A framework for comparing different information security risk analysis methodologies

  • Authors:
  • Anita Vorster;Les Labuschagne

  • Affiliations:
  • University of Johannesburg;University of Johannesburg

  • Venue:
  • SAICSIT '05 Proceedings of the 2005 annual research conference of the South African institute of computer scientists and information technologists on IT research in developing countries
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

Organisations wanting to conduct information security risk analysis may find selecting a methodology problematic. Currently there are numerous risk analysis methodologies available, some of which are qualitative while others are more quantitative in nature. These methodologies have a common goal of estimating the overall risk value. An organisation must select the most appropriate methodology based on its specific needs. This article addresses the problem by presenting a framework that can be used to compare different risk analysis methodologies. Five methodologies, which are currently available, were analysed in order to establish the framework for comparison.