A Comparative Study of Risk Assessment Methods, MEHARI & CRAMM with a New Formal Model of Risk Assessment (FoMRA) in Information Systems

作者: Imed El Fray

DOI: 10.1007/978-3-642-33260-9_37

关键词: CorrectnessRisk assessmentCRAMMInformation systemManagement scienceUnit (housing)Computer science

摘要: In this article, we present a comparative study of developed new formal mathematical model risk assessment (FoMRA) with expert methods in the information systems (IS). Proposed analysis verified correctness theoretical assumptions model. paper, examples computations illustrating application FoMRA and known accepted throughout world assessment: MEHARI CRAMM were presented related to specific unit public administration operating Poland.

参考文章(26)
Rex Kelly Rainer, Charles A. Snyder, Houston H. Carr, Risk analysis for information technology Journal of Management Information Systems. ,vol. 8, pp. 129- 147 ,(1991) , 10.1080/07421222.1991.11517914
I. E. Fray, W. Maćków, M. Kurkowski, J. Pejaś, A new mathematical model for analytical risk assessment and prediction in IT systems Control and Cybernetics. ,vol. 41, pp. 241- 268 ,(2012)
Moshe Morris Mano, Computer Security Management ,(1981)
Robert R. Moeller, IT Audit, Control, and Security ,(2010)
Herbert J. Mattord, Michael E. Whitman, Principles of Information Security, 4th Edition Cengage Learning. ,(2011)
Jean-Noël Ezingeard, Monica Bowen-Schrire, Triggers of change in information security management practices The Journal of General Management. ,vol. 32, pp. 53- 72 ,(2007) , 10.1177/030630700703200404
Herbert J. Mattord, Michael E. Whitman, Principles of Information Security ,(2002)
Amit Bhatnagar, Sanjoy Ghose, Segmenting consumers based on the benefits and risks of Internet shopping Journal of Business Research. ,vol. 57, pp. 1352- 1360 ,(2004) , 10.1016/S0148-2963(03)00067-5