A metric-driven IT risk scoring framework: incorporating contextual and organizational factors
| dc.authorid | 0009-0009-4710-2569 | |
| dc.authorid | 0000-0003-2865-6370 | |
| dc.contributor.author | Ünal, Nezih Mahmut | en_US |
| dc.contributor.author | Çeliktaş, Barış | en_US |
| dc.date.accessioned | 2025-10-21T06:36:48Z | |
| dc.date.available | 2025-10-21T06:36:48Z | |
| dc.date.issued | 2025-09-24 | |
| dc.department | Işık Üniversitesi, Lisansüstü Eğitim Enstitüsü, Bilgisayar Mühendisliği Yüksek Lisans Programı | en_US |
| dc.department | Işık University, School of Graduate Studies, Master’s Program in Computer Engineering | en_US |
| dc.department | Işık Üniversitesi, Mühendislik ve Doğa Bilimleri Fakültesi, Bilgisayar Mühendisliği Bölümü | en_US |
| dc.department | Işık University, Faculty of Engineering and Natural Sciences, Department of Computer Engineering | en_US |
| dc.description.abstract | Risk analysis is a critical process for organizations seeking to manage their cybersecurity posture effectively. However, traditional risk analysis frameworks, such as the Common Vulnerability Scoring System (CVSS), primarily evaluate technical impacts without incorporating organizational context and dynamic risk factors. This paper presents a metric-based risk analysis framework designed to provide a more adaptable and context-aware risk-scoring framework. The proposed model enables risk owners to define customized threat scenarios and dynamically adjust metric weights based on organizational needs. Unlike traditional approaches, our method integrates contextual parameters to improve the accuracy and relevance of risk calculations. Experimental evaluations demonstrate that the proposed framework enhances risk prioritization and provides more actionable insights for decision-makers. This study contributes to the field by addressing the limitations of existing risk analysis models and offering a systematic approach for cybersecurity risk management. | en_US |
| dc.description.version | Publisher's Version | en_US |
| dc.identifier.citation | Ünal, N. M. & Çeliktaş, B. (2025). A metric-driven IT risk scoring framework: incorporating contextual and organizational factors. Paper presented at the 2025 International Conference on Artificial Intelligence, Computer, Data Sciences and Applications (ACDSA), 1-7. doi:https://doi.org/10.1109/ACDSA65407.2025.11166074 | en_US |
| dc.identifier.doi | 10.1109/ACDSA65407.2025.11166074 | |
| dc.identifier.endpage | 7 | |
| dc.identifier.isbn | 9798331535629 | |
| dc.identifier.isbn | 9798331535636 | |
| dc.identifier.scopus | 2-s2.0-105018467434 | |
| dc.identifier.scopusquality | N/A | |
| dc.identifier.startpage | 1 | |
| dc.identifier.uri | https://hdl.handle.net/11729/6762 | |
| dc.identifier.uri | https://doi.org/10.1109/ACDSA65407.2025.11166074 | |
| dc.indekslendigikaynak | Scopus | en_US |
| dc.institutionauthor | Ünal, Nezih Mahmut | en_US |
| dc.institutionauthor | Çeliktaş, Barış | en_US |
| dc.institutionauthorid | 0009-0009-4710-2569 | |
| dc.institutionauthorid | 0000-0003-2865-6370 | |
| dc.language.iso | en | en_US |
| dc.peerreviewed | Yes | en_US |
| dc.publicationstatus | Published | en_US |
| dc.publisher | Institute of Electrical and Electronics Engineers Inc. | en_US |
| dc.relation.ispartof | 2025 International Conference on Artificial Intelligence, Computer, Data Sciences and Applications (ACDSA) | en_US |
| dc.relation.publicationcategory | Konferans Öğesi - Uluslararası - Öğrenci | en_US |
| dc.relation.publicationcategory | Konferans Öğesi - Uluslararası - Kurum Öğretim Elemanı | en_US |
| dc.rights | info:eu-repo/semantics/closedAccess | en_US |
| dc.subject | CVSS | en_US |
| dc.subject | Cybersecurity | en_US |
| dc.subject | Qualitative | en_US |
| dc.subject | Risk analysis | en_US |
| dc.subject | Risk scoring | en_US |
| dc.subject | Factor analysis | en_US |
| dc.subject | Risk assessment | en_US |
| dc.subject | Risk management | en_US |
| dc.subject | Risk perception | en_US |
| dc.subject | Analysis frameworks | en_US |
| dc.subject | Common vulnerability scoring systems | en_US |
| dc.subject | Contextual factors | en_US |
| dc.subject | Organizational context | en_US |
| dc.subject | Organizational dynamics | en_US |
| dc.subject | Organizational factors | en_US |
| dc.subject | Qualitative | en_US |
| dc.subject | Risk analyze | en_US |
| dc.title | A metric-driven IT risk scoring framework: incorporating contextual and organizational factors | en_US |
| dc.type | Conference Object | en_US |
| dspace.entity.type | Publication | en_US |
Dosyalar
Orijinal paket
1 - 1 / 1
Küçük Resim Yok
- İsim:
- A_Metric_Driven_IT_Risk_Scoring_Framework_Incorporating_Contextual_and_Organizational_Factors.pdf
- Boyut:
- 267.5 KB
- Biçim:
- Adobe Portable Document Format
Lisans paketi
1 - 1 / 1
Küçük Resim Yok
- İsim:
- license.txt
- Boyut:
- 1.17 KB
- Biçim:
- Item-specific license agreed upon to submission
- Açıklama:












