A Business aware Information Security Risk Analysis Method

Sadok, Moufida and Spagnoletti, Paolo (2010) A Business aware Information Security Risk Analysis Method. In: Information Technology and Innovation Trends in Organizations. Springer, HEIDELBERG -- DEU, p. 100-108. ISBN 978-3-7908-2631-9. (In Press)

Corporate Creators: Institute of Technology in Communications at Tunis, Techno park El Ghazala, CeRSI - LUISS Guido Carli

PDF (post-print) - Requires a PDF viewer such as GSview, Xpdf or Adobe Acrobat Reader

Official URL: http://www.springer.com/business+%26+management/bu...


Securing the organization critical information assets from sophisticated insider threats and outsider attacks is essential to ensure business continuity and efficiency. The information security risk management (ISRM) is the process that identifies the threats and vulnerabilities of an enterprise information system, evaluates the likelihood of their occurrence and estimates their potential business impact. It is a continuous process that allows cost effectiveness of implemented security controls and provides a dynamic set of tools to monitor the security level of the information system. However, the examination of existing practices of the enterprises reveals a poor effectiveness of information security management processes such as stated in the information security breaches surveys. In particular, the enterprises experience difficulties in assessing and managing their security risks, in implementing appropriate security controls, as well as in preventing security threats. The available ISRM models and frameworks mainly focus on the technical modules related to the development of security mitigation and prevention and do not pay much attention to the influence of business variables affecting the reliability of the provided solutions. This paper discusses the major business related factors for risk analysis and shows their interference in the ISRM process. These factors include the enterprise strategic environment, the organizational structure features, the customer relationship and the value chain configuration.


