2017
DOI: 10.1007/s10207-017-0382-0
|View full text |Cite
|
Sign up to set email alerts
|

A framework for estimating information security risk assessment method completeness

Abstract: In general, an information security risk assessment (ISRA) method produces risk estimates, where risk is the product of the probability of occurrence of an event and the associated consequences for the given organization. ISRA practices vary among industries and disciplines, resulting in various approaches and methods for risk assessments. There exist several methods for comparing ISRA methods, but these are scoped to compare the content of the methods to a predefined set of criteria, rather than process tasks… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1

Citation Types

0
58
0
1

Year Published

2017
2017
2023
2023

Publication Types

Select...
5
1
1

Relationship

3
4

Authors

Journals

citations
Cited by 73 publications
(75 citation statements)
references
References 20 publications
0
58
0
1
Order By: Relevance
“…This scheme makes them less suited for analyzing cause-effect relationships between method and results, since causes not present in the criteria may be neglected. The CURF bottom-up approach [5] solves this problem by mapping ISRA method content and using it as comparison criteria. For each added method reviewed in CURF, we identify which tasks the approach covers and combine all the tasks covered by all surveyed methods into a combined set.…”
Section: B Curf and Included Isra Methodsmentioning
confidence: 99%
See 3 more Smart Citations
“…This scheme makes them less suited for analyzing cause-effect relationships between method and results, since causes not present in the criteria may be neglected. The CURF bottom-up approach [5] solves this problem by mapping ISRA method content and using it as comparison criteria. For each added method reviewed in CURF, we identify which tasks the approach covers and combine all the tasks covered by all surveyed methods into a combined set.…”
Section: B Curf and Included Isra Methodsmentioning
confidence: 99%
“…The row scores reveal how well the ISRA methods scored overall. The three ISRA methods included in this study was also used as input for developing CURF (see [5]), following is a summary of each method and their differences.…”
Section: B Curf and Included Isra Methodsmentioning
confidence: 99%
See 2 more Smart Citations
“…There several tasks that are common when conducting an ISRAn [17], we gathered the common denominators and asked the participants to rate them according to their importance, 1 -Not important to 6 -Very important. Table XIV displays the results, with no notable difference between any groups.…”
Section: F What Is the Most Important Task Of The Isra?mentioning
confidence: 99%