Methodology and algorithm of information security risk management for local infrastructure

Main Article Content

Article Sidebar

Published Feb 14, 2018
Bulai Rodica Ciorbă Dumitru Poştaru Andrei Rostislav Călin


The complexity of information security does not resume to mere technicality, transferring significant liability to proper management. Risk analysis in information security is a powerful tool that comes in handy for managers in making decisions about the implementation of efficient information management systems, in order to achieve the organization's mission.

As a part of risk management, risk analysis is the systematic implementation of methods, techniques and management practices to assess the context, identify, analyze, evaluate, treat, monitor and communicate the risks for the information security and systems through which they are processed, stored or transmitted.

The ISO/IEC 27005:2011 – Information security risk management, does not specify any particular method for managing the risks associated with information security, but a general approach. It is up to the organization to devise control objectives that would reflect specific approaches to risk management and the degree of assurance required.

There are several models, methodologies and tools amongst which those like CRAMM (United Kingdom, Insight Consulting), Risicare/Mehari (France, Clusif), GSTool (Germany, ITGrundschutz). The theoretical model of the mentioned methodologies is hard to put in practice without experience required from the members of the risk analysis team. Using the appropriate risk assessment solution, an organization can devise its own security requirements.

How to Cite

Rodica, Bulai, Ciorbă Dumitru, Poştaru Andrei, and Rostislav Călin. 2018. “Methodology and Algorithm of Information Security Risk Management for Local Infrastructure”. Central and Eastern European EDem and EGov Days 325 (February):399-410.


Download data is not yet available.
Abstract 197 | PDF Downloads 217

Article Details