article · Engineering Technology & Applied Science Research
Information Security Risk Management (ISRM) is an essential requirement for organizations seeking to ensure the governance and protection of their information assets. Ontology-based knowledge representation has emerged as a promising solution to address information security challenges, as it enables the formalization of concepts, relationships, and constraints within a given domain. This paper proposes an ontology-based framework aligned with the ISO/IEC 27002 standard. The approach consists of extracting relevant concepts from textual sources using UML modeling and TF-IDF filtering, and representing them in OWL using the Protégé environment. The resulting ontology formally captures key ISRM entities—including assets, threats, vulnerabilities, risks, controls, and monitoring mechanisms. The ontology was validated using the FACT++ reasoner to assess consistency and semantic completeness. The results show that the proposed model ensures traceability across ISO/IEC 27002 control families, supports governance alignment, and improves visibility across risk treatment processes.
This page summarises published work. The authoritative version sits with the publisher.
DOI: 10.48084/etasr.15794
Is something wrong with this record? Report it or request removal.
Discussion
Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.
No discussion yet. Open the first thread.
New to MARATTO™? Create a free account.