Information security risk management terminology and key concepts

被引:0
|
作者
Schmidt, Michael [1 ]
机构
[1] Bavarian Acad Sci & Humanities, Leibniz Supercomp Ctr, Boltzmannstr 1,Garching N, D-85748 Munich, Germany
来源
关键词
Risk management; Information security; Terminology; Terms; Concepts; Frameworks; STATISTICAL STANDARDS; REVIEWS; ISO;
D O I
10.1057/s41283-022-00108-8
中图分类号
C [社会科学总论];
学科分类号
03 ; 0303 ;
摘要
Language is the foundation for any communication and the vocabulary used has a decisive influence on the ability of the communication partners to clearly understand each other. In Information Security Risk Management (ISRM), the terminology used is often dictated by industry standards and frameworks. However, there is no universally accepted terminology, which makes collaboration difficult for professionals and researchers alike. This publication compares the terminology defined by frequently used frameworks, such as ISO and NIST, in the field of ISRM. It examines the terms and inherent concepts of each terminology, compares the notion of risk and derives a concept diagram based on the most important key concepts. The result facilitates a common understanding of ISRM across frameworks and organisational boundaries, thus enables further research, discussion, intra- and inter-firm communication.
引用
收藏
页数:23
相关论文
共 50 条
  • [41] A meta-process for information security risk management
    Papadaki, Katerina
    Polemi, Nineta
    Damilos, Dimitrios Konnos
    GLOBAL E-SECURITY, PROCEEDINGS, 2008, 12 : 257 - +
  • [42] Fuzzy OWA Model for Information Security Risk Management
    Imamverdiev, Ya. N.
    Derakshande, S. A.
    AUTOMATIC CONTROL AND COMPUTER SCIENCES, 2011, 45 (01) : 20 - 28
  • [43] Assets Dependencies Model in Information Security Risk Management
    Breier, Jakub
    Schindler, Frank
    INFORMATION AND COMMUNICATION TECHNOLOGY, 2014, 8407 : 405 - 412
  • [44] Information Security and Risk Management: Trustworthiness and Human Interaction
    Phillips, Stephen C.
    Fair, Nicholas
    Erdogan, Gencer
    Tverdal, Simeon
    RESEARCH CHALLENGES IN INFORMATION SCIENCE, 2022, 446 : 821 - 822
  • [45] INFORMATION SECURITY OF THE BANK IN THE OPERATIONAL RISK MANAGEMENT SYSTEM
    Bezshtanko, D. V.
    FINANCIAL AND CREDIT ACTIVITY-PROBLEMS OF THEORY AND PRACTICE, 2012, 1 (12):
  • [46] Agile Approach with Kanban in Information Security Risk Management
    Dorca, Vasile
    Popescu, Sorin
    Munteanu, Radu, Jr.
    Chioreanu, Adrian
    Peleskei, Claudius
    PROCEEDING OF 2016 IEEE INTERNATIONAL CONFERENCE ON AUTOMATION, QUALITY AND TESTING, ROBOTICS (AQTR), 2016, : 19 - 24
  • [47] Information Security Risk Management in Critical Informative Systems
    Kiran, K. V. D.
    Reddy, L. S. S.
    Kumar, Velagapudi Pavan
    Dheeraj, Kalluri Krishna Sai
    2014 CONFERENCE ON IT IN BUSINESS, INDUSTRY AND GOVERNMENT (CSIBIG), 2014,
  • [48] Statistics Based Information Security Risk Management Methodology
    Saluja, Upasna
    Idris, Dato Norbik Bashah
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2015, 15 (10): : 117 - 123
  • [49] A Quantitative Model for Information-Security Risk Management
    Bojanc, Rok
    Jerman-Blazic, Borka
    ENGINEERING MANAGEMENT JOURNAL, 2013, 25 (02) : 25 - 37
  • [50] USER PARTICIPATION IN INFORMATION SYSTEMS SECURITY RISK MANAGEMENT
    Spears, Janine L.
    Barki, Henri
    MIS QUARTERLY, 2010, 34 (03) : 503 - 522