ORCID

Abstract

Information security risk assessment is an important part of enterprises’ management practices that helps to identify, quantify, and prioritize risks against criteria for risk acceptance and objectives relevant to the organization. Risk management refers to a process that consists of identification, management, and elimination or reduction of the likelihood of events that can negatively affect the resources of the information system to reduce security risks that potentially have the ability to affect the information system, subject to an acceptable cost of protection means that contain a risk analysis, analysis of the “cost-effectiveness” parameter, and selection, construction, and testing of the security subsystem, as well as the study of all aspects of security.

DOI

10.3390/encyclopedia1030050

Publication Date

2021-07-24

Publication Title

Encyclopedia

Volume

1

Issue

3

ISSN

2673-8392

Embargo Period

2021-10-22

Organisational Unit

School of Engineering, Computing and Mathematics

First Page

602

Last Page

617

Share

COinS