STORM-RM: a collaborative and multicriteria risk management methodology
by Theodoros Ntouskas; Nineta Polemi
International Journal of Multicriteria Decision Making (IJMCDM), Vol. 2, No. 2, 2012

Abstract: Risk management (RM) is a necessary process in order to identify, categorise and handle security threats, vulnerabilities and risks of information and communication systems (ICS). Existing RM methodologies for the implementation of standards impose various barriers (e.g., limitation in knowledge gathering, time and resources consumption, and cost) which make them unable to meet the growing needs of the current distributed and complex ICS and their hosting critical data and services. Identifying these weaknesses, we treat RM as a multi-criteria problem and we propose a multi-criteria group decision making methodology STORM-RM for its solution combining the analytic hierarchy process (AHP) with security management standards (ISO27001 and AS/NZS 4360).

Online publication date: Sat, 30-Aug-2014

The full text of this article is only available to individual subscribers or to users at subscribing institutions.

 
Existing subscribers:
Go to Inderscience Online Journals to access the Full Text of this article.

Pay per view:
If you are not a subscriber and you just want to read the full contents of this article, buy online access here.

Complimentary Subscribers, Editors or Members of the Editorial Board of the International Journal of Multicriteria Decision Making (IJMCDM):
Login with your Inderscience username and password:

    Username:        Password:         

Forgotten your password?


Want to subscribe?
A subscription gives you complete access to all articles in the current issue, as well as to all articles in the previous three years (where applicable). See our Orders page to subscribe.

If you still need assistance, please email subs@inderscience.com