An expert system for risk assessment of information system security based on ISO 27002 | IEEE Conference Publication | IEEE Xplore