ARiMA - A New Approach to Implement ISO/IEC 27005

Alexander Leitner, Ingrid Schaumüller-Bichl · 2009

This paper deals with the implementation of a new IT risk management approach according to the ISO/IEC 27005 standard. The development of this new approach is closely linked to requirements of Austrian public authorities concerning IT risk analysis. For this reason a survey was carried out to get these requirements. Methods available on the international market have been evaluated to analyse how they comply with the subprocesses defined in ISO/IEC 27005 and to obtain the best practice approaches for the development of a new method. Finally the paper presents the core of a new IT risk management approach considering all mentioned aspects.

Read the paper · More papers on PaperTik