Title of article :
A Comparative Study of Risk Assessment Methodologies for Information Systems
Author/Authors :
Pandey, S. K. Institute of Chartered Accountants of India - Department of Information Technology, India , Mustafa, K. Jamia Millia Islamia - Department of Computer Science, India
Abstract :
Today’s highly vulnerable world information systems are subjected to greater risks than ever before. As a result, related officials should be in a position to identify the risks which an organization faces and its management policies have to effectively manage those risks. Risk assessment is currently used as a key technique for managing security information systems. Literature reveals various information security risk assessment methods that can be implemented by the organizations, and each has different approaches to assess the information security risks. Organizations find it difficult to select an information security risk assessment method. Therefore, there is a need for a critical review of existing risk assessment methodologies. This paper presents a brief discussion on the top risk assessment methodologies, particularly COBRA, CORAS, CRAMM, OCTAVE, SOMAP, and NIST Guide, along with its strengths and weaknesses. After that, a comparative study is also done as the basis of the review results. Further research directions may also be taken by the weaknesses section. This work provides an evaluation to determine whether an information security risk assessment method is in line with information technology governance or not. The research paper will help the senior IT personnel to provide their recommendations for using a risk assessment methodology based on the specific requirements of an organization.
Keywords :
Risk Assessment , Review of Risk Assessment Methodologies , Information Security , Comparative Study of Risk Assessment Methodologies
Journal title :
Bulletin Of Electrical Engineering and Informatics
Journal title :
Bulletin Of Electrical Engineering and Informatics