of networks has become a challenge for organizations. Information security advisors of organizations face difficult and complex decisions in the evaluation and selection of information security controls that permit the defense of their resources and assets. Information security controls must be selected based on an appropriate level of security. However, their selection needs intensive investigation regarding vulnerabilities, risks, and threats prevailing in the organization as well as consideration of the implementation, mitigation, and budgetary constraints of the organization. The goal of this paper was to improve the information security control analysis method by proposing a formalized approach, i.e., fuzzy Analytical Hierarchy Process (AHP). This approach was used to prioritize and select the most relevant set of information security controls to satisfy the information security requirements of an organization. We argue that the prioritization of the information security controls using fuzzy AHP leads to an efficient and cost-effective assessment and evaluation of information security controls for an organization in order to select the most appropriate ones. The proposed formalized approach and prioritization processes are based on International Organization for Standardization and the International Electrotechnical Commission (ISO/IEC) 27001:2013. But in practice, organizations may apply this approach to any information security baseline manual.
format Online
Article
Text
id pubmed-7085684
institution National Center for Biotechnology Information
language English
publishDate 2020
publisher MDPI
record_format MEDLINE/PubMed
spelling pubmed-70856842020-04-21 Prioritization of Information Security Controls through Fuzzy AHP for Cloud Computing Networks and Wireless Sensor Networks Tariq, Muhammad Imran Ahmed, Shakeel Memon, Nisar Ahmed Tayyaba, Shahzadi Ashraf, Muhammad Waseem Nazir, Mohsin Hussain, Akhtar Balas, Valentina Emilia Balas, Marius M. Sensors (Basel) Article With the advent of cloud computing and wireless sensor networks, the number of cyberattacks has rapidly increased. Therefore, the proportionate security of networks has become a challenge for organizations. Information security advisors of organizations face difficult and complex decisions in the evaluation and selection of information security controls that permit the defense of their resources and assets. Information security controls must be selected based on an appropriate level of security. However, their selection needs intensive investigation regarding vulnerabilities, risks, and threats prevailing in the organization as well as consideration of the implementation, mitigation, and budgetary constraints of the organization. The goal of this paper was to improve the information security control analysis method by proposing a formalized approach, i.e., fuzzy Analytical Hierarchy Process (AHP). This approach was used to prioritize and select the most relevant set of information security controls to satisfy the information security requirements of an organization. We argue that the prioritization of the information security controls using fuzzy AHP leads to an efficient and cost-effective assessment and evaluation of information security controls for an organization in order to select the most appropriate ones. The proposed formalized approach and prioritization processes are based on International Organization for Standardization and the International Electrotechnical Commission (ISO/IEC) 27001:2013. But in practice, organizations may apply this approach to any information security baseline manual. MDPI 2020-02-28 /pmc/articles/PMC7085684/ /pubmed/32121185 http://dx.doi.org/10.3390/s20051310 Text en © 2020 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).
spellingShingle Article
Tariq, Muhammad Imran
Ahmed, Shakeel
Memon, Nisar Ahmed
Tayyaba, Shahzadi
Ashraf, Muhammad Waseem
Nazir, Mohsin
Hussain, Akhtar
Balas, Valentina Emilia
Balas, Marius M.
Prioritization of Information Security Controls through Fuzzy AHP for Cloud Computing Networks and Wireless Sensor Networks
title Prioritization of Information Security Controls through Fuzzy AHP for Cloud Computing Networks and Wireless Sensor Networks
title_full Prioritization of Information Security Controls through Fuzzy AHP for Cloud Computing Networks and Wireless Sensor Networks
title_fullStr Prioritization of Information Security Controls through Fuzzy AHP for Cloud Computing Networks and Wireless Sensor Networks
title_full_unstemmed Prioritization of Information Security Controls through Fuzzy AHP for Cloud Computing Networks and Wireless Sensor Networks
title_short Prioritization of Information Security Controls through Fuzzy AHP for Cloud Computing Networks and Wireless Sensor Networks
title_sort prioritization of information security controls through fuzzy ahp for cloud computing networks and wireless sensor networks
topic Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7085684/
https://www.ncbi.nlm.nih.gov/pubmed/32121185
http://dx.doi.org/10.3390/s20051310
work_keys_str_mv AT tariqmuhammadimran prioritizationofinformationsecuritycontrolsthroughfuzzyahpforcloudcomputingnetworksandwirelesssensornetworks
AT ahmedshakeel prioritizationofinformationsecuritycontrolsthroughfuzzyahpforcloudcomputingnetworksandwirelesssensornetworks
AT memonnisarahmed prioritizationofinformationsecuritycontrolsthroughfuzzyahpforcloudcomputingnetworksandwirelesssensornetworks
AT tayyabashahzadi prioritizationofinformationsecuritycontrolsthroughfuzzyahpforcloudcomputingnetworksandwirelesssensornetworks
AT ashrafmuhammadwaseem prioritizationofinformationsecuritycontrolsthroughfuzzyahpforcloudcomputingnetworksandwirelesssensornetworks
AT nazirmohsin prioritizationofinformationsecuritycontrolsthroughfuzzyahpforcloudcomputingnetworksandwirelesssensornetworks
AT hussainakhtar prioritizationofinformationsecuritycontrolsthroughfuzzyahpforcloudcomputingnetworksandwirelesssensornetworks
AT balasvalentinaemilia prioritizationofinformationsecuritycontrolsthroughfuzzyahpforcloudcomputingnetworksandwirelesssensornetworks
AT balasmariusm prioritizationofinformationsecuritycontrolsthroughfuzzyahpforcloudcomputingnetworksandwirelesssensornetworks