评价风险评估方法有效性的DEA模型
DEA Model for Effectiveness Evaluation of Risk Assessment Methods
-
摘要: 决定信息安全评估结果是否科学有效的前提和基础是选择正确的风险评估方法,因此如何选择就成为关键。该文将模糊综合评价方法和数据包络(DEA)方法相结合,提出一种筛选评估方法的数学模型,用于评价风险评估方法的有效性。该方法充分考虑评价指标的客观性,从工程的角度综合计算进行风险评估活动的投入与产出,从定量的角度考察风险评估的评估效果,该方法具有良好的可操作性,为风险评估人员筛选更有效、科学、合理的评估方法提供一个具有实用价值的数学工具。Abstract: The legitimacy method selection is the precondition and foundation of a scientific and effective assessment process in information security assessment. By considering the relevant criteria and the cost in the view of project risk assessment, this paper proposes an optimized method for effectiveness evaluation of risk assessment methods based on the fuzzy integrated assessment method and the DEA-model. By taking full consideration of the objectivity of evaluations, this method calculates the input and output of risk assessment activities and inspects the assessment effect of risk evaluation. This method has good maneuverability and thus it could be an option to select more efficient and scientific assessment methods when carrying out risk assessment.