conference-paper Open access

An initial insight into Information Security Risk Assessment practices

  • Annals of Computer Science and Information Systems
  • Polskie Towarzystwo Informatyczne
Research footprint

At a glance

Citations
7
References
20
Comments
0
Paper overview

Öz

Much of the debate surrounding risk management in information security (InfoSec) has been at the academic level, where the question of how practitioners view predominant issues is an essential element often left unexplored. Thus, this article represents an initial insight into how the InfoSec risk professionals see the InfoSec risk assessment (ISRA) field. We present the results of a 46-participant study where have gathered data regarding known issues in ISRA. The survey design was such that we collected both qualitative and quantitative data for analysis. One of the key contributions from the study is knowledge regarding how to handle risks at different organizational tiers, together with an insight into key roles and knowledge needed to conduct risk assessments. Also, we document several issues concerning the application of qualitative and quantitative methods, together with drawbacks and advantages. The findings of the analysis provides incentives to strengthen the research and scientific work for future research in InfoSec management.

Record transparency

Publication details

DOI
10.15439/2016f158
OpenAlex
W2526903273
Document type
conference-paper
Language
EN
Source
Annals of Computer Science and Information Systems
Last metadata update
Community

Comments

Oturum Açın to join the discussion.

  1. No comments yet. Start the discussion.