Risk Management Standards - The Perception of ease of use



Full text

Journal of Information System Security
Volume 6, Number 3 (2010)
Pages 2341
ISSN 1551-0123
Piya Shedden — University of Melbourne, Australia
A. B. Ruighaver — Deakin University, Australia
Atif Ahmad — University of Melbourne, Australia
Information Institute Publishing, Washington DC, USA




Information security risk assessment has emerged as the primary means by which organizations secure information infrastructure. A number of risk management standards and methodologies, such as the AS/NZS 4360 and HB231 provide organizations with guidance on developing a risk assessment process. However, while there exists such high-level guidance, there is correspondingly little literature on the practice of conducting risk assessments. This paper presents the results of a case study undertaken as part of a larger investigation that examines the information security risk assessment processes implemented by organizations as well as the reasons for adopting them. This research finds that organizations apply the high-level generic methodology outlined in the AS/NZS 4360 risk management standard due to a perceived ease of use. This research also finds that organizations simplify the risk methodology for the purposes of broad application across the organization. The process of simplification is achieved at the expense of the granularity of detail thereby reducing the depth at which the methodology is applied. The resulting outcome is a risk assessment methodology that no longer reflects the comprehensive nature of the original standard.




Information Security, Risk Management, Risk Assessment, Risk Management standards, Information Security Guidelines




