{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T16:53:59Z","timestamp":1781110439415,"version":"3.54.1"},"reference-count":108,"publisher":"IGI Global Scientific Publishing","issue":"3","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018,7,1]]},"abstract":"<p>In the digital era, organization-wide information security risk assessment has gained importance because it can impact businesses in many ways. In this article, the authors propose a model to assess the information security risk using Fuzzy Petri Nets (FPN). Deeply rooted in the OCTAVE framework, this research presents a taxonomy of risk practice areas and risk factors. The authors apply the constituents of the taxonomy to risk assessment through a well-defined FPN model. The primary motive of the article is to extend the usability of FPNs to newer and less explored domains like audit and evaluation of information security risks. The unique contribution of this article is the definition and development of a comprehensive and measurable model of risk assessment and quantification. The model can also serve as a tool to capture the risk perception of the respondents for validating the criticality of risk and facilitate the top management to invest in information security control eco-system judiciously.<\/p>","DOI":"10.4018\/jcit.2018070104","type":"journal-article","created":{"date-parts":[[2018,6,6]],"date-time":"2018-06-06T10:01:17Z","timestamp":1528279277000},"page":"48-69","source":"Crossref","is-referenced-by-count":4,"title":["Developing an Information Security Risk Taxonomy and an Assessment Model using Fuzzy Petri Nets"],"prefix":"10.4018","volume":"20","author":[{"given":"Dhanya","family":"Pramod","sequence":"first","affiliation":[{"name":"Symbiosis Centre for Information Technology (SCIT), Symbiosis International (Deemed University), Pune, India"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9667-6181","authenticated-orcid":true,"given":"S. Vijayakumar","family":"Bharathi","sequence":"additional","affiliation":[{"name":"Symbiosis Centre for Information Technology (SCIT), Symbiosis International (Deemed University), Pune, India"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"JCIT.2018070104-0","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2012.04.001"},{"key":"JCIT.2018070104-1","doi-asserted-by":"publisher","DOI":"10.1007\/s10845-012-0683-0"},{"key":"JCIT.2018070104-2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijinfomgt.2015.08.001"},{"key":"JCIT.2018070104-3","doi-asserted-by":"crossref","unstructured":"Alberts, C. Behrens, Sandra., Pethia, Richard., & Wilson, William. (1999). Operationally Critical Threat, Asset, and Vulnerability Evaluation (OCTAVE) Framework, Version 1.0. Retrieved from http:\/\/resources.sei.cmu.edu\/library\/asset-view.cfm?AssetID=13473","DOI":"10.21236\/ADA367718"},{"key":"JCIT.2018070104-4","doi-asserted-by":"crossref","unstructured":"Alberts, C., Dorofee, A., Stevens, J., & Woody, C. (2005). OCTAVE-S (Registered) Implementation Guide, Version 1.0. Retrieved from http:\/\/oai.dtic.mil\/oai\/oai?verb=getRecord&metadataPrefix=html&identifier=ADA453286","DOI":"10.21236\/ADA453304"},{"key":"JCIT.2018070104-5","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijinfomgt.2011.07.002"},{"key":"JCIT.2018070104-6","doi-asserted-by":"publisher","DOI":"10.1109\/3477.650056"},{"issue":"1","key":"JCIT.2018070104-7","first-page":"12","article-title":"Business Continuity Management Factors and Organizational Performance: A study on the Moderating Role of it Capability.","volume":"7","author":"Z. A.Bakar","year":"2015","journal-title":"Journal Of Management Info"},{"key":"JCIT.2018070104-8","doi-asserted-by":"publisher","DOI":"10.1145\/2245276.2232005"},{"key":"JCIT.2018070104-9","doi-asserted-by":"publisher","DOI":"10.1016\/j.im.2013.11.004"},{"key":"JCIT.2018070104-10","doi-asserted-by":"publisher","DOI":"10.1007\/s40171-017-0157-5"},{"key":"JCIT.2018070104-11","doi-asserted-by":"publisher","DOI":"10.4018\/IRMJ.2017100101"},{"issue":"3","key":"JCIT.2018070104-12","first-page":"330","article-title":"A conceptual model for ERP failure prediction using fuzzy petri-nets for small and medium enterprises.","volume":"87","author":"V.Bharathi","year":"2012","journal-title":"European Journal of Scientific Research"},{"key":"JCIT.2018070104-13","doi-asserted-by":"publisher","DOI":"10.3844\/jcssp.2013.139.146"},{"issue":"6","key":"JCIT.2018070104-14","first-page":"747","article-title":"A FPN Based Risk Assessment Model for ERP Implementation in Small and Medium Enterprises.","volume":"19","author":"V.Bharathi","year":"2014","journal-title":"Middle East Journal of Scientific Research"},{"key":"JCIT.2018070104-15","first-page":"46","article-title":"A model of security monitoring.","author":"M.Bishop","year":"1989","journal-title":"Fifth Annual Computer Security Applications Conference"},{"key":"JCIT.2018070104-16","doi-asserted-by":"publisher","DOI":"10.2991\/978-94-6239-100-0_1"},{"key":"JCIT.2018070104-17","doi-asserted-by":"publisher","DOI":"10.1109\/TSG.2014.2345780"},{"key":"JCIT.2018070104-18","doi-asserted-by":"publisher","DOI":"10.1109\/3477.891146"},{"key":"JCIT.2018070104-19","doi-asserted-by":"publisher","DOI":"10.1109\/JBHI.2013.2279595"},{"key":"JCIT.2018070104-20","doi-asserted-by":"publisher","DOI":"10.2753\/MIS0742-1222290305"},{"key":"JCIT.2018070104-21","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2008.10.070"},{"key":"JCIT.2018070104-22","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2012.09.010"},{"key":"JCIT.2018070104-23","doi-asserted-by":"publisher","DOI":"10.2753\/MIS0742-1222310210"},{"key":"JCIT.2018070104-24","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2015.10.001"},{"key":"JCIT.2018070104-25","doi-asserted-by":"publisher","DOI":"10.1016\/j.csi.2004.03.012"},{"key":"JCIT.2018070104-26","doi-asserted-by":"publisher","DOI":"10.1108\/IMCS-07-2013-0053"},{"key":"JCIT.2018070104-27","doi-asserted-by":"publisher","DOI":"10.1016\/0020-0190(91)90114-W"},{"key":"JCIT.2018070104-28","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10975-6_18"},{"key":"JCIT.2018070104-29","doi-asserted-by":"publisher","DOI":"10.1108\/DPM-12-2014-0272"},{"key":"JCIT.2018070104-30","doi-asserted-by":"publisher","DOI":"10.1016\/j.cie.2010.12.003"},{"key":"JCIT.2018070104-31","doi-asserted-by":"publisher","DOI":"10.1111\/j.1540-5915.2012.00361.x"},{"issue":"8","key":"JCIT.2018070104-32","doi-asserted-by":"crossref","first-page":"15","DOI":"10.22215\/timreview\/712","article-title":"Quantitative metrics and risk assessment: The three tenets model of cybersecurity.","volume":"3","author":"J.Hughes","year":"2013","journal-title":"Technology Innovation Management Review"},{"key":"JCIT.2018070104-33","doi-asserted-by":"crossref","first-page":"66","DOI":"10.1145\/373256.373266","article-title":"Access control mechanisms for inter-organizational workflow.","author":"M. H.Kang","year":"2001","journal-title":"Proceedings of the sixth ACM symposium on Access control models and technologies"},{"issue":"3","key":"JCIT.2018070104-34","first-page":"163","article-title":"Effective information security requires a balance of social and technology factors.","volume":"9","author":"T.Kayworth","year":"2010","journal-title":"MIS Quarterly Executive"},{"key":"JCIT.2018070104-35","doi-asserted-by":"publisher","DOI":"10.1377\/hlthaff.2012.0693"},{"key":"JCIT.2018070104-36","doi-asserted-by":"publisher","DOI":"10.1201\/1086.1065898X\/46353.15.4.20060901\/95124.6"},{"key":"JCIT.2018070104-37","doi-asserted-by":"publisher","DOI":"10.14569\/IJACSA.2011.021216"},{"key":"JCIT.2018070104-38","doi-asserted-by":"publisher","DOI":"10.1016\/j.telpol.2012.04.011"},{"key":"JCIT.2018070104-39","doi-asserted-by":"publisher","DOI":"10.2308\/isys-50339"},{"key":"JCIT.2018070104-40","doi-asserted-by":"publisher","DOI":"10.1145\/1029208.1029219"},{"key":"JCIT.2018070104-41","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2004.17"},{"key":"JCIT.2018070104-42","doi-asserted-by":"publisher","DOI":"10.1108\/IJCHM-08-2013-0367"},{"key":"JCIT.2018070104-43","doi-asserted-by":"publisher","DOI":"10.1109\/HICSS.2013.192"},{"key":"JCIT.2018070104-44","doi-asserted-by":"publisher","DOI":"10.1016\/j.chb.2015.08.011"},{"key":"JCIT.2018070104-45","doi-asserted-by":"publisher","DOI":"10.1109\/ICEIE.2010.5559829"},{"key":"JCIT.2018070104-46","doi-asserted-by":"publisher","DOI":"10.1109\/TSMCB.2012.2223671"},{"key":"JCIT.2018070104-47","doi-asserted-by":"publisher","DOI":"10.4156\/jcit.vol6.issue3.16"},{"key":"JCIT.2018070104-48","doi-asserted-by":"publisher","DOI":"10.1109\/21.87067"},{"key":"JCIT.2018070104-49","first-page":"303","article-title":"The inevitability of failure: The flawed assumption of security in modern computing environments.","volume":"Vol. 10","author":"P. A.Loscocco","year":"1998","journal-title":"Proceedings of the 21st National Information Systems Security Conference"},{"key":"JCIT.2018070104-50","doi-asserted-by":"publisher","DOI":"10.1111\/isj.12063"},{"key":"JCIT.2018070104-51","doi-asserted-by":"publisher","DOI":"10.1108\/09685220810893207"},{"key":"JCIT.2018070104-52","author":"F.Macedo","year":"2012","journal-title":"Comparative study of information security risk assessment models"},{"key":"JCIT.2018070104-53","doi-asserted-by":"publisher","DOI":"10.1016\/S0167-4048(02)00109-8"},{"key":"JCIT.2018070104-54","doi-asserted-by":"publisher","DOI":"10.1016\/j.dss.2012.12.036"},{"key":"JCIT.2018070104-55","doi-asserted-by":"publisher","DOI":"10.1108\/14684520710832333"},{"key":"JCIT.2018070104-56","unstructured":"Mell, P., Scarfone, K., & Romanosky, S. (2007, June). A complete guide to the common vulnerability scoring system version 2.0. FIRST-Forum of Incident Response and Security Teams."},{"key":"JCIT.2018070104-57","doi-asserted-by":"publisher","DOI":"10.1007\/s10796-015-9572-3"},{"key":"JCIT.2018070104-58","doi-asserted-by":"publisher","DOI":"10.1016\/j.asoc.2011.01.027"},{"key":"JCIT.2018070104-59","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2013.12.003"},{"key":"JCIT.2018070104-60","doi-asserted-by":"publisher","DOI":"10.1109\/ICCONS.2017.8250682"},{"key":"JCIT.2018070104-61","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4471-4189-1_1"},{"key":"JCIT.2018070104-62","doi-asserted-by":"publisher","DOI":"10.1109\/91.324809"},{"key":"JCIT.2018070104-63","doi-asserted-by":"publisher","DOI":"10.1016\/j.jsis.2014.01.002"},{"key":"JCIT.2018070104-64","doi-asserted-by":"publisher","DOI":"10.1080\/18756891.2009.9727665"},{"key":"JCIT.2018070104-65","first-page":"1","article-title":"Developing an Information Security and Risk Management Strategy.","volume":"2","author":"J. P.Pironti","year":"2010","journal-title":"ISACA Journal"},{"issue":"1","key":"JCIT.2018070104-66","first-page":"58","article-title":"A study of various approaches to assess and provide web based application security.","volume":"2","author":"D.Pramod","year":"2011","journal-title":"International Journal of Innovation, Management and Technology"},{"issue":"4","key":"JCIT.2018070104-67","first-page":"122","article-title":"Incorporating security into Web Applications-An Aspect oriented approach. International Journal of Management","volume":"2","author":"D.Pramod","year":"2012","journal-title":"IT and Engineering"},{"issue":"11","key":"JCIT.2018070104-68","first-page":"1852","article-title":"A Fuzzy Petri-Net Model for Predicting the Post-Implementation Risks of ERP in Small and Medium Enterprises.","volume":"9","author":"D.Pramod","year":"2014","journal-title":"International Review on Computers and Software"},{"issue":"23","key":"JCIT.2018070104-69","first-page":"19133","article-title":"A study on the user perception and awareness of smartphone security.","volume":"9","author":"D.Pramod","year":"2014","journal-title":"International Journal of Applied Engineering Research"},{"issue":"3","key":"JCIT.2018070104-70","first-page":"2262","article-title":"An aspect oriented process based approach to information risk management.","volume":"5","author":"D.Pramod","year":"2013","journal-title":"IACSIT International Journal of Engineering and Technology"},{"key":"JCIT.2018070104-71","doi-asserted-by":"publisher","DOI":"10.7763\/IJCEE.2009.V1.69"},{"key":"JCIT.2018070104-72","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-13241-4_11"},{"issue":"2","key":"JCIT.2018070104-73","first-page":"53","article-title":"A study on data privacy, protection& sanitization practices during disk disposal by Indian Educational Institutes.","volume":"10","author":"R.Raman","year":"2013","journal-title":"International Journal of Computer Science Issues"},{"key":"JCIT.2018070104-74","doi-asserted-by":"publisher","DOI":"10.4067\/S0718-18762017000300003"},{"key":"JCIT.2018070104-75","doi-asserted-by":"publisher","DOI":"10.1287\/isre.1080.0174"},{"key":"JCIT.2018070104-76","doi-asserted-by":"publisher","DOI":"10.4018\/IJISCRAM.2015070105"},{"key":"JCIT.2018070104-77","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2011.12.001"},{"key":"JCIT.2018070104-78","doi-asserted-by":"crossref","unstructured":"Rothlin, S., & McCann, D. (2016). The Social Environment: Ethics and Information Technology. In International Business Ethics (pp. 341-363). Springer Berlin Heidelberg.","DOI":"10.1007\/978-3-662-47434-1_16"},{"key":"JCIT.2018070104-79","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2015.10.006"},{"key":"JCIT.2018070104-80","doi-asserted-by":"publisher","DOI":"10.1016\/j.ejor.2014.09.055"},{"key":"JCIT.2018070104-81","doi-asserted-by":"publisher","DOI":"10.1108\/02644401011029925"},{"key":"JCIT.2018070104-82","doi-asserted-by":"publisher","DOI":"10.1109\/TITB.2009.2021065"},{"key":"JCIT.2018070104-83","author":"T.Shimeall","year":"2013","journal-title":"Introduction to Information Security: A Strategic-based Approach"},{"key":"JCIT.2018070104-84","doi-asserted-by":"publisher","DOI":"10.1007\/s40171-013-0047-4"},{"key":"JCIT.2018070104-85","doi-asserted-by":"publisher","DOI":"10.1057\/ejis.2012.59"},{"key":"JCIT.2018070104-86","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijinfomgt.2015.11.009"},{"key":"JCIT.2018070104-87","doi-asserted-by":"publisher","DOI":"10.1016\/j.accinf.2012.06.007"},{"key":"JCIT.2018070104-88","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4614-3558-7_2"},{"key":"JCIT.2018070104-89","doi-asserted-by":"publisher","DOI":"10.1109\/TPWRS.2004.836256"},{"key":"JCIT.2018070104-90","doi-asserted-by":"publisher","DOI":"10.19026\/rjaset.9.1430"},{"issue":"14","key":"JCIT.2018070104-91","first-page":"1","article-title":"Survey on fuzzy Petri nets for classification.","volume":"8","author":"S. M.Taj","year":"2015","journal-title":"Indian Journal of Science and Technology"},{"key":"JCIT.2018070104-92","doi-asserted-by":"crossref","unstructured":"Taylor, R. G. (2015). Potential Problems with Information Security Risk Assessments. Information Security Journal: A Global Perspective, 24(4-6), 177-184.","DOI":"10.1080\/19393555.2015.1092620"},{"key":"JCIT.2018070104-93","doi-asserted-by":"publisher","DOI":"10.1109\/TPWRS.2008.2002298"},{"key":"JCIT.2018070104-94","doi-asserted-by":"publisher","DOI":"10.1057\/ejis.2013.27"},{"key":"JCIT.2018070104-95","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2004.01.012"},{"key":"JCIT.2018070104-96","doi-asserted-by":"publisher","DOI":"10.1109\/TIE.2009.2020077"},{"key":"JCIT.2018070104-97","doi-asserted-by":"publisher","DOI":"10.3923\/itj.2012.396.398"},{"key":"JCIT.2018070104-98","doi-asserted-by":"publisher","DOI":"10.1109\/APSCC.2006.57"},{"key":"JCIT.2018070104-99","doi-asserted-by":"publisher","DOI":"10.1016\/S0167-4048(02)00414-5"},{"key":"JCIT.2018070104-100","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2014.04.005"},{"key":"JCIT.2018070104-101","first-page":"1","article-title":"Towards an intelligence-driven information security risk management process for organisations.","author":"J.Webb","year":"2013","journal-title":"24th Australasian Conference on Information Systems (ACIS)"},{"key":"JCIT.2018070104-102","doi-asserted-by":"publisher","DOI":"10.1016\/S1363-4127(01)00309-0"},{"key":"JCIT.2018070104-103","doi-asserted-by":"publisher","DOI":"10.1016\/0167-4048(87)90066-6"},{"issue":"2","key":"JCIT.2018070104-104","first-page":"50","article-title":"An Empirical Examination of the Relationship Between Information Security\/Business Strategic Alignment and Information Security Governance Domain Areas. Journal of Business Systems","volume":"9","author":"W.Yaokumah","year":"2014","journal-title":"Governance and Ethics"},{"key":"JCIT.2018070104-105","doi-asserted-by":"publisher","DOI":"10.1016\/j.hrmr.2012.06.010"},{"key":"JCIT.2018070104-106","doi-asserted-by":"publisher","DOI":"10.3923\/itj.2012.500.503"},{"key":"JCIT.2018070104-107","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-015-9451-9"}],"container-title":["Journal of Cases on Information Technology"],"original-title":[],"language":"ng","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=207366","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,6]],"date-time":"2022-05-06T19:46:09Z","timestamp":1651866369000},"score":1,"resource":{"primary":{"URL":"https:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/JCIT.2018070104"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2018,7,1]]},"references-count":108,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2018,7]]}},"URL":"https:\/\/doi.org\/10.4018\/jcit.2018070104","relation":{},"ISSN":["1548-7717","1548-7725"],"issn-type":[{"value":"1548-7717","type":"print"},{"value":"1548-7725","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018,7,1]]}}}