article
A framework for quantifying cyber security risks
Research footprint
At a glance
- Citations
- 2
- References
- 0
- Comments
- 0
Paper overview
Abstract
Recent years have seen an increasing amount of information becoming available which is of benefit to the security risk process. Traditionally, security risk management is an asset-based, qualitative process based on expert opinion and information at hand; periodically a group of experts assesses applicable risks and determines correct risk levels and whether new risks should be added to the list. This paper proposes a threat-based, traceable quantitative risk management approach that uses current information to quantify risks. This leads to a near real-time risk process, where available information is processed, and the risks are automatically updated. The approach was tested in practice at the main banks in the Netherlands.
Record transparency
Publication details
- DOI
- 10.69554/cykn3231
- OpenAlex
- W3168157531
- Document type
- article
- Language
- EN
- Source
- Cyber security.
- Last metadata update
Comments
Log in to join the discussion.