科研速览 · Science Skim继续刷下去 · Keep skimming →
◆ EDPACS2026-04-14· Business

Multi-criteria decision modeling for cybersecurity investment and IT risk governance

Manzoor Ansari, Syed Arshad Ali, Masood Alam, Salem Al Hudaify, Mohammad Al Natour

原始摘要(英文原文)· Original abstract
The decisions made regarding cybersecurity investments are one of the most significant and analytically intricate ones that IT governance practitioners are confronted with nowadays. As the threat landscapes continue to change faster than ever before, constrained budgets and competing stakeholder demands, single-criteria methods of optimizing security spend have been shown to be structurally insufficient. The given paper is a proposal of a multi-criteria decision modeling (MCDM) framework that is specifically tailored to cybersecurity investment prioritization and to IT risk governance. Based on Analytic Hierarchy Process (AHP), Technique for Order Preference by Similarity to Ideal Solution (TOPSIS) and stochastic dominance analysis, the proposed model allows organizations to evaluate, in a unified decision architecture, financial exposure, regulatory compliance burden, operational resilience, threat probability, and strategic alignment against each other. The framework uses quantity of uncertainty based on Monte Carlo simulation and sensitivity analysis to resolve the fact that the approach is imprecise by nature to estimate cybersecurity risks. An example of the application of the model is presented in a realistic case study of four areas of investment (endpoint security, identity and access management, cloud security posture management, and security operations center capability). The effects on audit, governance, and integration with industry standards like ISO/IEC 27,005, COBIT 2019, and NIST CSF 2.0 are discussed.
读原文 · Read the paper ↗

AI 追问PRO

登录后使用 AI 追问

讨论区

登录后参与讨论

相关论文 · Related

Multi-criteria decision modeling for cybersecurity investment and IT risk governance — 科研速览 Science Skim