Risks Management relating to Information Systems Security. Assessment Methods for the Risk Level in Information Security

被引:0
|
作者
Baicu, Floarea [1 ]
Baicu, Andrei Mihai [2 ]
机构
[1] Hyper Univ Bucharest, Bucharest, Romania
[2] VIO TOP, Bucharest, Romania
来源
QUALITY-ACCESS TO SUCCESS | 2012年 / 13卷 / 129期
关键词
risk levels; acceptable risk level; tolerable risk; risk criteria; risk acceptability curve;
D O I
暂无
中图分类号
C93 [管理学];
学科分类号
12 ; 1201 ; 1202 ; 120202 ;
摘要
The paper presents several methods to assess in an organization the risk level concerning information security, qualitative, quantitative and combined methods as well as an original method based on the curve of risk acceptability. This method is mathematically proven by the drawing-up of parallel hyperbolic curves that intersect certain strictly fixed points, which mark the risk levels. All presented methods take into account the utilization value of the asset and the losses that the organization could encounter due to its destruction or effect on the business. Methods can be applied successively during various development stages of the information security management system, as the system security improves, while considering the own needs of the organization at a certain moment and the risk level accepted as tolerable risk. This paper also presents the risk criteria in relation to which the risk level significance is established.
引用
收藏
页码:112 / 115
页数:4
相关论文
共 50 条
  • [41] Information Security Risk Assessment and Management Method in Computer Networks
    Anikin, Igor V.
    2015 INTERNATIONAL SIBERIAN CONFERENCE ON CONTROL AND COMMUNICATIONS (SIBCON), 2015,
  • [42] Security through Information Risk Management
    Johnson, M. Eric
    Goetz, Eric
    Pfleeger, Shari Lawrence
    IEEE SECURITY & PRIVACY, 2009, 7 (03) : 45 - 52
  • [43] The Quantification Management of Information Security Risk
    Lao, Guoling
    Wang, Liping
    2008 4TH INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND MOBILE COMPUTING, VOLS 1-31, 2008, : 10377 - 10380
  • [44] RISK ASSESSMENT INFORMATION SECURITY SYSTEMS ORGANIZATION WITH MATLAB SYSTEM
    Glushenko, Sergey
    BIZNES INFORMATIKA-BUSINESS INFORMATICS, 2013, 26 (04): : 35 - +
  • [45] Security risk assessment challenges in port information technology systems
    Makrodimitris, Georgios
    Polemi, Nineta
    Douligeris, Christos
    Makrodimitris, Georgios, 1600, Springer Verlag (441): : 24 - 35
  • [46] Information systems security metrics management
    Kovacich, G
    COMPUTERS & SECURITY, 1997, 16 (07) : 610 - 618
  • [47] Information systems security risk assessment on improved fuzzy AHP
    Wu, Xiaoping
    Fu, Yu
    Wang, Jiasheng
    2009 ISECS INTERNATIONAL COLLOQUIUM ON COMPUTING, COMMUNICATION, CONTROL, AND MANAGEMENT, VOL IV, 2009, : 365 - 369
  • [48] Security management: An information systems setting
    Warren, MJ
    Batten, LM
    INFORMATION SECURITY AND PRIVACY, 2002, 2384 : 257 - 270
  • [49] Security management for radiological information systems
    Caramella, D
    Braccini, G
    Fabbrini, F
    Montanari, S
    Neri, E
    CAR '97 - COMPUTER ASSISTED RADIOLOGY AND SURGERY, 1997, 1134 : 1011 - 1011
  • [50] Information systems security metrics management
    Kovacich, Gerald
    Computers and Security, 1997, 16 (07): : 610 - 618