Full metadata record
DC FieldValueLanguage
dc.contributor.authorMock, Ralf Günter-
dc.contributor.authorAeschlimann, Philipp-
dc.date.accessioned2018-11-29T08:11:32Z-
dc.date.available2018-11-29T08:11:32Z-
dc.date.issued2012-
dc.identifier.isbn978-0-415-68379-1de_CH
dc.identifier.isbn978-0-203-13510-5de_CH
dc.identifier.urihttps://digitalcollection.zhaw.ch/handle/11475/13323-
dc.description.abstractOptimising the way of questioning in check lists offers great potential to improve the quality of risk assessment surveys of IT infrastructures at enterprises. For this, staggered lists of IT security measurements are constructed (Guttman scales) whereas the Code of Practice ISO/IEC 27002 provides the objectives and recommendations relating to information security management in this regard. The FMEA approach finally structures the overall risk analysis process. A questionnaire/survey design using this "Best Practice FMEA" enables the analyst to represent the results in the form of matrices of measurements with regard to the Code's Objectives improving statistical  analysis and validity. In this paper, the statistical evaluation process uses k-means. This is a nonhierarchical clustering method which is compared with hierarchical clustering methods. With regard to applicability, the k-means approach is found easier to implement at (small and medium-sized) enterprises. The representation of results is more comprehensive for complex data bases. Apart from that, both clustering methods are equivalent as they group the Objectives in the same way. The results of a literature research show the placement of Best Practice FMEA among other IT risk assessment approaches, e.g. CRAMM and OCTAVE-S. Comparison criteria are derived from the ISO/IEC-Guide 73. It becomes apparent that Best Practice FMEA is most applicable at small-scale enterprises which are not fully covered by the other approaches. The paper finally shows the transfer of the previous paper-based approach into the novel web based tool ITRA:GUST. The concepts of tool design and software architecture are presented. The closing remarks summarise and reason the method development of Best Practice FMEA and ITRA:GUST.de_CH
dc.language.isoende_CH
dc.publisherTaylor & Francisde_CH
dc.rightsLicence according to publishing contractde_CH
dc.subjectAuditde_CH
dc.subjectFMEAde_CH
dc.subjectRisk assessmentde_CH
dc.subjectIT securityde_CH
dc.subject.ddc004: Informatikde_CH
dc.subject.ddc658.5: Produktionssteuerungde_CH
dc.titleITRA:GUST : the Guttman scaling tool for supporting IT risk assessment auditsde_CH
dc.typeKonferenz: Paperde_CH
dcterms.typeTextde_CH
zhaw.departementSchool of Engineeringde_CH
zhaw.organisationalunitInstitut für Informatik (InIT)de_CH
zhaw.publisher.placeLondonde_CH
zhaw.conference.detailsEuropean Safety and Reliability Conference (ESREL 2011), Troyes, France, 18-22 September 2011de_CH
zhaw.funding.euNode_CH
zhaw.originated.zhawYesde_CH
zhaw.pages.end1344de_CH
zhaw.pages.start1336de_CH
zhaw.publication.statuspublishedVersionde_CH
zhaw.publication.reviewPeer review (Publikation)de_CH
zhaw.title.proceedingsAdvances in safety, reliability and risk management : ESREL 2011de_CH
Appears in collections:Publikationen School of Engineering

Files in This Item:
There are no files associated with this item.
Show simple item record
Mock, R. G., & Aeschlimann, P. (2012). ITRA:GUST : the Guttman scaling tool for supporting IT risk assessment audits [Conference paper]. Advances in Safety, Reliability and Risk Management : ESREL 2011, 1336–1344.
Mock, R.G. and Aeschlimann, P. (2012) ‘ITRA:GUST : the Guttman scaling tool for supporting IT risk assessment audits’, in Advances in safety, reliability and risk management : ESREL 2011. London: Taylor & Francis, pp. 1336–1344.
R. G. Mock and P. Aeschlimann, “ITRA:GUST : the Guttman scaling tool for supporting IT risk assessment audits,” in Advances in safety, reliability and risk management : ESREL 2011, 2012, pp. 1336–1344.
MOCK, Ralf Günter und Philipp AESCHLIMANN, 2012. ITRA:GUST : the Guttman scaling tool for supporting IT risk assessment audits. In: Advances in safety, reliability and risk management : ESREL 2011. Conference paper. London: Taylor & Francis. 2012. S. 1336–1344. ISBN 978-0-415-68379-1
Mock, Ralf Günter, and Philipp Aeschlimann. 2012. “ITRA:GUST : The Guttman Scaling Tool for Supporting IT Risk Assessment Audits.” Conference paper. In Advances in Safety, Reliability and Risk Management : ESREL 2011, 1336–44. London: Taylor & Francis.
Mock, Ralf Günter, and Philipp Aeschlimann. “ITRA:GUST : The Guttman Scaling Tool for Supporting IT Risk Assessment Audits.” Advances in Safety, Reliability and Risk Management : ESREL 2011, Taylor & Francis, 2012, pp. 1336–44.


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.