摘要: Unified and formal knowledge models of the information security domain are fundamental requirements for supporting enhancing existing risk management approaches. This paper describes a ontology which provides an ontological structure knowledge. Besides best-practice guidelines such as German IT Grundschutz Manual also concrete considered organization is incorporated. An evaluation conducted by expert team has shown that this model can be used to support broad range