DocumentCode :
2885947
Title :
Correlating Risk Findings to Quantify Risk
Author :
Sanders, Aric ; Tong Sun ; Yin Pan ; Bo Yuan
Author_Institution :
Xerox Corp., Rochester, NY, USA
fYear :
2012
fDate :
3-5 Sept. 2012
Firstpage :
752
Lastpage :
759
Abstract :
Research in quantitative Information Technology (IT) risk analysis has increased in the past decade, but much of that research has focused on creating new approaches that replace existing ones. Since organizations have extensive sunk costs invested in their risk management programs, there exists a need to extend and improve existing approaches. Additionally, many quantitative approaches are difficult to implement without mathematical expertise or specialized tools, focus on quantifying individual vulnerabilities, provide little insight into underlying process gaps affecting IT risk and do not facilitate including environmental factors in risk ratings. Our research focuses on identifying attributes or characteristics of risk that are missing from existing approaches, and quantifying their relevance using statistical analysis techniques. We seek to identify and quantify attributes that further close the gap between enumerating IT risks and understanding the actual risk they present. In this paper we identify the relationship between risk findings as a key attribute, and demonstrate using correlation to quantify the relationship. Correlation analysis enables organizations to uncover process gaps, and situations where default risk ratings may not be sufficient. In this paper, we discuss the benefits of correlating risk findings and demonstrate value and feasibility through an empirical case study.
Keywords :
organisational aspects; risk management; security of data; statistical analysis; IT risk analysis; correlation analysis; information security; process gaps; quantitative information technology; risk attribute identification; risk findings; risk management programs; risk quantification; statistical analysis; Correlation; Databases; Measurement; Organizations; Risk management; Servers; correlation; information security; risk analysis;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Privacy, Security, Risk and Trust (PASSAT), 2012 International Conference on and 2012 International Confernece on Social Computing (SocialCom)
Conference_Location :
Amsterdam
Print_ISBN :
978-1-4673-5638-1
Type :
conf
DOI :
10.1109/SocialCom-PASSAT.2012.95
Filename :
6406396
Link To Document :
بازگشت