Measuring Risk Using Existing Frameworks

نویسندگان

  • Edwin Covert
  • Fran Nielsen
چکیده

his article focuses on risks to information technology (IT) systems. Technically speaking, risk to an IT system is a function of the likelihood that some threat will attack, or exploit, some vulnerability in the system and a calculation of the potential impact resulting from these attacks or exploitations. Two ways exist to calculate risk to an IT system: quantitatively and qualitatively. Each approach has its strengths and weaknesses. Quantitative risk assessment attempts to calculate some “regret for loss,” as Case and Smith describe it. This is usually expressed in monetary terms. On the other hand, a qualitative risk assessment expresses risk in abstract terms such as high, medium, or low. Calculating risk, however, is not the same as measuring risk, nor is it the same as creating risk metrics. Calculating risk is about a single issue, or a single threat and vulnerability pairing. Measuring risk — or risk metrics — is about monitoring risk over time.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Measuring Liquidity Risk Management and Impact on Bank Performance in Iran

A bank as a business units needs to have liquid assets which can be easily converted into cash at short notice. Thus the concept of liquidity risk management is important for any commercial banks. The impact of liquidity position in management of banks have remained significant, though very elusive in the process of investment analysis vis-à-vis bank portfolio management. In addition, liquidity...

متن کامل

Measuring the Impact of Enterprise Architecture

Enterprise architecture frameworks provide a basis to systematically document and manage the information technology assets of an organization. Numerous frameworks have emerged to support large scale organizations and government entities but to date there has been no empirical support to determine if they meet the needs of their users. We present a research model to enable empirical testing of t...

متن کامل

Daan van Beek - A Functional Framework for Solving Multi-objective Optimization Problems using Genetic Algorithms

By studying single-objective genetic algorithms and multiobjective genetic algorithms this paper determines the functions needed to update existing single-objective genetic algorithms programmed in functional languages in order to make them applicable to multi-objective problems. By performing a literature study knowledge about genetic algorithms and their special multi-objective versions was c...

متن کامل

Risk Management Framework for IT-Centric Micro and Small Companies

This paper proposes a new risk management framework tailored for IT-centric micro and small companies based on the analysis of the best practices in risk management concepts, specifically the risk management frameworks. The proposed framework for risk management is a synergy of various elements from the existing frameworks, tailored to the specifics of the IT-centric micro and small companies a...

متن کامل

Building a Comprehensive Conceptual Framework for Power Systems Resilience Metrics

Recently, the frequency and severity of natural and man-made disasters (extreme events), which have a high-impact low-frequency (HILF) property, are increased. These disasters can lead to extensive outages, damages, and costs in electric power systems. A power system must be built with “resilience” against disasters, which means its ability to withstand disasters efficiently while ensuring the ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • Information Systems Security

دوره 14  شماره 

صفحات  -

تاریخ انتشار 2005