Risk Identification for an Information Security Management System Implementation

Nor Aza Ramli, Normaziah Abdul Aziz · International Conference on Emerging Security Information, Systems and Technologies · 2012

ISO/IEC 27001 is an international standard that provides a set of requirements for an Information S ecurity Management System (ISMS) implementation. A risk assessment exercise for an ISMS implementation requires human expertise with comprehensive understanding and considerable knowledge in information security. A common risk assessment exercise is based on three sub-processes, namely, risk identifi cation, risk analysis and risk evaluation. The lack of tools esp ecially in the automation of risk identification emphasized the ne ed of experienced personnel and this becomes a challenge for organizations seeking compliance with the ISMS standard. This paper proposes a relationship concept in asset and threat identification which is part of the risk identifica tion sub-process. The concept provides a foundation to automate the risk assessment process for an identified scope of an IS MS implementation.

Read the paper · More papers on PaperTik