A New Model for Information Security Risk Management
Ali Shirazi () and
Mozaffar Kazemi
Additional contact information
Ali Shirazi: Tarbiyat Modares University
Mozaffar Kazemi: Parsa-Sharif Research Center
A chapter in ICT for an Inclusive World, 2020, pp 551-566 from Springer
Abstract:
Abstract This article introduces a new risk management method for information security risk management, proposed and applied for the first time in the IT department of a telecommunication company in Iran. According to law requirements and security strategic plan, the mentioned company implemented information security risk management (ISMS). So one of the main phases of ISMS is the risk management. The results show that the methodology of the information security risk management containing the risk identification, risk analysis, risk evaluation and risk treatment, uses the frameworks of ISO 27005, ISO 27002, ISO 27011, OCTAVE and NIST 800-30 and OWASP standards. This new method is practical and accurate and is suitable for large scale organizations.
Keywords: Information security; Risk assessment model; Security risk management; Risk management in ISMS (search for similar items in EconPapers)
Date: 2020
References: Add references at CitEc
Citations:
There are no downloads for this item, see the EconPapers FAQ for hints about obtaining it.
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:spr:lnichp:978-3-030-34269-2_38
Ordering information: This item can be ordered from
http://www.springer.com/9783030342692
DOI: 10.1007/978-3-030-34269-2_38
Access Statistics for this chapter
More chapters in Lecture Notes in Information Systems and Organization from Springer
Bibliographic data for series maintained by Sonal Shukla () and Springer Nature Abstracting and Indexing ().