Journal Article10.1016/0167-4048(93)90056-B
A comparative framework for risk analysis methods
91
TL;DR: A framework for risk management terminology is suggested and the application of the framework will be demonstrated through a high level discussion of the CRAMM, LAVA and MELISA risk analysis methods.
read more
About: This article is published in Computers & Security. The article was published on 01 Oct 1993. The article focuses on the topics: Risk analysis & Risk analysis (business).
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
Coping with systems risk: security planning models for management decision making
TL;DR: Results of comparative qualitative studies in two information services Fortune 500 firms identify an approach that can effectively deal with systems risk, and this theory-based security program includes use of a security risk planning model, education/training in security awareness, and Countermeasure Matrix analysis.
Why there aren't more information security research studies
TL;DR: A description of a conceptual model based on the study of SRM at the firm level, the methodology designed to test this model, the problems faced while attempting to test the model, and suggestions for those who attempt to conduct work in highly sensitive areas are provided.
393
A framework for the governance of information security
TL;DR: There is a need to integrate information security into corporate governance through the development of an information security governance (ISG) framework and a framework to aid an organization in its ISG efforts is proposed.
273
Patent
Overall risk in a system
Nicholas Heinrich
- 29 Mar 2002
TL;DR: A computer-implemented method and system for assessing the overall risk in at least part of an information technology system includes inputting into a risk assessment database a plurality of identified risks in a system; associating the risks to at least one severity band in a risk echelon; assigning a value to each risk; multiplying each risk value by a coefficient factor; and summing the factored risk values to determine the overall risks as discussed by the authors.
189
A framework for integrated risk management in information technology
TL;DR: This work explores the environment of IT in organizations, identifies the probable threats, and proposes a framework for integrated risk management, which can be used to guide organizations in reducing the losses resulting from the realization of threats to IT use.
162
References
•Book
Computers at Risk: Safe Computing in the Information Age
Telecommunications Board
- 01 Feb 1990
TL;DR: The book explores the diversity of the field, the need to engineer countermeasures based on speculation of what experts think computer attackers may do next, why the technology community has failed to respond to the need for enhanced security systems, how innovators could be encouraged to bring more options to the marketplace, and balancing the importance of security against the right of privacy.
85
Principles and procedures of the LRAM approach to information systems risk analysis and management
TL;DR: The Livermore Risk Analysis Methodology (LRAM) was developed in accord with principles and can be used to determine which specific security controls and counter measures can be effective and justifiable by management-set criteria.
46
Computer security methodology: Risk analysis and project definition
K. P. Badenhorst,Jan H. P. Eloff +1 more
TL;DR: The issue of risk analysis is addressed in view of an overall information security plan to address the selection of computer security countermeasures.
24
Framework of a methodology for the life cycle of computer security in an organization
K. P. Badenhorst,Jan H. P. Eloff +1 more
TL;DR: The objective of this paper is to design a methodology for the introduction, development and maintenance of computer security within major organizations.
22