International Journal of Computer Applications
Information security control assessment provides a comprehensive control analysis approach to assist an organization in measuring the effectiveness of its current and planned security controls. ISO/IEC 27005 is a risk management framework that can manage and treat risks in organizations. However, ISO/IEC 27005 does not define a clear guideline on how to select and prioritize information security control despite the need for an efficient security analysis method. The ISO 27005 framework mostly depends on subjective judgment and qualitative approaches for security control analysis.