IT security risk management
Mohammed Ketel · 2008
Threats (accidental or malicious) are potential causes of unwanted events that can result in harm to the assets of the organization and may affect the profit and/or a company reputation. A risk management process (qualitative or quantitative) is needed in order to identify, describe, and analyze the possible vulnerabilities that could affect the company's assets. In this paper, we present the quantitative indexes that are used to measure risk and introduce the scenario-based qualitative approaches via attack trees.