2016
DOI: 10.2495/safe-v6-n2-270-281
|View full text |Cite
|
Sign up to set email alerts
|

A systematic review of information security risk assessment

Abstract: Many standards exist to guide the process of risk assessment, particularly in the field of information security. This leads to many, subtly different, definitions of risk analysis, evaluation and assessment. Consequently, researchers often confuse these terms and disciplines, which leads to further confusion within the community. In this sense, it is important to come to a common understanding of the processes and terminology to clarify research in this area. A common approach to achieve this goal is to carry … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
9
0
4

Year Published

2018
2018
2024
2024

Publication Types

Select...
4
2
2

Relationship

0
8

Authors

Journals

citations
Cited by 20 publications
(15 citation statements)
references
References 41 publications
(59 reference statements)
0
9
0
4
Order By: Relevance
“…En [60] se hace una revisión de las publicaciones científicas asociadas al análisis de riesgos, pero centradas en las metodologías NIST SP800-30, ISO27005/ISO27001, OCTAVE e ISRAM. Determina que estos mecanismos de análisis de riesgos tienen importantes carencias, como por ejemplo que no pueden abordar algunos factores importantes, como son la fuga de activos, los activos creados por los usuarios y el conocimiento crítico.…”
Section: Pan L and A Tomlinson "unclassified
See 2 more Smart Citations
“…En [60] se hace una revisión de las publicaciones científicas asociadas al análisis de riesgos, pero centradas en las metodologías NIST SP800-30, ISO27005/ISO27001, OCTAVE e ISRAM. Determina que estos mecanismos de análisis de riesgos tienen importantes carencias, como por ejemplo que no pueden abordar algunos factores importantes, como son la fuga de activos, los activos creados por los usuarios y el conocimiento crítico.…”
Section: Pan L and A Tomlinson "unclassified
“…• Los métodos deben tener mecanismos de soporte a la toma de decisiones [57]. • Los resultados del análisis de riesgos son informales y poco analíticos, obteniendo puntuaciones de riesgo subjetivas [58,60]. • Necesidad de contar con orientaciones y perspectivas económicas del análisis de riesgos [60].…”
Section: Tabla 1 Modelos Identificados Durante La Revisión Sistemáticaunclassified
See 1 more Smart Citation
“…For example, [29] used risk evaluation and risk estimation interchangeably. On the contrary, the meaning ascribed to the concepts sometimes cause confusion when improperly defined among stakeholders [30]. This study preferred to use risk evaluation for risk quantification or qualification.…”
Section: Related Workmentioning
confidence: 99%
“…This would enable them to prioritise their investments and customise their security arrangements to meet the organisation's needs. Security solutions should be guided by a conceptual framework that takes into account the various insider types, as well as how security controls interact to reduce insider risk along the various threat pathways [10,26,37,44,45].…”
Section: Introductionmentioning
confidence: 99%