EconPapers    
Economics at your fingertips  
 

STORM-RM: a collaborative and multicriteria risk management methodology

Theodoros Ntouskas and Nineta Polemi

International Journal of Multicriteria Decision Making, 2012, vol. 2, issue 2, 159-177

Abstract: Risk management (RM) is a necessary process in order to identify, categorise and handle security threats, vulnerabilities and risks of information and communication systems (ICS). Existing RM methodologies for the implementation of standards impose various barriers (e.g., limitation in knowledge gathering, time and resources consumption, and cost) which make them unable to meet the growing needs of the current distributed and complex ICS and their hosting critical data and services. Identifying these weaknesses, we treat RM as a multi-criteria problem and we propose a multi-criteria group decision making methodology STORM-RM for its solution combining the analytic hierarchy process (AHP) with security management standards (ISO27001 and AS/NZS 4360).

Keywords: risk management; STORM-RM; analytical hierarchy process; AHP; multicriteria decision making; MCDM; collaboration; methodology; group decision making; security management standards. (search for similar items in EconPapers)
Date: 2012
References: Add references at CitEc
Citations: View citations in EconPapers (2)

Downloads: (external link)
http://www.inderscience.com/link.php?id=46941 (text/html)
Access to full text is restricted to subscribers.

Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.

Export reference: BibTeX RIS (EndNote, ProCite, RefMan) HTML/Text

Persistent link: https://EconPapers.repec.org/RePEc:ids:ijmcdm:v:2:y:2012:i:2:p:159-177

Access Statistics for this article

More articles in International Journal of Multicriteria Decision Making from Inderscience Enterprises Ltd
Bibliographic data for series maintained by Sarah Parker ().

 
Page updated 2025-03-19
Handle: RePEc:ids:ijmcdm:v:2:y:2012:i:2:p:159-177