2014
DOI: 10.1108/imcs-07-2013-0053
|View full text |Cite
|
Sign up to set email alerts
|

Current challenges in information security risk management

Abstract: Purpose – The purpose of this paper is to give an overview of current risk management approaches and outline their commonalities and differences, evaluate current risk management approaches regarding their capability of supporting cost-efficient decisions without unnecessary security trade-offs, outline current fundamental problems in risk management based on industrial feedback and academic literature and provide potential solutions and research directions to address the identified problems. D… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

6
52
0

Year Published

2015
2015
2024
2024

Publication Types

Select...
5
1

Relationship

0
6

Authors

Journals

citations
Cited by 75 publications
(63 citation statements)
references
References 32 publications
6
52
0
Order By: Relevance
“…The current installment of the NIST SP 800-30 -Guide for Conducting Risk Assessments is at revision one [18] (NIST80030) and was developed to further statutory responsibilities under the Federal Information Security Management Act. NIST800-30 was designed to aid larger and complex organizations in information risk management.…”
Section: Reviewed Methodsmentioning
confidence: 99%
See 4 more Smart Citations
“…The current installment of the NIST SP 800-30 -Guide for Conducting Risk Assessments is at revision one [18] (NIST80030) and was developed to further statutory responsibilities under the Federal Information Security Management Act. NIST800-30 was designed to aid larger and complex organizations in information risk management.…”
Section: Reviewed Methodsmentioning
confidence: 99%
“…However, reaching realistic estimates of P&C has been one of the major challenges of the InfoSec risk community since the very beginning [35,36], especially in the quantitative approaches [37]. We have defined the following issues and tasks for the ISRA estimation process (supplemented with issues and tasks from the risk identification process): Table 2 Risk estimation processes and output comparison.…”
Section: Main Process 2: Risk Estimationmentioning
confidence: 99%
See 3 more Smart Citations