A Framework for selecting IT Security Risk Management Methods based on ISO27005
Gunnar Wahlgren, Khalid Bencherifa, Stewart James Kowalski
Abstract
Gunnar Wahlgren, Khalid Bencherifa, Stewart James Kowalski
Abstract
The ISO27005 is an international standard that gives recommendation on IT Security Risk Management Methods. In this short paper we outline a criteria framework to analysis 7 of the major IT security risk methodology used. This framework can be used by organizations to select the appropriated methodology to fit their organizations risk posture and risk environment.
OpenAlex reports 5 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
The ISO27005 is an international standard that gives recommendation on IT Security Risk Management Methods. In this short paper we outline a criteria framework to analysis 7 of the major IT security risk methodology used. This framework can be used by organizations to select the appropriated methodology to fit their organizations risk posture and risk environment.
Key concepts: Risk management framework, Risk management, Computer science, IT risk management, Risk analysis (engineering), Security management, Standard of Good Practice, Risk assessment