MARATTO

book chapter

A Framework for Assessing the Security Risk of Requirements

Abstract

The growing adoption of cloud services in business operations has introduced new security challenges for compliance management. This chapter aims to present a structured approach to evaluating the security risks associated with business process compliance requirements. A fuzzy logic-based framework is developed using the ISO 27001 standard to assess the risk levels of compliance requirements extracted from regulatory documents. The results show that the framework enables accurate classification of requirements into low, medium, or high risk, enhancing decision-making in compliance budgeting. This approach supports effective compliance management, improves information security, and can be adapted across various industries.

Research topics

  • Information and Cyber Security
  • Software Engineering Techniques and Practices
  • Software Reliability and Analysis Research

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.4018/979-8-3693-9137-2.ch013

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.