Reconsideration of Risk Communication and Risk Assessment Support Methods for Security

Ryôichi Sasaki · 2023

Although modern society is said to be a risk society and there is growing interest in risk, there has been little research on risk communication with regard to security activities. On the other hand, the authors introduced risk communication into the process of risk assessment for information security measures and developed a multiple risk communicator (MRC) to facilitate organizational agreement on the optimal combination of countermeasures in the year of 2007. We have been extending the MRC over the years. This paper describes two matters that have not been mentioned in the past. This paper describes (1) the differences between general risk communication and the risk communication that the authors have conducted for security activities and the reasons for these differences, and (2) the clarification of the interrelationships between the first multiple risk communicator MRC and its later extensions, and the results of their systematization as MRC. The extensions of MRC are (1) Social-MRC, which enables consensus building among more than 1,000 participants, (2) MRC-EDC, a risk assessment method that can be applied to multi-stage attacks, (3) MRC-IoT, a risk assessment method suitable for IoT, (4) MRC-QQ, a risk assessment method using a quasi-quantitative method that is easy for everyone to apply. The MRC will continue to be expanded.

Read the paper · More papers on PaperTik