Quantitative and Qualitative Approach for IT Risk Assessment

  • Sung S
N/ACitations
Citations of this article
66Readers
Mendeley users who have this article in their library.

Abstract

— IT risk management currently plays more and more important role in almost all aspects of contemporary organizations' functionality. It requires reliable and cyclical realization of its key task which is risk analysis. Literature of subject presents problems of risk analysis in different way, the most often skipped or selectively treated the problem of quantitative methods application for the purpose of risk analysis. The article presents the issue of one of the most significant stages of risk analysis which is IT risk assessment, especially focusing on chosen quantitative methods such as ALE (Annual Loss Expected) method, Courtney method, Fisher's method, using survey research ISRAM model (Information Security Risk Analysis Method) and other derived ratios. There were also shortly presented chosen qualitative methods – FMEA (Failure Mode and Effects Analysis) and FMECA (Failure Mode and Effects Criticality Analysis), NIST SP 800-30 method and CRAMM methodology.

Cite

CITATION STYLE

APA

Sung, S. H. (2015). Quantitative and Qualitative Approach for IT Risk Assessment. Asia-Pacific Journal of Convergent Research Interchange, 1(1), 29–35. https://doi.org/10.21742/apjcri.2015.03.04

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free