Multi-criteria model for evaluation of information security risk assessment methods and tools

Mario Sajko, Nikola Hadjina, Darija Pešut · The 33rd International Convention MIPRO · 2010

Methods and tools for supporting the process of information security risk assessment are determined through several attributes. These attributes make a particular method and tool more or less suitable for solving risk assessment problems in companies. During the process of selecting these methods, companies have limitations such as financing, human resources, knowledge, time, etc. These limitations determine the approach to solving the problem of risk assessment. In respect to these limitations on one side and the attributes of risk assessment methods/tools on the other, we can establish a model for assisting the selection of a suitable method/tool. The experience gained in some Croatian companies when applying this model for the selection of their appropriate risk assessment support is also presented in this paper.

Read the paper · More papers on PaperTik