Assets Dependencies Model in Information Security Risk Management
2014
Information security risk management is a fundamental process conducted for the purpose of securing information assets in an organization. It usually involves asset identification and valuation, threat analysis, risk analysis and implementation of countermeasures. A correct asset valuation is a basis for accurate risk analysis, but there is a lack of works describing the valuation process with respect to dependencies among assets. In this work we propose a method for inspecting asset dependencies, based on common security attributes - confidentiality, integrity and availability. Our method should bring more detailed outputs from the risk analysis and therefore make this process more objective.
Keywords:
- Information security
- Confidentiality
- Risk management
- Valuation (finance)
- Risk analysis (engineering)
- Asset (computer security)
- Security information and event management
- Data mining
- Risk analysis (business)
- Information security management
- Political science
- Knowledge management
- information security risk management
- Countermeasure
- Correction
- Source
- Cite
- Save
- Machine Reading By IdeaReader
13
References
4
Citations
NaN
KQI