Implementing an effective qualitative risk analysis
József Beinschróth · 2022
Operating of an IT system should be based on risk management. It means a kind of risk analysis should be applied periodically. Qualitative methods are used widespreadly. However, general experience of IT security experts that the implementation of qualitative risk analysis is achieved only formally, using minimal time and effort. This way gives false, unusable, formal result. In this article we examine how to recognise faulty solution, how to avoid faulty achievement. We determine the necessary circumstances how to implement a qualitative risk analysis which gives real, useable result which really supports optimal operation.