Full metadata record
DC FieldValueLanguage
dc.contributor.authorMock, Ralf Günter-
dc.contributor.authorKollmann, Eva-
dc.contributor.authorStraumann, Hugo-
dc.contributor.authorBallhaus, Corin-
dc.date.accessioned2018-11-29T07:47:28Z-
dc.date.available2018-11-29T07:47:28Z-
dc.date.issued2009-
dc.identifier.isbn978-0-415-55509-8de_CH
dc.identifier.urihttps://digitalcollection.zhaw.ch/handle/11475/13316-
dc.description.abstractOn the strength of experience with risk analysis methodology in IT-operating enterprises, an approach has to be able to deal with limited resources. This prompts an analyst to perform a heuristic and biased approach, which is typically a questionnaire structured by a IT security standard. The difficulty is to draw up a limited set of concise IT security related questions, which result in meaningful outcomes for IT risk analysis purposes. In the proposed approach, the Code of Practice ISO/IEC 27002 is used to structure the analysis and to restrict the number of questions. The Code’s recommendations are rephrased and a Guttman scale is introduced for an IT security FMEA-like risk analysis approach. For frequency assessments it is assumed that an implemented high-level security measurement results in low frequencies of undesired events. The paper pictures the adapted IT-FMEA approach and presents the results of a feasibility study at Switzerland's leading telecom provider.de_CH
dc.language.isoende_CH
dc.publisherTaylor & Francisde_CH
dc.rightsLicence according to publishing contractde_CH
dc.subjectAuditde_CH
dc.subjectToolde_CH
dc.subjectIT securityde_CH
dc.subjectRisk assessmentde_CH
dc.subject.ddc005: Computerprogrammierung, Programme und Datende_CH
dc.subject.ddc658.5: Produktionssteuerungde_CH
dc.titleGuttman scaling in the FMEA of IT security objectives in enterprisesde_CH
dc.typeKonferenz: Paperde_CH
dcterms.typeTextde_CH
zhaw.departementSchool of Engineeringde_CH
zhaw.organisationalunitInstitut für Informatik (InIT)de_CH
zhaw.publisher.placeLondonde_CH
zhaw.conference.detailsEuropean Safety and Reliability Conference (ESREL 2009), Prague, Czech Republic, 7-10 September 2009de_CH
zhaw.funding.euNode_CH
zhaw.originated.zhawYesde_CH
zhaw.pages.end1990de_CH
zhaw.pages.start1983de_CH
zhaw.publication.statuspublishedVersionde_CH
zhaw.publication.reviewPeer review (Publikation)de_CH
zhaw.title.proceedingsReliability, risk, and safety : theory and applicationsde_CH
Appears in collections:Publikationen School of Engineering

Files in This Item:
There are no files associated with this item.
Show simple item record
Mock, R. G., Kollmann, E., Straumann, H., & Ballhaus, C. (2009). Guttman scaling in the FMEA of IT security objectives in enterprises [Conference paper]. Reliability, Risk, and Safety : Theory and Applications, 1983–1990.
Mock, R.G. et al. (2009) ‘Guttman scaling in the FMEA of IT security objectives in enterprises’, in Reliability, risk, and safety : theory and applications. London: Taylor & Francis, pp. 1983–1990.
R. G. Mock, E. Kollmann, H. Straumann, and C. Ballhaus, “Guttman scaling in the FMEA of IT security objectives in enterprises,” in Reliability, risk, and safety : theory and applications, 2009, pp. 1983–1990.
MOCK, Ralf Günter, Eva KOLLMANN, Hugo STRAUMANN und Corin BALLHAUS, 2009. Guttman scaling in the FMEA of IT security objectives in enterprises. In: Reliability, risk, and safety : theory and applications. Conference paper. London: Taylor & Francis. 2009. S. 1983–1990. ISBN 978-0-415-55509-8
Mock, Ralf Günter, Eva Kollmann, Hugo Straumann, and Corin Ballhaus. 2009. “Guttman Scaling in the FMEA of IT Security Objectives in Enterprises.” Conference paper. In Reliability, Risk, and Safety : Theory and Applications, 1983–90. London: Taylor & Francis.
Mock, Ralf Günter, et al. “Guttman Scaling in the FMEA of IT Security Objectives in Enterprises.” Reliability, Risk, and Safety : Theory and Applications, Taylor & Francis, 2009, pp. 1983–90.


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.