DocumentCode
2665556
Title
Information Systems Security Risk Assessment: Harmonization with International Accounting Standards
Author
Munteanu, Adrian ; Fotache, Doina ; Dospinescu, Octavian
Author_Institution
Fac. of Econ. & Bus. Adm., Alexandru loan Cuza Univ. of Iasi, Iasi, Romania
fYear
2008
fDate
10-12 Dec. 2008
Firstpage
1111
Lastpage
1117
Abstract
This paper emerges from research by (Alter, S. et al., 2004), (Dillard, K. et al., 2004), (Landoll, D.J., 2006) and (Soliman, K., 2006), and it draws on real-world examples so as to underline some limits of quantitative risk assessment. The paper is a case study and emphasized that theoretical formulas used in information security risk assessments do not contain the time dimension of the analysis. The article further develops findings published in our article Information Security Risk Assessment: The Qualitative versus Quantitative Dilemma (Soliman, K., 2006) as we agree that the risk of information system security may only be assessed or estimated, but in practice, it cannot be measured accurately. A degree of trust should be associated with the assessment made by the security analyst. There are other elements that must be evaluated: average time for threat identification, average time for releasing technical procedures to reduce or accept threat and average time necessary until the system becomes operational and the threat is eliminated. The value of loss is different in any of the three moments and should be estimate for any of them.
Keywords
accounts data processing; information systems; security of data; information system security risk assessment; international accounting standard; threat acceptance; threat identification; threat reduction; trust; Communication system control; ISO standards; Information security; Information systems; Management information systems; Monitoring; NIST; Risk analysis; Risk management; Terminology; assets assessment; data source; information risk; information security; quantitative assessment; time dimension;
fLanguage
English
Publisher
ieee
Conference_Titel
Computational Intelligence for Modelling Control & Automation, 2008 International Conference on
Conference_Location
Vienna
Print_ISBN
978-0-7695-3514-2
Type
conf
DOI
10.1109/CIMCA.2008.26
Filename
5172781
Link To Document