Risk analysis and risk management using MEHARI
نویسنده
چکیده
In the new information society, risks are all over, every day, each minute. The present study presents MEHARImethodology set for risk analysis and risk management developed by CLUSIF (Club de la Securite de l'Information Francais. For many years, numerous security publications have been considering risk analysis to be the foundation of security actions and referring to it as such. This is still true for the most recent standards in the domain of information security management, in particular ISO/IEC 27001, which explicitly refers to risks identifying, evaluating and treating processes. These standards that explicitly call on the idea of "risk" and the need to evaluate and control risks do not propose any methodology for analyzing risks, stating simply that organizations must choose their own methodology. It seems that even the expression "risk management" can be interpreted differently from one organization to another, and that the supporting methodologies can be significantly different depending on the objectives targeted. MEHARI -methodology set– presents ways to secure your every byte and reduce organization risks to minim.
منابع مشابه
Using fuzzy FMEA and fuzzy logic in project risk management
Risk management is one of the most important phases of project management and isthe most recently used by many researchers. In this paper, a fuzzy based method wasproposed which identifies different kinds of risks through the project life cycle.Then, the project risk magnitude can be obtained in regards to five factors, namely“severity”, “occurrence”, and “not detection” which form fuzzy FMEA a...
متن کاملDeveloping a Method for Risk Analysis in Tile and Ceramic Industry Using Failure Mode and Effects Analysis by Data Envelopment Analysis
The failure mode and effects analysis (FMEA) is a widely used analytical technique that helps to identify and reduce the risks of failure in a system, component, or process. One important issue of FMEA is the determination of the risk priorities of failure modes. Risk ranking is produced in order to prioritize the focus on each of the failure modes that are identified. In this study, we applied...
متن کاملA Comparative Study of Risk Assessment Methods, MEHARI & CRAMM with a New Formal Model of Risk Assessment (FoMRA) in Information Systems
In this article, we present a comparative study of a developed new formal mathematical model of risk assessment (FoMRA) with expert methods of risk assessment in the information systems (IS). Proposed analysis verified the correctness of theoretical assumptions of developed model. In the paper, the examples of computations illustrating the application of FoMRA and known and accepted throughout ...
متن کاملA COMPARATIVE MODEL OF EVM AND PROJECT’S SCHEDULE RISK ANALYSIS USING MONTE CARLO SIMULATION
<span style="color: #000000; font-family: Tahoma, sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: justify; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; display: inline !important; float: none; backgro...
متن کاملA COMPARATIVE MODEL OF EVM AND PROJECT’S SCHEDULE RISK ANALYSIS USING MONTE CARLO SIMULATION
<span style="color: #000000; font-family: Tahoma, sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: justify; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; display: inline !important; float: none; backgro...
متن کامل