2014
DOI: 10.7232/iems.2014.13.1.087
|View full text |Cite
|
Sign up to set email alerts
|

Development of a Failure Mode and Effects Analysis Based Risk Assessment Tool for Information Security

Abstract: Risk management is recognized as a significant element in Information Security Management while the failure mode and effects analysis (FMEA) is widely used in risk analysis in manufacturing industry. This paper aims to present the development work of the Information Security FMEA Circle (InfoSec FMEA Circle) which is used to support the risk management framework by modifying traditional FMEA methodologies. In order to demonstrate the "appropriateness" of the InfoSec FMEA Circle for the purposes of assessing in… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
7
0

Year Published

2020
2020
2022
2022

Publication Types

Select...
3

Relationship

0
3

Authors

Journals

citations
Cited by 3 publications
(7 citation statements)
references
References 15 publications
(33 reference statements)
0
7
0
Order By: Relevance
“…FMEA is growing and can be used in various fields, including Information Technology. The difference in the use of FMEA is based on the risk object to be measured (Lai and Chin, 2014). In addition, the focal point of risk measurement in this research is IT risks.…”
Section: Failure Mode and Effect Analysis (Fmea)mentioning
confidence: 99%
See 3 more Smart Citations
“…FMEA is growing and can be used in various fields, including Information Technology. The difference in the use of FMEA is based on the risk object to be measured (Lai and Chin, 2014). In addition, the focal point of risk measurement in this research is IT risks.…”
Section: Failure Mode and Effect Analysis (Fmea)mentioning
confidence: 99%
“…The FMEA method applied in risk management bears a consistency issue (Barends et al, 2012;Estorilio and Posso, 2010;Gary Teng et al, 2006;Oldenhof et al, 2011). A research conducted by (Lai and Chin, 2014) proposed Information Security FMEA Circle that modified traditional FMEA methodology. Moreover, another research by (Oldenhof et al, 2011) examined the consistency of FMEA by assessing risks in different teams in a case study.…”
Section: Related Workmentioning
confidence: 99%
See 2 more Smart Citations
“…Establish the context: Identify the objectives of the project, event or relationship and then consider the internal and external parameters. According to Lai and Chin (2004), the process part of ISO 31000:2009 is the same as AS/NZS 4360:1999, AIRMIC, ALARM, IRM:2002 and ISO 27005:2011. The FMEA is a methodology aimed as a risk assessment tool because of its semi-quantitative approach in calculating RPN.…”
Section: Background Of Iso 31000:2009mentioning
confidence: 99%