Checklist-based risk analysis with evidential reasoning

  • Authors:
  • Sungbaek Cho;Zbigniew Ciechanowicz

  • Affiliations:
  • Univ. of London, London, UK;Univ. of London, London, UK

  • Venue:
  • Sec '01 Proceedings of the 16th international conference on Information security: Trusted information: the new decade challenge
  • Year:
  • 2001

Quantified Score

Hi-index 0.00

Visualization

Abstract

Measuring risk is not a simple task since it almost invariably includes an analyst's subjective judgment. Risk analysis often forces the analyst to estimate or predict future events, which are uncertain. Therefore, we should consider the uncertainties associated with judgments made by the analyst. Hence in this article, we try to apply belief functions, which are used to express and manipulate uncertainties. We use an evidential network to combine answers and uncertainties from a checklist-based risk analysis. A checklist method is still useful in that it is relatively easier and simpler than other risk analysis methods. Furthermore, a checklist-based risk analysis can be used in a baseline approach. To establish the measure of risk in a checklist-based risk analysis can also be applied to the self-assessment of BS7799 compliance when preparing for accredited certification against BS7799.