Use of Decision Support Techniques for Information System Risk Management

Donald L. Buckshaw · Wiley StatsRef: Statistics Reference Online · 2014

Abstract Identifying and understanding security risks for information system design or evaluation is very challenging. Making decisions about accepting or mitigating these risks through a rational, traceable, and understandable process is even harder. Quantitative risk analysis techniques can help stakeholders understand and communicate risk‐informed design decisions even when the stakeholders have conflicting objectives. Quantitative risk analysis also helps stakeholders understand security, cost, and functionality trade‐off decisions in repeatable process. This paper discusses the roles of stakeholders in risk analysis, the advantages and disadvantages of quantitative risk analysis, basic cyber risk decision support concepts and processes, and the mathematical definitions of risk for information systems. This paper recommends the use of properly constructed quantitative risk analysis models and discourages the use of semiquantitative risk analysis models.

Read the paper · More papers on PaperTik