Information security risk management terminology and key concepts

被引:0
|
作者
Schmidt, Michael [1 ]
机构
[1] Bavarian Acad Sci & Humanities, Leibniz Supercomp Ctr, Boltzmannstr 1,Garching N, D-85748 Munich, Germany
来源
关键词
Risk management; Information security; Terminology; Terms; Concepts; Frameworks; STATISTICAL STANDARDS; REVIEWS; ISO;
D O I
10.1057/s41283-022-00108-8
中图分类号
C [社会科学总论];
学科分类号
03 ; 0303 ;
摘要
Language is the foundation for any communication and the vocabulary used has a decisive influence on the ability of the communication partners to clearly understand each other. In Information Security Risk Management (ISRM), the terminology used is often dictated by industry standards and frameworks. However, there is no universally accepted terminology, which makes collaboration difficult for professionals and researchers alike. This publication compares the terminology defined by frequently used frameworks, such as ISO and NIST, in the field of ISRM. It examines the terms and inherent concepts of each terminology, compares the notion of risk and derives a concept diagram based on the most important key concepts. The result facilitates a common understanding of ISRM across frameworks and organisational boundaries, thus enables further research, discussion, intra- and inter-firm communication.
引用
收藏
页数:23
相关论文
共 50 条
  • [31] Information Security Risk Management and Incompatible Parts of Organization
    Talabeigi, Elham
    Naeeini, Seyyed Gholamreza Jalali
    JOURNAL OF INDUSTRIAL ENGINEERING AND MANAGEMENT-JIEM, 2016, 9 (04): : 964 - 977
  • [32] An economic modelling approach to information security risk management
    Bojanc, Rok
    Jerman-Blazic, Borka
    INTERNATIONAL JOURNAL OF INFORMATION MANAGEMENT, 2008, 28 (05) : 413 - 422
  • [33] A situation awareness model for information security risk management
    Webb, Jeb
    Ahmad, Atif
    Maynard, Sean B.
    Shanks, Graeme
    COMPUTERS & SECURITY, 2014, 44 : 1 - 15
  • [34] Information Security Risk Management Model for Big Data
    Yang, Min
    ADVANCES IN MULTIMEDIA, 2022, 2022
  • [35] Enterprise Information Technology Security: Risk Management Perspective
    Rot, Artur
    WCECS 2009: WORLD CONGRESS ON ENGINEERING AND COMPUTER SCIENCE, VOLS I AND II, 2009, : 1171 - 1176
  • [36] 1 Information Security Risk Management for Systems Engineers
    Gauvain, Tony
    INCOSE International Symposium, 1999, 9 (01): : 780 - 785
  • [37] Verification, Validation, and Evaluation in Information Security Risk Management
    Fenz, Stefan
    Ekelhart, Andreas
    IEEE SECURITY & PRIVACY, 2011, 9 (02) : 58 - 65
  • [38] A Case Study on Risk Management of Enterprise Information Security
    Huang, Rengen
    Zhu, Zhen
    2015 2nd International Conference on Creative Education (ICCE 2015), Pt 2, 2015, 11 : 201 - 208
  • [39] CORRELATED FAILURES, DIVERSIFICATION, AND INFORMATION SECURITY RISK MANAGEMENT
    Chen, Pei-yu
    Kataria, Gaurav
    Krishnan, Ramayya
    MIS QUARTERLY, 2011, 35 (02) : 397 - 422
  • [40] A management perspective on risk of security threats to information systems
    Farahmand F.
    Navathe S.B.
    Sharp G.P.
    Enslow P.H.
    Information Technology and Management, 2005, 6 (2-3) : 203 - 225