Methods of Risk Assessment for Information Security Management

The study showed that mainly for analysis and risk assessment used statistical data on incidents and information security threats. In many countries at the state level, such statistics are not kept, which limits the possibilities of existing tools for national use. It should also be noted that the study sets tools expert certain limitations (on the used set of parameters) and gives him the possibility of applying for evaluation of a wider range of values. Based on this, two methods are presented for analysis and evaluation of risk, which allow you to use a wide range of parameters, giving the opportunity to create a more flexible means of assessment, and calculate risks based on statistics and on expert judgment, made in uncertain, formalized environment with regard to time period, industry, economic and managerial specifics of the enterprise, etc. In addition, the developed methods will make it possible to reproduce the results, both in numerical and in verbal form, for example, using linguistic variable, often used for description of complex systems described by the parameters shown not only in quantitative but also in qualitative form.
Method of Analysis and Information Security Risk Assessment; Risk; Risk Analysis; Risk Assessment; Risk Management; Risk Profile

