ARiMA - A New Approach to Implement ISO/IEC 27005
Alexander Leitner, Ingrid Schaumüller-Bichl
Abstract
Alexander Leitner, Ingrid Schaumüller-Bichl
Abstract
This paper deals with the implementation of a new IT risk management approach according to the ISO/IEC 27005 standard. The development of this new approach is closely linked to requirements of Austrian public authorities concerning IT risk analysis. For this reason a survey was carried out to get these requirements. Methods available on the international market have been evaluated to analyse how they comply with the subprocesses defined in ISO/IEC 27005 and to obtain the best practice approaches for the development of a new method. Finally the paper presents the core of a new IT risk management approach considering all mentioned aspects.
OpenAlex reports 9 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
This paper deals with the implementation of a new IT risk management approach according to the ISO/IEC 27005 standard. The development of this new approach is closely linked to requirements of Austrian public authorities concerning IT risk analysis. For this reason a survey was carried out to get these requirements. Methods available on the international market have been evaluated to analyse how they comply with the subprocesses defined in ISO/IEC 27005 and to obtain the best practice approaches for the development of a new method. Finally the paper presents the core of a new IT risk management approach considering all mentioned aspects.
Key concepts: Risk management, Autoregressive integrated moving average, Computer science, Risk analysis (engineering), Core (optical fiber), Reliability engineering, Systems engineering, Engineering