Factors in the selection of a risk assessment method
نویسنده
چکیده
Risk assessment is a fundamental decisionmaking process in the development of information security, resulting in the selection of appropriate safeguards for an information system. It is a two-stage process. In the first stage, a risk analysis process defines the scope of the risk assessment, identifies information resources (assets), and determines and prioritizes risks to the assets. In the second stage, a risk management process makes decisions to control unacceptable risks; a decision may be to transfer a risk (for example via insurance), ignore a risk, or reduce a risk, via selection of appropriate safeguards. Risk assessments also fulfil other roles, including the engagement of management in information security decision making, and enabling definition and refinement of security policy. Formal and comprehensive risk assessment methods are essential for the direction and control of data collection and data interpretation, for the provision of defined deliverables, and generally to underpin the risk assessment process with a phased framework[1]. Each method is based on an underlying risk model, which typically varies from one method to another. A risk model consists of a set of key concepts and terms[2], and references assets, threats, risks, impacts, safeguards, vulnerabilities and the relationships between them. Risk assessment methods are usually classified as quantitative or qualitative. Qualitative methods produce descriptive estimates for risks – for example, “very high” risk – whereas quantitative methods produce numeric exposure estimates for risks, often measured in dollar terms – for example, by annual loss exposure. Many methods employ some degree of automation. Risk assessment methods have evolved over three generations[3]. First generation methods are based on checklists of safeguards which are checked for presence, and then recommended if absent. Second generation methods determine information security requirements as a fundamental process within the method. Third generation methods identify logical information security requirements and physical information security requirements. Formal risk assessment methods differ in a variety of ways, for example, in their underlying risk models. Each method has its own peculiar set of problems, for example, a dependence on subjective estimates of information security input data. Problems with current risk assessment methods are described by many authors[1,4-9]. Organizations must frequently select or develop a risk assessment method, necessitating a comparison of many diverse and imperfect methods. This selection or development should be based both on an organization’s specific requirements, as well as on a set of ideal requirements for a risk assessment method[10]. Organizations consider and evaluate a set of factors for each method being considered, based on such requirements, in order to choose a method. This paper aims to specify a set of factors to be considered in the selection of a risk assessment method. The paper begins by describing a set of ideal requirements for a risk assessment method. Factors to be considered in the selection of a risk assessment method are then proposed and discussed. The paper presents and discusses empirical results obtained from testing the factors in two large, Australian organizations. A conclusion evaluates the research results, and gives directions for future research.
منابع مشابه
Presenting a model for assessing the risk of welding cracks using the ّFBWM method
One of the most dangerous industries is welding and inspection. Risk assessment is a rational procedure for determining the probable repercussions of prospective incidents on people, materials, equipment, and the environment. The risk assessment identifies the efficacy of selected control mechanisms and offers essential data for risk reduction, risk management, control system enhancement, and r...
متن کاملPresenting a model for assessing the risk of welding cracks using the ّFBWM method
One of the most dangerous industries is welding and inspection. Risk assessment is a rational procedure for determining the probable repercussions of prospective incidents on people, materials, equipment, and the environment. The risk assessment identifies the efficacy of selected control mechanisms and offers essential data for risk reduction, risk management, control system enhancement, and r...
متن کاملارائه یک روش نرم افزاری جهت استفاده از ارزیابی ریسک در بهینه سازی اقدامات حفاظت حریق ساختمان
Background and aims: The property loss and physical injuries due to fire events in buildings demonstrate the necessity of implementation of efficient and performance based fire safety measures. Effective and high efficiency protection is possible when design and selection of protection measures are based on risk assessment. This study aims at presenting a software method to make possible sele...
متن کاملDeveloping a model of influential factors for fraud risk assessment in Iran
Trust among traders is one of the bases of markets mechanism and fraud damages existing trust. Therefore, the deleterious impact of fraud on societies and companies is obvious. When fraud occurs, the society expects auditors to detect and report fraud. Therefore, the role of auditors in countering fraud has become increasingly significant. To detect fraud, auditors need to perform a high-qualit...
متن کاملErgonomic Assessment of Musculoskeletal Disorders' Risk Factors in Construction Workers Using Cornell Questionnaire and WERA Method
Introduction: With regard to high prevalence of musculoskeletal disorders in the construction industry workers, the aim of this study was to investigate the prevalence of musculoskeletal disorders and their relevant risk factors in workers of a construction factory. Methods: This descriptive-analytical cross-sectional study was conducted in 2019. In this regard, 150 workers were selected from ...
متن کاملPostural Ergonomic Risk Assessment (Pera) in The Workers of the Automobile Parts Assembly Line: A New Observational Method for the Cube Model
Assembly lines are associated with health risk and musculoskeletal disorders, particularly in the upper limbs. The aim of this study was to analyze three risk factors of posture, duration and force by using the postural ergonomic risk assessment (PERA) method in the workers of the assembly unit of automobile parts. Material and Methods: This descriptive cross-sectional study was conducted in th...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- Inf. Manag. Comput. Security
دوره 4 شماره
صفحات -
تاریخ انتشار 1996