Information Systems Security Risk Assessment: Harmonization with International Accounting Standards

  • Authors:
  • Adrian Munteanu;Doina Fotache;Octavian Dospinescu

  • Affiliations:
  • -;-;-

  • Venue:
  • CIMCA '08 Proceedings of the 2008 International Conference on Computational Intelligence for Modelling Control & Automation
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper emerges from research by [1],[11], [22] and [21], and it draws on real-world examples so as to underline some limits of quantitative risk assessment. The paper is a case study and emphasis that theoretical formulas used in information security risk assessments do not contain the time dimension of the analysis. The article further develops findings published in our article Information Security Risk Assessment: The Qualitative versus Quantitative Dilemma [21] as we agree that the risk of information system security may only be assessed or estimated, but in practice, it cannot be measured accurately. A degree of trust should be associated with the assessment made by the security analyst. There are other elements that must be evaluate: average time for threat identification, average time for releasing technical procedures to reduce or accept threat and average time necessary until the system becomes operational and the threat is eliminated. The value of loss is different in any of the three moments and should be estimate for any of them.