题名 |
New Risk Analysis Method for Information System Security |
作者 |
Easter C. K. Huang;Chung-Jen Chin |
关键词 |
Personal Information Protection ; information security ; risk analysis ; FMEA ; ISO27001 ; certification |
期刊名称 |
資訊安全通訊 |
卷期/出版年月 |
20卷4期(2014 / 10 / 01) |
页次 |
23 - 40 |
内容语文 |
英文 |
英文摘要 |
This study used the Failure Mode Effect Analysis (FMEA) that is one of the most popular methods for risk analysis to explain the regulatory compliance rate with the information security risk analysis of the Taiwan universities. Using the regression analysis, the independent variables including violating times to Taiwanese laws, the self-detecting violating times to Taiwanese laws, the attacked times that detected by government and the non-conformities issued by third-party to the dependent variables that the risk priority number (RPN) that the multiplication of occurrence of violation (O), the Severity (S) and detecting ability (D). The multicollinearity is not obvious, and the result is significant correlation of the variables that independent variables could explain 68% to the dependent variable. In this study, the FMEA could explain the regulatory compliance that means the risk analysis could improve information security detective methods for the preventive purposes. |
主题分类 |
基礎與應用科學 >
資訊科學 |
参考文献 |
|