Unraveling the establishment of residual risk in cybersecurity
Isaac D. Sánchez-García, Tomás San Feliú, Jose A. Calvo‐Manzano
Abstract
Isaac D. Sánchez-García, Tomás San Feliú, Jose A. Calvo‐Manzano
Abstract
This paper addresses the background, concepts, related variables, and current problems related to the calculation of Residual Risk (RR) in cybersecurity management systems. The objective of this paper is to clarify the concept of residual risk and identify the main problems that prevent the establishment of an adequate residual risk calculation at the organizational level and to provide possible solutions to this problem that will serve as a starting point for both practitioners and researchers in measuring the effectiveness of the countermeasures applied.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
This paper addresses the background, concepts, related variables, and current problems related to the calculation of Residual Risk (RR) in cybersecurity management systems. The objective of this paper is to clarify the concept of residual risk and identify the main problems that prevent the establishment of an adequate residual risk calculation at the organizational level and to provide possible solutions to this problem that will serve as a starting point for both practitioners and researchers in measuring the effectiveness of the countermeasures applied.
Key concepts: Residual, Residual risk, Risk analysis (engineering), Risk management, Computer science, Computer security, Point (geometry), Risk assessment