The Experts below are selected from a list of 207 Experts worldwide ranked by ideXlab platform

Taimyoung Chung - One of the best experts on this subject based on the ideXlab platform.

  • risk assessment method based on business process oriented asset evaluation for information system Security
    International Conference on Conceptual Structures, 2007
    Co-Authors: Seonho Park, Taimyoung Chung
    Abstract:

    We presented risk assessment methodology focused on business-process oriented asset evaluation and qualitative risk analysis method. The business process-oriented asset evaluation is to evaluate asset's value by the degree of asset contribution related to business process. Namely, asset's value is different according to the importance of department to which asset belongs, the contribution of asset's business, and Security Safeguard, etc. We proposed new asset's value evaluation applied to the weight of above factors. The weight is decided by evaluation matrix by Delphi team. We assess risk by qualitative method applied to the improved international standard method which is added the effectiveness of operating Safeguard at information system. It reflects an assumption that they can reduce risk level when existent Safeguards are established appropriately. Our model derives to practical risk assessment method than existent risk assessment method, and improves reliability of risk analysis.

  • International Conference on Computational Science (3) - Risk Assessment Method Based on Business Process-Oriented Asset Evaluation for Information System Security
    Computational Science – ICCS 2007, 2007
    Co-Authors: Seonho Park, Taimyoung Chung
    Abstract:

    We presented risk assessment methodology focused on business-process oriented asset evaluation and qualitative risk analysis method. The business process-oriented asset evaluation is to evaluate asset's value by the degree of asset contribution related to business process. Namely, asset's value is different according to the importance of department to which asset belongs, the contribution of asset's business, and Security Safeguard, etc. We proposed new asset's value evaluation applied to the weight of above factors. The weight is decided by evaluation matrix by Delphi team. We assess risk by qualitative method applied to the improved international standard method which is added the effectiveness of operating Safeguard at information system. It reflects an assumption that they can reduce risk level when existent Safeguards are established appropriately. Our model derives to practical risk assessment method than existent risk assessment method, and improves reliability of risk analysis.

Seonho Park - One of the best experts on this subject based on the ideXlab platform.

  • risk assessment method based on business process oriented asset evaluation for information system Security
    International Conference on Conceptual Structures, 2007
    Co-Authors: Seonho Park, Taimyoung Chung
    Abstract:

    We presented risk assessment methodology focused on business-process oriented asset evaluation and qualitative risk analysis method. The business process-oriented asset evaluation is to evaluate asset's value by the degree of asset contribution related to business process. Namely, asset's value is different according to the importance of department to which asset belongs, the contribution of asset's business, and Security Safeguard, etc. We proposed new asset's value evaluation applied to the weight of above factors. The weight is decided by evaluation matrix by Delphi team. We assess risk by qualitative method applied to the improved international standard method which is added the effectiveness of operating Safeguard at information system. It reflects an assumption that they can reduce risk level when existent Safeguards are established appropriately. Our model derives to practical risk assessment method than existent risk assessment method, and improves reliability of risk analysis.

  • International Conference on Computational Science (3) - Risk Assessment Method Based on Business Process-Oriented Asset Evaluation for Information System Security
    Computational Science – ICCS 2007, 2007
    Co-Authors: Seonho Park, Taimyoung Chung
    Abstract:

    We presented risk assessment methodology focused on business-process oriented asset evaluation and qualitative risk analysis method. The business process-oriented asset evaluation is to evaluate asset's value by the degree of asset contribution related to business process. Namely, asset's value is different according to the importance of department to which asset belongs, the contribution of asset's business, and Security Safeguard, etc. We proposed new asset's value evaluation applied to the weight of above factors. The weight is decided by evaluation matrix by Delphi team. We assess risk by qualitative method applied to the improved international standard method which is added the effectiveness of operating Safeguard at information system. It reflects an assumption that they can reduce risk level when existent Safeguards are established appropriately. Our model derives to practical risk assessment method than existent risk assessment method, and improves reliability of risk analysis.

Edgar Weippl - One of the best experts on this subject based on the ideXlab platform.

  • workshop based multiobjective Security Safeguard selection
    Availability Reliability and Security, 2006
    Co-Authors: Thomas Neubauer, Christian Stummer, Edgar Weippl
    Abstract:

    Companies spend considerable amounts of resources on minimizing Security breaches but often neglect efficient Security measures and/or are not aware whether their investments are effective. While Security Safeguards traditionally are evaluated through a single (aggregated) criterion such as the return on investment, this may not suffice any longer as economic and legal requirements force top management to pay more attention to Security issues. Thus, there is a demand for decision support tools that assist decision makers in allocating Security Safeguards with respect to multiple objectives of the involved stakeholders. This paper proposes a tool called MOS/sup 3/T (multi-objective Security Safeguard selection tool), that integrates ideas from multiobjective decision making in a workshop environment The stepwise procedure for the assessment and interactive selection of sets of Security Safeguards improves Security awareness of top management while minimizing the resources required for implementing a proper Security environment that meets a corporate's needs.

  • ARES - Workshop-based multiobjective Security Safeguard selection
    First International Conference on Availability Reliability and Security (ARES'06), 2006
    Co-Authors: Thomas Neubauer, Christian Stummer, Edgar Weippl
    Abstract:

    Companies spend considerable amounts of resources on minimizing Security breaches but often neglect efficient Security measures and/or are not aware whether their investments are effective. While Security Safeguards traditionally are evaluated through a single (aggregated) criterion such as the return on investment, this may not suffice any longer as economic and legal requirements force top management to pay more attention to Security issues. Thus, there is a demand for decision support tools that assist decision makers in allocating Security Safeguards with respect to multiple objectives of the involved stakeholders. This paper proposes a tool called MOS/sup 3/T (multi-objective Security Safeguard selection tool), that integrates ideas from multiobjective decision making in a workshop environment The stepwise procedure for the assessment and interactive selection of sets of Security Safeguards improves Security awareness of top management while minimizing the resources required for implementing a proper Security environment that meets a corporate's needs.

Thomas Neubauer - One of the best experts on this subject based on the ideXlab platform.

  • a comparison of Security Safeguard selection methods
    International Conference on Enterprise Information Systems, 2009
    Co-Authors: Thomas Neubauer
    Abstract:

    IT Security incidents pose a major threat to the efficient execution of corporate strategies and business processes. Although companies generally spend a lot of money on Security companies are often not aware of their spending on Security and even more important if these investments into Security are effective. This paper provides decision makers with an overview of decision support techniques, describes pros and cons of these

  • ICEIS (3) - A COMPARISON OF Security Safeguard SELECTION METHODS
    Proceedings of the 11th International Conference on Enterprise Information, 2009
    Co-Authors: Thomas Neubauer
    Abstract:

    IT Security incidents pose a major threat to the efficient execution of corporate strategies and business processes. Although companies generally spend a lot of money on Security companies are often not aware of their spending on Security and even more important if these investments into Security are effective. This paper provides decision makers with an overview of decision support techniques, describes pros and cons of these

  • workshop based multiobjective Security Safeguard selection
    Availability Reliability and Security, 2006
    Co-Authors: Thomas Neubauer, Christian Stummer, Edgar Weippl
    Abstract:

    Companies spend considerable amounts of resources on minimizing Security breaches but often neglect efficient Security measures and/or are not aware whether their investments are effective. While Security Safeguards traditionally are evaluated through a single (aggregated) criterion such as the return on investment, this may not suffice any longer as economic and legal requirements force top management to pay more attention to Security issues. Thus, there is a demand for decision support tools that assist decision makers in allocating Security Safeguards with respect to multiple objectives of the involved stakeholders. This paper proposes a tool called MOS/sup 3/T (multi-objective Security Safeguard selection tool), that integrates ideas from multiobjective decision making in a workshop environment The stepwise procedure for the assessment and interactive selection of sets of Security Safeguards improves Security awareness of top management while minimizing the resources required for implementing a proper Security environment that meets a corporate's needs.

  • ARES - Workshop-based multiobjective Security Safeguard selection
    First International Conference on Availability Reliability and Security (ARES'06), 2006
    Co-Authors: Thomas Neubauer, Christian Stummer, Edgar Weippl
    Abstract:

    Companies spend considerable amounts of resources on minimizing Security breaches but often neglect efficient Security measures and/or are not aware whether their investments are effective. While Security Safeguards traditionally are evaluated through a single (aggregated) criterion such as the return on investment, this may not suffice any longer as economic and legal requirements force top management to pay more attention to Security issues. Thus, there is a demand for decision support tools that assist decision makers in allocating Security Safeguards with respect to multiple objectives of the involved stakeholders. This paper proposes a tool called MOS/sup 3/T (multi-objective Security Safeguard selection tool), that integrates ideas from multiobjective decision making in a workshop environment The stepwise procedure for the assessment and interactive selection of sets of Security Safeguards improves Security awareness of top management while minimizing the resources required for implementing a proper Security environment that meets a corporate's needs.

Christian Stummer - One of the best experts on this subject based on the ideXlab platform.

  • workshop based multiobjective Security Safeguard selection
    Availability Reliability and Security, 2006
    Co-Authors: Thomas Neubauer, Christian Stummer, Edgar Weippl
    Abstract:

    Companies spend considerable amounts of resources on minimizing Security breaches but often neglect efficient Security measures and/or are not aware whether their investments are effective. While Security Safeguards traditionally are evaluated through a single (aggregated) criterion such as the return on investment, this may not suffice any longer as economic and legal requirements force top management to pay more attention to Security issues. Thus, there is a demand for decision support tools that assist decision makers in allocating Security Safeguards with respect to multiple objectives of the involved stakeholders. This paper proposes a tool called MOS/sup 3/T (multi-objective Security Safeguard selection tool), that integrates ideas from multiobjective decision making in a workshop environment The stepwise procedure for the assessment and interactive selection of sets of Security Safeguards improves Security awareness of top management while minimizing the resources required for implementing a proper Security environment that meets a corporate's needs.

  • ARES - Workshop-based multiobjective Security Safeguard selection
    First International Conference on Availability Reliability and Security (ARES'06), 2006
    Co-Authors: Thomas Neubauer, Christian Stummer, Edgar Weippl
    Abstract:

    Companies spend considerable amounts of resources on minimizing Security breaches but often neglect efficient Security measures and/or are not aware whether their investments are effective. While Security Safeguards traditionally are evaluated through a single (aggregated) criterion such as the return on investment, this may not suffice any longer as economic and legal requirements force top management to pay more attention to Security issues. Thus, there is a demand for decision support tools that assist decision makers in allocating Security Safeguards with respect to multiple objectives of the involved stakeholders. This paper proposes a tool called MOS/sup 3/T (multi-objective Security Safeguard selection tool), that integrates ideas from multiobjective decision making in a workshop environment The stepwise procedure for the assessment and interactive selection of sets of Security Safeguards improves Security awareness of top management while minimizing the resources required for implementing a proper Security environment that meets a corporate's needs.