• DocumentCode
    2665556
  • Title

    Information Systems Security Risk Assessment: Harmonization with International Accounting Standards

  • Author

    Munteanu, Adrian ; Fotache, Doina ; Dospinescu, Octavian

  • Author_Institution
    Fac. of Econ. & Bus. Adm., Alexandru loan Cuza Univ. of Iasi, Iasi, Romania
  • fYear
    2008
  • fDate
    10-12 Dec. 2008
  • Firstpage
    1111
  • Lastpage
    1117
  • Abstract
    This paper emerges from research by (Alter, S. et al., 2004), (Dillard, K. et al., 2004), (Landoll, D.J., 2006) and (Soliman, K., 2006), and it draws on real-world examples so as to underline some limits of quantitative risk assessment. The paper is a case study and emphasized that theoretical formulas used in information security risk assessments do not contain the time dimension of the analysis. The article further develops findings published in our article Information Security Risk Assessment: The Qualitative versus Quantitative Dilemma (Soliman, K., 2006) as we agree that the risk of information system security may only be assessed or estimated, but in practice, it cannot be measured accurately. A degree of trust should be associated with the assessment made by the security analyst. There are other elements that must be evaluated: average time for threat identification, average time for releasing technical procedures to reduce or accept threat and average time necessary until the system becomes operational and the threat is eliminated. The value of loss is different in any of the three moments and should be estimate for any of them.
  • Keywords
    accounts data processing; information systems; security of data; information system security risk assessment; international accounting standard; threat acceptance; threat identification; threat reduction; trust; Communication system control; ISO standards; Information security; Information systems; Management information systems; Monitoring; NIST; Risk analysis; Risk management; Terminology; assets assessment; data source; information risk; information security; quantitative assessment; time dimension;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computational Intelligence for Modelling Control & Automation, 2008 International Conference on
  • Conference_Location
    Vienna
  • Print_ISBN
    978-0-7695-3514-2
  • Type

    conf

  • DOI
    10.1109/CIMCA.2008.26
  • Filename
    5172781