An Attempt to Structure Risk Assessment

Laleh Pirzadeh (Institutionen för data- och informationsteknik (Chalmers))
Nordsec 2012, The 17th Conference on Secure IT Systems (2012)
[Konferensbidrag, refereegranskat]

We propose a security Risk Assessment process model which details the steps in the Risk Assessment process, such as resources used for Risk Assessment, actions performed on these resources, input data gained by these actions, risk evaluation methods applied and finally the output produced. The model highlights different paths that can be taken in RA methods, some issues with the existing methods and potential areas for development of new methods.

Nyckelord: Information System Security Risk Assessment; Risk Assessment process model; Risk Analysis; Risk Quantification and Qualification

