Strategic Approaches in Network Communication and Information Security Risk Assessment

0Citations
Citations of this article
17Readers
Mendeley users who have this article in their library.

Abstract

Risk assessment is a critical sub-process in information security risk management (ISRM) that is used to identify an organization’s vulnerabilities and threats as well as evaluate current and planned security controls. Therefore, adequate resources and return on investments should be considered when reviewing assets. However, many existing frameworks lack granular guidelines and mostly operate on qualitative human input and feedback, which increases subjective and unreliable judgment within organizations. Consequently, current risk assessment methods require additional time and cost to test all information security controls thoroughly. The principal aim of this study is to critically review the Information Security Control Prioritization (ISCP) models that improve the Information Security Risk Assessment (ISRA) process, by using literature analysis to investigate ISRA’s main problems and challenges. We recommend that designing a streamlined and standardized Information Security Control Prioritization model would greatly reduce the uncertainty, cost, and time associated with the assessment of information security controls, thereby helping organizations prioritize critical controls reliably and more efficiently based on clear and practical guidelines.

Cite

CITATION STYLE

APA

Alsafwani, N., Fazea, Y., & Alnajjar, F. (2024, June 1). Strategic Approaches in Network Communication and Information Security Risk Assessment. Information (Switzerland). Multidisciplinary Digital Publishing Institute (MDPI). https://doi.org/10.3390/info15060353

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free