scholarly journals Qualitative Risk Assessment of Cybersecurity and Development of Vulnerability Enhancement Plans in Consideration of Digitalized Ship

2021 ◽  
Vol 9 (6) ◽  
pp. 565
Author(s):  
Yunja Yoo ◽  
Han-Seon Park

The International Maritime Organization (IMO) published the Guidelines on Maritime Cyber Risk Management in 2017 to strengthen cybersecurity in consideration of digitalized ships. As part of these guidelines, the IMO recommends that each flag state should integrate and manage matters regarding cyber risk in the ship safety management system (SMS) according to the International Safety Management Code (ISM Code) before the first annual verification that takes place on or after 1 January 2021. The purpose of this paper is to identify cybersecurity risk components in the maritime sector that should be managed by the SMS in 2021 and to derive priorities for vulnerability improvement plans through itemized risk assessment. To this end, qualitative risk assessment (RA) was carried out for administrative, technical, and physical security risk components based on industry and international standards, which were additionally presented in the IMO guidelines. Based on the risk matrix from the RA analysis results, a survey on improving cybersecurity vulnerabilities in the maritime sector was conducted, and the analytic hierarchy process was used to analyze the results and derive improvement plan priority measures.

2014 ◽  
Vol 543-547 ◽  
pp. 3565-3568
Author(s):  
Xiao Qiang Peng ◽  
Ting Ting Lu

To solve the difficult quantify analysis problem in the process of information security risk assessment, on the basis of the original qualitative risk assessment method, the fuzzy analytic hierarchy process is put forward, in order to realize the organic combination of subjective and objective assessment of risk factors. Based on the improvement of the analytic hierarchy process and fuzzy evaluation method, the two methods are organically combined. On the basis of the analysis and assessment of risk probability and impact of the incident, the risk rank of each risk factor is determined, and the information system risk control suggestions are given


2021 ◽  
Vol 245 ◽  
pp. 03082
Author(s):  
Fei Wu ◽  
Ling Cheng ◽  
Yinglei Yu ◽  
Jiajia Sun

Based on the 19 selected representative chemical enterprises in jiangsu province, we investigate the safety risk situation of chemical enterprises from the aspects of personnel technical level, equipment failure, major hazard sources, production process, environment, accident, certification, safety assessment and emergency response capacity. We found the following problems: the most part of staffs education is below undergraduate course; have major hidden dangers at district/county level and above; the vast majority of enterprises of dangerous chemicals maximum action/reaction temperature over dangerous chemicals flash point, etc. The index system of chemical enterprise safety risk state is constructed from six aspects: personnel, equipment, material, method, environment and safety management. The key index system of security risk state warning is put forward from the aspects of personnel, equipment, method, environment and safety management. We use the analytic hierarchy process (AHP) method to determine the chemical enterprise safety risk status indicators weight, and finally determine the state of the chemical enterprise safety risk classification standard.


2014 ◽  
Vol 505-506 ◽  
pp. 990-994
Author(s):  
Rong Shi ◽  
Ming Jie Li

The work on Airlines security risk assessment at home and abroad is mainly confined to safety evaluation, and the research on security risk assessment is very few. Taking an example of flight safety system of an airline, fuzzy comprehensive evaluation and analytic hierarchy process (AHP) is used to calculate the value of the risk of flight safety system based on risk assessment matrix. Flight safety risk assessment index system is established, and weights of the index system are determined by analytic hierarchy process. The indicators relevant values of risk probability and severity are calculated respectively by using fuzzy evaluation. And ultimately the values of flight safety risk assessment are gotten. Example calculations demonstrate the feasibility, effectiveness and practicality.


Author(s):  
Ming Xiang He ◽  
Xin An

<p>Information security risk assessment was an important component of information systems security engineering and the selection of assessment method had a direct impact on the final results of the assessment. But there were too many elements in the process of information security risk assessment. How to find the optimal elements from many elements to simplify the calculation of risk value and provide a strong basis for taking relevant measures, which was a problem needed to be solved. In addition, the reliability of the risk assessment results could not be guaranteed only through a single qualitative or quantitative assessment method. By Analytic Hierarchy Process (AHP), the relative weight of elements related to information security risk could be calculated. Then the optimal indicators, which provided a strong basis for taking relevant measures, could be selected by sorting the weights of elements to reduce the number of indicators. Moreover, Analytic Hierarchy Process, a method of the combination of qualitative and quantitative assessment methods, could overcome the shortcomings of single qualitative or quantitative assessment method.</p>


2015 ◽  
Vol 744-746 ◽  
pp. 570-573
Author(s):  
Wei Zhan ◽  
Hao Lin ◽  
Zhi Lei Li

Based on the investigation of soil slope in Zhejiang province, the main influence factors of soil slope stability were analyzed and the risk assessment indexes of soil slop were selected. Then the risk assessment model of soil slope was established by the method of analytic hierarchy process according to the importance of each index. The security risk assessment system of soil slope was obtained finally. The research result has important reference for the soil slope management.


Sign in / Sign up

Export Citation Format

Share Document