A neutrosophic framework for evaluating security measures in information systems

نویسندگان

1 Regional Autonomous University of the Andes, Tulcan, Carchi, Ecuador.

2 Regional Autonomous University of the Andes, Tulcan, Carchi, Ecuador.

3 Regional Autonomous University of the Andes, Tulcan, Carchi, Ecuador.

4 Regional Autonomous University of the Andes, Tulcan, Carchi, Ecuador.

doi
10.22105/jfea.2024.468184.1546
چکیده

This study introduces a neutrosophic framework combined with the multi-attribute decision-making methods TODIM and PROMETHEE to evaluate security measures in information systems. Addressing the inherent uncertainty and complexity of cybersecurity challenges, this research focuses on optimizing decision-making processes by leveraging the unique capabilities of neutrosophic logic. The study identifies a critical gap in existing literature, where comprehensive evaluations of cybersecurity measures often overlook the dynamic and uncertain nature of threats. By integrating expert assessments with neutrosophic numbers, the framework captures truth, indeterminacy, and falsity in decision-making, ensuring a more nuanced evaluation. The results reveal that access policies and privilege control are the most effective measures, followed by continuous monitoring and personnel training. This approach not only enhances the prioritization of security strategies but also demonstrates the applicability of neutrosophic methods in complex decision environments. The study contributes a replicable methodology for improving cybersecurity measures in other domains, thereby advancing data protection strategies and decision analysis under uncertainty.