DECISION MODELING BASED APPROACH TO THE BS 7799 DEPLOYMENT

Summary: The paper describes decision modeling based approach to the BS 7799 deployment. First we briefly introduce why BS 7799 is important in the age of Electronic Commerce. Then we identify limitations that characterize risk driven approach to the BS 7799 deployment. We argue that these limitations can be overcome with decision modeling based approach using AHP hierarchy. This hierarchy includes two types of criteria levels – static and dynamic. Decision making model that uses this hierarchy includes three particular processes: BS 7799 Deployment Modeling, Risk Driven Countermeasure (RDC) generation and Human Resource Allocation Alternatives (HRAA) generation process. Our approach is supported with three powerful tools to achieve appropriate quality of decisions and performance. BS 7799 Deployment Modeling uses EC 2000, RDC process uses CRAMM and HRAA generation is based on GUHA. Proposed decision modeling approach controls interactions between all three tools and generates final objective – optimal BS 7799 deployment.