Title :
Understanding Insecure IT: Practical Risk Assessment
Author :
Liu, Simon ; Kuhn, Rick ; Rossman, Hart
Author_Institution :
US National Library of Medicine
Abstract :
Risk assessment involves gathering and evaluating risk information so that enterprise stakeholders can make mitigation decisions. Once we identify the risks, we can rank the probability of each one´s occurrence and its impact on the organization. Some risks are more likely to occur than others, and different risks can affect an organization in different ways, so a practical risk assessment can help ensure that enterprises identify the most significant risks and determine the best actions for mitigating them.
Keywords :
Costs; Disaster management; Equations; Frequency; Information analysis; Information security; Risk analysis; Risk management; Technology management; Terrorism; IT professional; risk; security; threats; vulnerability;
Journal_Title :
IT Professional
DOI :
10.1109/MITP.2009.62