IT security risk management

Mohammed Ketel · 2008

Threats (accidental or malicious) are potential causes of unwanted events that can result in harm to the assets of the organization and may affect the profit and/or a company reputation. A risk management process (qualitative or quantitative) is needed in order to identify, describe, and analyze the possible vulnerabilities that could affect the company's assets. In this paper, we present the quantitative indexes that are used to measure risk and introduce the scenario-based qualitative approaches via attack trees.

Read the paper · More papers on PaperTik