Multicriteria Decision Analysis on Information Security Policy: A Prioritization Approach

  • Jonathan Salar Cabrera Institute of Computing and Engineering, Davao Oriental State College of Science and Technology, Philippines
  • Ariel Roy Luceño Reyes College of Information and Computing, University of Southeastern Philippines, Philippines
  • Cindy Almosura Lasco Institute of Computing and Engineering, Davao Oriental State College of Science and Technology, Philippines
Keywords: analytic hierarchy process, evaluation process, information security, prioritization


Security is the most serious concern in the digital environment. To provide a sound and firm security policy, a multi-holistic approach must be considered when making strategic decisions. Thus, the objective of this study was to evaluate the information security (IS) and decision making of Davao Oriental State University (DORSU) using the analytic hierarchy process (AHP) approach. The four aspects of IS, namely, the technology, management, economy, and culture were used with the three IS components consisting of confidentiality, integrity, and availability to implement the AHP. The results showed that the technology and management have higher significant values than the economic and cultural aspects. Meanwhile, for the IS components, the integrity signifies the highest priority followed by confidentiality, lastly, and availability. These results emphasize an imbalance in implementing IS policy, which must be addressed to ensure that the data integrity, confidentiality, and availability are balanced, particularly during the information exchange transactions.


