Information Security Threats: A Comparative Analysis of Impact, Probability, and Preparedness
Mary R. Sumner · Information Systems Management · 2009
The objectives are: (1) to determine the risk assessment of information security threats, based upon the perceived impact and the perceived probability of occurrence of these threats; (2) to determine the extent of risk mitigation, based upon the perceived level of preparedness for each of these information security threats; and (3) to determine the extent to which the of occurrence and the impact of information security threats relate to the level of preparedness.