Risk analysis supported by information security metrics

  • Authors:
  • Jakub Breier;Ladislav Hudec

  • Affiliations:
  • Institute of Applied Informatics;Institute of Applied Informatics

  • Venue:
  • Proceedings of the 12th International Conference on Computer Systems and Technologies
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

This work presents motivation for using metrics as an instrument for the risk analysis. There are information security standards, like ISO 27000 family, which serve as a reference for risk analysis and assessment, however there is a lack of formal methods and some discrete-scale evaluation. The main goal of this work is to propose the metric - control objective mappings, so the chosen metrics will help the management decide whether the control objectives are fulfilled or not. We present a mathematical model of evaluation based on metrics, which should lead to more automatized risk analysis.