Authors:
E. Vicente
;
A. Mateos
and
A. Jiménez-Martín
Affiliation:
Universidad Politécnica de Madrid, Spain
Keyword(s):
Risk Analysis, Fuzzy Logic, Dynamic Programming, Simulated Annealing.
Related
Ontology
Subjects/Areas/Topics:
Artificial Intelligence
;
Dynamic Programming
;
Information Systems
;
Knowledge Discovery and Information Retrieval
;
Knowledge-Based Systems
;
Mathematical Programming
;
Methodologies and Technologies
;
Operational Research
;
Optimization
;
Symbolic Systems
Abstract:
In this paper we focus on the selection of safeguards in a fuzzy risk analysis and management methodology for information systems (IS). Assets are connected by dependency relationships, and a failure of one asset may affect other assets. After computing impact and risk indicators associated with previously identified threats, we identify and apply safeguards to reduce risks in the IS by minimizing the transmission probabilities of failures throughout the asset network. However, as safeguards have associated costs, the aim is to select the
safeguards that minimize costs while keeping the risk within acceptable levels. To do this, we propose a dynamic programming-based method that incorporates simulated annealing to tackle optimizations problems.