RISK ASSESSMENT MODEL FOR ORGANIZATIONAL INFORMATION SECURITY Balla
@inproceedings{Dioubate2015RISKAM, title={RISK ASSESSMENT MODEL FOR ORGANIZATIONAL INFORMATION SECURITY Balla}, author={Moussa Dioubate and Nurul Nuha Abdul Molok and Shuhaili Talib and Abu Osman Md. Tap}, year={2015} }
Information security risk assessment (RA) plays an important role in the organization’s future strategic planning. Generally there are two types of RA approaches: quantitative RA and qualitative RA. The quantitative RA is an objective study of the risk that use numerical data. On the other hand, the qualitative RA is a subjective evaluation based on judgment and experiences which does not operate on numerical data. It is difficult to conduct a purely quantitative RA method, because of the…
References
SHOWING 1-10 OF 19 REFERENCES
A Quantitative Model for Information-Security Risk Management
- Computer Science, Economics
- 2012
The proposed model for managing information-security risks is based on a quantitative analysis of the security risks that enable organizations to introduce optimum security solutions and is designed as a standard procedure to lead the organization from the initial selection of input data to the final recommendations for the selection of the appropriate solutions.
Information Security Risk Assessment: Towards a Business Practice Perspective
- Computer Science, BusinessAISM 2010
- 2010
It is suggested that a business practice perspective be incorporated into ISRA methods in order to identify information leakage, unofficial, critical information assets and critical process knowledge of organisations.
Information risk management: Qualitative or quantitative? Cross industry lessons from medical and financial fields
- Business
- 2011
Enterprises across the world are taking a hard look at their risk management practices. A number of qualitative and quantitative models and approaches are employed by risk practitioners to keep risk…
Quantitative Model for Economic Analyses of Information Security Investment in an Enterprise Information System
- Computer Science, Economics
- 2012
A mathematical model is presented for the optimal security-technology investment evaluation and decision-making processes based on the quantitative analysis of security risks and digital asset assessments in an enterprise that allows direct comparison and quantitative assessment of different security measures.
Information Security Risk Analysis Methods and Research Trends: AHP and Fuzzy Comprehensive Method
- Computer Science
- 2014
Development and application of soft computing such as rough sets, grey sets, fuzzy systems, generic algorithm, support vector machine, and Bayesian network and hybrid model are developed.
A Model-based Information Security Risk Assessment Method for Science Gateways
- Computer ScienceIWSG
- 2013
A novel method to do risk assessments: MISRAM, the Model-based Information Security Risk Assessment Method, which uses an information architecture model, a method to assign values to information assets and IT components, and a methods to calculate risks.
QUIRC: A Quantitative Impact and Risk Assessment Framework for Cloud Security
- Computer Science2010 IEEE 3rd International Conference on Cloud Computing
- 2010
A quantitative risk and impact assessment framework (QUIRC) is presented, which enables stakeholders to comparatively assess the relative robustness of different cloud vendor offerings and approaches in a defensible manner.
RISK MANAGEMENT AND INFORMATION TECHNOLOGY PROJECTS
- Engineering, Computer Science
- 2014
The main focus of this paper is to investigate the impacts of Knowledge Management (KM) on Risk Management (RM) in IT project implementation process.
The Quantification Management of Information Security Risk
- Computer Science2008 4th International Conference on Wireless Communications, Networking and Mobile Computing
- 2008
This article quantifies the risk from the angle of view of financial risk and refers to the mature quantitative models and methods that will promote the development of information security risk management as well as integration with other financial risks.