A tentative proposal
John C. Beachboard, Alma Cole, Mike Mellor, Steven Hernandez, Kregg Aytes, Nelson Massad · 2006
Despite the availability of numerous methods and publications concerning the proper conduct of information security risk analyses, "there is a relative dearth of insights that help firms to understand the socio-organizational challenges of managing the deployment and use of these tools to prevent IS security compromises" [3, p. 3627]. This paper builds a case for then briefly outlines a possible approach for developing an "open development" strategy to address recognized deficiencies in the area of risk analysis. This is an abbreviated version of a longer paper that describes the identified initiatives in greater detail. For a complete version of this paper, please contact the first author.