A Comparative Study on Information Security Risk Analysis Methods

V. K. Agrawal · Journal of Computers · 2017

Background -Risk Analysis is an integral part of management practice and an essential element of good corporate governance.There are many risk analysis methods available today, and it is a tedious task for an organization (particularly small and mid-scale company) to choose the proper method.Problem -Although many methods and tools are available in this domain, very few inventories do exist that are structured according to a set of common properties.There are many risk analysis methods available today, and the main task for an organization is to determine which one to use.Contribution -The objective of this review paper is to provide researchers, an analysis of four risk analysis methods using the Campbell et al. classification scheme.The major contributions of this paper are; 1) Present a summary of four Information Security Risk analysis methods using ontology, 2) Classify these risk analysis methods using Campbell et al. classification scheme, 3) Compare risk analysis methods based on generic attributes i.e. input, outcome, purpose, effort, scalability, methodology, etc.

Read the paper · More papers on PaperTik