Modeling Security Risk with Three Views

Susan Lincke, Madhavi Adavi · 2019

Organizations are responsible for implementing due care, or controls for risk, by calculating the likelihood multiplied by the impact for high-risk threats. Organizations cover their own risk expenditures and they do this independently. However, this may be myopic. We investigate a societal perspective by calculating risk via three models: an individual, organizational and societal view of security at a high level for two issues: ransomware and mobile privacy. For these two issues, we consider fault, responsibility, interdependency and ethics. By considering a more societal and interdependent solution, new or better solutions arise.

Read the paper · More papers on PaperTik