Information security risk management terminology and key concepts

Author:

Schmidt MichaelORCID

Abstract

AbstractLanguage is the foundation for any communication and the vocabulary used has a decisive influence on the ability of the communication partners to clearly understand each other. In Information Security Risk Management (ISRM), the terminology used is often dictated by industry standards and frameworks. However, there is no universally accepted terminology, which makes collaboration difficult for professionals and researchers alike. This publication compares the terminology defined by frequently used frameworks, such as ISO and NIST, in the field of ISRM. It examines the terms and inherent concepts of each terminology, compares the notion of risk and derives a concept diagram based on the most important key concepts. The result facilitates a common understanding of ISRM across frameworks and organisational boundaries, thus enables further research, discussion, intra- and inter-firm communication.

Funder

Bayerische Akademie der Wissenschaften

Publisher

Springer Science and Business Media LLC

Subject

Strategy and Management,Economics and Econometrics,Finance,Business and International Management

Reference56 articles.

1. Alberts, Christopher and Dorofee Audrey. 2002. Managing Information Security Risks: The OCTAVE Approach. Addison-Wesley Professional. ISBN: 0-321-11886-3.

2. American National Standards Institute [ANSI]. 2011. ANSI/ASSE Z690.1. Vocabulary for Risk Management.

3. Aven, Terje. 2011. On the new ISO guide on risk management terminology. Reliability Engineering & System Safety 96(7): 719-726. ISSN: 0951-8320. https://doi.org/10.1016/j.ress.2010.12.020.

4. Aven, Terje. 2016. Risk assessment and risk management: Review of recent advances on their foundation. European Journal of Operational Research 253(1): 1-13. ISSN: 0377-2217. https://doi.org/10.1016/j.ejor.2015.12.023.

5. Aven, Terje et al. 2018. Society for Risk Analysis Glossary. SRA. https://www.sra.org/riskanalysis-introduction/risk-analysis-glossary/

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3