Data security risk assessment method based on AHP-TOPSIS fusion model
Online published: 2026-06-01
Copyright
With the in-depth development of digital transformation, data security risk assessment is confronted with challenges such as incomplete assessment indicators, strong subjectivity in weight distribution, and non-intuitive risk ranking. This paper proposes a data security risk assessment model integrating analytic hierarchy process (AHP) and technique for order preference by similarity to ideal solution (TOPSIS). Based on the national standard GB/T45577-2025, an assessment system is established covering three primary indicators including data security management, data processing activity security and data security technology, as well as 24 secondary indicators. Secondly, the double-layer AHP method is used to calculate index weights, and subjective deviation is reduced via expert scoring and consistency test. Finally, TOPSIS is adopted to comprehensively rank hazard degrees of different data security risks and realize quantitative assessment of data security risks. Case analysis shows that this model can effectively identify hazard degrees of various data security risks, providing a scientific basis for decision-making of data security risk management.
Key words: data security; risk assessment; quantitative assessment; AHP; TOPSIS
Chen Lin , Liu Xize , Li Shaohu , Guo Chong . Data security risk assessment method based on AHP-TOPSIS fusion model[J]. Journal of Cybersecurity, 2026 . DOI: 10.20172/j.issn.2097-3136.260525
表 2 比较判断矩阵元素取值Table 2 Values of the elements in the comparison judgment matrix |
| 取值含义 | |
| 1 | 指标i与j指标同等重要 |
| 3 | 指标i比j指标略微重要 |
| 5 | 指标i比j指标明显重要 |
| 7 | 指标i比j指标特别重要 |
| 9 | 指标i比j指标极其重要 |
| 2,4,6,8 | 介于对应判断之间 |
| 对应倒数 | 指标j与指标i重要性之比: |
表 3 一致指标取值Table 3 Value of the consistent index |
| n | RI | n | RI |
| 1 | 0 | 6 | 1.26 |
| 2 | 0 | 7 | 1.36 |
| 3 | 0.52 | 8 | 1.41 |
| 4 | 0.90 | 9 | 1.46 |
| 5 | 1.12 | 10 | 1.49 |
表 4 数据安全风险影响因素评价分数矩阵Table 4 Data security risk influencing factors evaluation score matrix |
| 防护程度 | 严重缺陷 | 基本不足 | 较好 | 最佳实践 |
| 高敏感 | 0 | 2 | 4 | 6 |
| 较高敏感 | 1 | 3 | 5 | 7 |
| 一般敏感 | 2 | 4 | 6 | 8 |
| 低敏感 | 3 | 5 | 7 | 9 |
表 5 数据资产敏感度分级标准Table 5 Data asset sensitivity classification criteria |
| 敏感度等级 | 判定依据 | 典型示例 | 评分等级 |
| 高敏感 | 涉及核心业务运行或大规模个人敏感信息,数据泄露 可能造成重大经济损失、法律风险或社会影响 | 大规模用户身份信息、金融交易数据、核心业务 数据库、关键基础设施运行数据 | 0 |
| 较高敏感 | 与重要业务决策或经营活动相关,泄露可能影响企业 竞争力或客户利益 | 企业经营数据、供应链数据、客户交易记录、 跨部门共享业务数据 | 1 |
| 一般敏感 | 与日常业务管理相关,但泄露后影响相对有限 | 内部管理文件、普通业务记录、一般业务统计数据 | 2 |
| 低敏感 | 数据公开性较高或泄露后影响较小 | 公开资料、已发布报告、非敏感统计信息 | 3 |
表 6 安全防护措施实施程度分级标准Table 6 Classification criteria for security protection implementation Levels |
| 防护实施等级 | 判定证据 | 典型表现 | 对应等级 |
| 严重缺陷 | 关键安全控制未部署或制度缺失 | 未建立数据安全管理制度,无访问控制策略,无日志审计 | 严重缺陷 |
| 基本不足 | 已部署部分安全措施,但覆盖不足 或执行不稳定 | 有基础安全制度,但部分系统未实施访问控制或安全监测 | 基本不足 |
| 较好 | 主要安全控制已部署并稳定运行 | 建立较完善的管理制度,具备访问控制、日志审计和漏洞扫描机制 | 较好 |
| 最佳实践 | 形成完整安全治理体系并持续改进 | 建立制度—执行—监测—整改闭环机制,并具备持续安全监测能力 | 最佳实践 |
表 7 数据安全风险评估指标体系各风险评分以及二级指标权重Table 7 Scores of each scheme and the weights of secondary indicators in the data security risk assessment indicator system |
| 一级指标 | 二级指标 | 风险A | 风险B | 风险C | 风险D | 权重 |
| 数据安全 管理 (U1) | 数据安全管理制度 | 9 | 7 | 8 | 6 | 0.12 |
| 安全组织机构 | 8 | 7 | 8 | 6 | 0.10 | |
| 分类分级管理 | 9 | 8 | 7 | 6 | 0.14 | |
| 人员安全管理 | 8 | 6 | 7 | 5 | 0.11 | |
| 合作外包管理 | 8 | 5 | 7 | 6 | 0.09 | |
| 安全威胁和应急管理 | 9 | 7 | 9 | 6 | 0.15 | |
| 开发运维管理 | 8 | 7 | 8 | 6 | 0.11 | |
| 云数据安全 | 8 | 6 | 8 | 7 | 0.12 | |
| 数据处理 活动安全 (U2) | 数据收集安全 | 9 | 8 | 7 | 6 | 0.12 |
| 数据存储安全 | 9 | 8 | 8 | 6 | 0.15 | |
| 数据使用和加工安全 | 8 | 7 | 6 | 5 | 0.11 | |
| 数据提供安全 | 8 | 7 | 6 | 5 | 0.12 | |
| 数据公开安全 | 7 | 6 | 5 | 5 | 0.10 | |
| 数据删除安全 | 8 | 7 | 6 | 5 | 0.12 | |
| 其他数据处理活动安全 | 7 | 6 | 5 | 5 | 0.11 | |
| 数据处理合规性 | 9 | 8 | 7 | 6 | 0.14 | |
| 数据安全 技术 (U3) | 网络安全防护 | 9 | 8 | 9 | 7 | 0.13 |
| 身份鉴别与访问控制 | 9 | 9 | 8 | 7 | 0.15 | |
| 监测预警 | 8 | 9 | 7 | 6 | 0.13 | |
| 数据脱敏 | 8 | 7 | 6 | 5 | 0.12 | |
| 数据防泄露 | 9 | 8 | 7 | 6 | 0.14 | |
| 数据接口安全 | 8 | 7 | 6 | 6 | 0.11 | |
| 数据备份恢复 | 7 | 8 | 9 | 7 | 0.12 | |
| 安全审计 | 7 | 9 | 8 | 6 | 0.13 |
表 8 各风险在一级指标层的加权得分Table 8 Weighted scores of each plan at the first-level indicator level |
| 风险类别 | 数据安全 管理(U1) | 数据处理活 动安全(U2) | 数据安全 技术(U3) |
| 数据泄露风险 | 8.4 | 8.0 | 8.3 |
| 数据篡改风险 | 7.3 | 7.0 | 8.0 |
| 数据破坏风险 | 8.5 | 6.8 | 7.5 |
| 数据丢失风险 | 6.4 | 6.0 | 5.8 |
表 9 基于TOPSIS的综合评价结果Table 9 Comprehensive evaluation results based on TOPSIS |
| 风险类别 | 综合得分 | 排名 | ||
| 数据泄露风险 | 0.010 | 0.135 | 0.929 | 1 |
| 数据破坏风险 | 0.090 | 0.080 | 0.471 | 2 |
| 数据篡改风险 | 0.080 | 0.100 | 0.453 | 3 |
| 数据丢失风险 | 0.120 | 0.000 | 0.000 | 4 |
表 10 不同赋权方法下一级指标权重对比Table 10 Comparison of first-level indicator weights under different weighting methods |
| 赋权方法 | 数据资产 敏感度 | 安全脆 弱性 | 威胁可利 用性 |
| AHP主观权重 | 0.500 | 0.280 | 0.220 |
| 熵权法客观权重 | 0.313 | 0.254 | 0.433 |
| 组合权重( | 0.369 | 0.262 | 0.369 |
| 组合权重( | 0.407 | 0.267 | 0.326 |
| 组合权重( | 0.444 | 0.272 | 0.284 |
表 11 不同赋权方法下TOPSIS综合评价结果对比Table 11 Comparison of TOPSIS comprehensive evaluation results under different weighting methods |
| 风险类型 | AHP-TOPSIS 贴近度 | 螪权-TOPSIS 贴近度 | |
| 数据泄露风险 | |||
| 数据复改风险 | |||
| 数据破坏风险 | |||
| 数据丢失风险 |
表 12 动态修正示例指标评分变化Table 12 Example of indicator score adjustment based on dynamic correction mechanism |
| 指标 | 初始评分 | 防护提 升量 m(t) | 漏洞暴 露 v(t) | 告警强 度 a(t) | 修正后 评分 |
| 数据防泄露 | 9.0 | +0.5 | 0 | 0 | 9.0 |
| 身份鉴别与访问控制 | 9.0 | +0.3 | 0 | 0 | 9.0 |
| 网络安全防护 | 9.0 | 0 | 0.4 | 0.3 | 8.3 |
| 监测预警 | 8.0 | 0 | 0.2 | 0.4 | 7.4 |
表 13 不同方法下数据安全风险评估结果对比Table 13 Comparison of data security risk assessment results under different methods |
| 方法 | 数据泄露 风险 | 数据篡改 风险 | 数据破坏 风险 | 数据丢失 风险 |
| 单纯AHP(加权求和) | 8.266 | 7.370 | 7.804 | 6.156 |
| 等权TOPSIS | 0.975 | 0.618 | 0.648 | 0.000 |
| 熵权TOPSIS | 0.978 | 0.685 | 0.677 | 0.000 |
| 本文AHP-TOPSIS | 0.963 | 0.522 | 0.735 | 0.000 |
| 1 |
Ahmad Jan M, Adil M, Brik B, et al. Making sense of big data in intelligent transportation systems: current trends, challenges and future directions[J]. ACM Computing Surveys, 2025, 57 (8): 1- 43.
|
| 2 |
Demirbaga Ü, Aujla G S, Jindal A, et al. Cloud computing for big data analytics[M]//Big Data Analytics: Theory, Techniques, Platforms, and Applications. Cham: Springer Nature Switzerland, 2024: : 43-77.
|
| 3 |
Wang H C, Fu T F, Du Y Q, et al. Scientific discovery in the age of artificial intelligence[J]. Nature, 2023, 620 (7972): 47- 60.
|
| 4 |
Sun P J, Shen S G, Wan Y, et al. A survey of IoT privacy security: architecture, technology, challenges, and trends[J]. IEEE Internet of Things Journal, 2024, 11 (21): 34567- 34591.
|
| 5 |
Karpatne A, Deshwal A, Jia X W, et al. AI-enabled scientific revolution in the age of generative AI: second NSF workshop report[J]. npj Artificial Intelligence, 2025, 1, 18.
|
| 6 |
Wang D D, Yang T F. Research on the promotion effect of the marketization of data elements on the digital transformation of manufacturing enterprises: an empirical evaluation of a multiperiod DID model[J]. Sustainability, 2025, 17 (7): 3199.
|
| 7 |
LIU J, HAN T, ZHAO J, et al. An Intelligent Risk Assessment Methodology for the Full Lifecycle Security of Data[J]. Symmetry, 2025, 17 (6): 820.
|
| 8 |
Bhatt P, Valecha R, Rao H R. Situational awareness about data breaches and ransomware attacks: a multi-dimensional cyber threat impact framework and content analyses of practitioner-public discourses[J]. International Journal of Information Management, 2025, 83, 102902.
|
| 9 |
Badshah A, Daud A, Alharbey R, et al. Big data applications: overview, challenges and future[J]. Artificial Intelligence Review, 2024, 57 (11): 290.
|
| 10 |
Cheimonidis P, Rantos K. A novel proactive and dynamic cyber risk assessment methodology[J]. Computers & Security, 2025, 154, 104439.
|
| 11 |
Gao L J, Chen Z Y, Zhao W, et al. Does cybersecurity regulation reduce corporate data-breach risk[J]. Finance Research Letters, 2025, 78, 107171.
|
| 12 |
Lai L Y. Research and design of data security risk assessment model based on fusion of deep learning and analytic hierarchy process (AHP)[J]. Procedia Computer Science, 2025, 262, 747- 756.
|
| 13 |
Santos-Olmo A, Sánchez L E, Rosado D G, et al. Towards an integrated risk analysis security framework according to a systematic analysis of existing proposals[J]. Frontiers of Computer Science, 2024, 18 (3): 183808.
|
| 14 |
Zhang X, Shen W, Liang Z, et al. Data Security Risk Assessment Method Based on Big Data Technology[C]//2024 IEEE 16th International Conference on Computational Intelligence and Communication Networks (CICN). IEEE, 2024: 589-594.
|
| 15 |
Saeedi K, HASSAN M A, ALARIFI S, ALMAGWASHI H. An intuitive approach to cybersecurity risk assessment for non-governmental organizations[J]. Transforming Government: People, Process and Policy, 2025, 19 (1): 159- 182.
|
| 16 |
Azem Qashou A M, Bahar N, Mohamed H. Qualitative exploration of data security risks in mobile cloud computing for higher education[J]. Security and Privacy, 2025, 8 (2): e70001.
|
| 17 |
Shukla A, Katt B, Yamin M M. A quantitative framework for security assurance evaluation and selection of cloud services: a case study[J]. International Journal of Information Security, 2023, 22 (6): 1621- 1650.
|
| 18 |
ZHANG X, SHEN W, LIANG Z, et al. Data Security Risk Assessment Method Based on Big Data Technology[C]//2024 IEEE 16th International Conference on Computational Intelligence and Communication Networks (CICN). Indore, India: IEEE, 2024: 589-594. DOI: 10.1109/CICN63059.2024.10847402.
|
| 19 |
Moreira F, Canedo E, Nunes R, et al. Cybersecurity risk assessment through analytic hierarchy process: integrating multicriteria and sensitivity analysis[C]//Proceedings of the 27th International Conference on Enterprise Information Systems. SCITEPRESS - Science and Technology Publications, 2025: 117-128.
|
| 20 |
Wang K N, Hong Y, Li C X. Fuzzy risk assessment method for airborne network security based on AHP-TOPSIS[J]. Computers, Materials & Continua, 2024, 80(1): 1123-1142.
|
| 21 |
Kostelić K. TOPSIS-based framework for evaluating employee cybersecurity risk[J]. Croatian Operational Research Review, 2025, 16 (1): 31- 44.
|
| 22 |
Elder S, Rahman M R, Fringer G, et al. A survey on software vulnerability exploitability assessment[J]. ACM Computing Surveys, 2024, 56 (8): 1- 41.
|
| 23 |
Bhol S G. Applications of multi criteria decision making methods in cyber security[M]//Choudhury A, Kaushik K, Kumar V, et al. Cyber-Physical Systems Security: A Multi-disciplinary Approach. Singapore: Springer Nature Singapore, 2025: : 233-258.
|
| 24 |
Mohammed S, Oleiwi A K, kh Asman T, et al. A survey of MCDM-based software engineering method[J]. Babylonian Journal of Mathematics, 2024, 2024, 13- 18.
|
| 25 |
Adewuyi A A, Cheng H, Shi Q, et al. SC-TRUST: a dynamic model for trustworthy service composition in the Internet of Things[J]. IEEE Internet of Things Journal, 2022, 9 (5): 3298- 3312.
|
| 26 |
Guo C P, Wang X W, Chu P. Fuzzy AHP-based security evaluation for wireless integrated access system[C]//Proceedings of the 2021 International Conference on Intelligent Transportation, Big Data & Smart City (ICITBS). Piscataway: IEEE Press, 2021: 554-557.
|
| 27 |
Khan A W, Khan M U, Ali Khan J, et al. Identification and prioritization of security challenges of big data on cloud computing based on SLR: a fuzzy-TOPSIS analysis approach[J]. Journal of Software: Evolution and Process, 2021, 33 (12): e2387.
|
| 28 |
Guo L J, Yao Z Q, Lin M W, et al. Fuzzy TOPSIS-based privacy measurement in multiple online social networks[J]. Complex & Intelligent Systems, 2023, 9 (6): 6089- 6101.
|
| 29 |
Zhang Z H, Liu Z Y, Yang L, et al. Security risk assessment of image classification model based on ANP-TOPSIS[C]//Proceedings of the 2023 International Conference on Networking and Network Applications (NaNA). Piscataway: IEEE Press, 2023: 300-306.
|
| 30 |
Li X T. Personal information security risk assessment for E-waste recycling based on fuzzy–GRA–TOPSIS and FMEA[J]. IEEE Transactions on Engineering Management, 2024, 71, 8240- 8250.
|
/
| 〈 |
|
〉 |