Back to Search Start Over

The Validity of Information Security Risk Assessment Methods for Organizations.

Authors :
Astakhova, L. V.
Source :
Scientific & Technical Information Processing; Oct2020, Vol. 47 Issue 4, p241-247, 7p
Publication Year :
2020

Abstract

Based on statistical data, a contradiction is shown between an increase in financial investments in the information security (IS) of organizations and a steady increase in the number of IS incidents caused by internal users. A conclusion is made about the cognitive vulnerability and low degree of validity of modern IS risk assessment methods. Stereotypes have been identified, the result of which are cognitive errors in assessing IS risks: the priority of technical protection of information from external threats of IS over organizational and technical protection from internal threats; distrust of the internal client, perception of it exclusively as an object of tough managerial influence, ignoring its subjective role in IS management; restriction of work with personnel within the IS management system with one-time measures and static criteria for assessing human risks and inattention to systemic measures and dynamic, situational criteria. The necessity of updating standards for IS risk management, as well as the development of new methods and tools for assessing, IS risks based on rejecting outdated stereotypes, is substantiated. [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
01476882
Volume :
47
Issue :
4
Database :
Complementary Index
Journal :
Scientific & Technical Information Processing
Publication Type :
Academic Journal
Accession number :
149026798
Full Text :
https://doi.org/10.3103/S014768822004005X