3.8 Article

Identifying core control items of information security management and improvement strategies by applying fuzzy DEMATEL

Journal

INFORMATION AND COMPUTER SECURITY
Volume 23, Issue 2, Pages 161-177

Publisher

EMERALD GROUP PUBLISHING LTD
DOI: 10.1108/ICS-04-2014-0026

Keywords

Information management; Identification; Information security; Organizational decision-making; Fuzzy logic; British standards

Ask authors/readers for more resources

Purpose - The purpose of this paper is to analyze the cause-and-effect relationship and the mutually influential level among information security control items, as well as to provide organizations with a method for analyzing and making systematic decisions for improvement. Design/methodology/approach - This study utilized the Fuzzy DEMATEL to analyze causeand-effect relationships and mutual influence of the 11 control items of the International Organization for Standardization (ISO) 27001 Information Security Management System (ISMS), which are discussed by seven experts in Taiwan to identify the core control items for developing the improvement strategies. Findings - The study has found that the three core control items of the ISMS are security policy (SC1), access control (SC7) and human resource security (SC4). This study provides organizations with a direction to develop improvement strategies and effectively manage the ISMS of the organization. Originality/value - The value of this study is for an organization to effectively dedicate resources to core control items, such that other control items are driven toward positive change by analyzing the cause-and-effect relation and the mutual influential level among information security control items, through a cause-and-effect matrix and a systematic diagram.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

3.8
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available