• DocumentCode
    3506758
  • Title

    A cause and effect approach towards risk analysis

  • Author

    Pirzadeh, L. ; Jonsson, E.

  • Author_Institution
    Dept. of Comput. Sci. & Eng., Chalmers Univ. of Technol., Goteborg, Sweden
  • fYear
    2011
  • fDate
    21-21 Sept. 2011
  • Firstpage
    80
  • Lastpage
    83
  • Abstract
    Risk analysis is critical for IT systems and for organizations and their daily operation. There are various tools and methods to analyse risk. Most approaches take risk assessment as a result of specific factors (such as threats and vulnerabilities) without investigating the impact of various types of system operation. Therefore, we suggest a causal approach toward risk analysis based on an existing security model. We start out from a current risk analysis method and improve it by taking the system operation, causal relation between the impairments, as well as latency effects into account. The approach exhibits the impact of the attack chain of impairments on system risk. We claim that the approach presented in this paper will make it possible to conduct a more refined quantitative assessment of risk.
  • Keywords
    information technology; organisational aspects; risk analysis; security of data; IT systems; causal approach; cause-effect approach; impairment attack chain; impairment causal relation; latency effects; organizations; risk analysis method; risk assessment; security model; system operation; Analytical models; Equations; Mathematical model; Reliability; Risk management; Security; causal chain of impairments; metrics; risk analysis; security model; security planning; system operation;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security Measurements and Metrics (Metrisec), 2011 Third International Workshop on
  • Conference_Location
    Banff, AB
  • Print_ISBN
    978-1-4673-1245-5
  • Type

    conf

  • DOI
    10.1109/Metrisec.2011.20
  • Filename
    6165767