An empirical test of the perceived relationship between risk and the constituents severity and probability

نویسندگان

  • Teodor Sommestad
  • Henrik Karlzén
  • Peter Nilsson
  • Jonas Hallberg
چکیده

Purpose – In methods and manuals, the product of an information security incident’s probability and severity is seen as a risk to manage. The purpose of the test described in this paper is to investigate if information security risk is perceived in this way, if decision-making style influences the perceived relationship between the three variables and if the level of information security expertise influences the relationship between the three variables. Design/methodology/approach – Ten respondents assessed 105 potential information security incidents. Ratings of the associated risks were obtained independently from ratings of the probability and severity of the incidents. Decision-making style was measured using a scale inspired from the Cognitive Style Index; information security expertise was self-reported. Regression analysis was used to test the relationship between variables. Findings – The ten respondents did not assess risk as the product of probability and severity, regardless of experience, expertise and decision-making style. The mean variance explained in risk ratings using an additive term is 54.0 or 38.4 per cent, depending on how risk is measured. When a multiplicative term was added, the mean variance only increased by 1.5 or 2.4 per cent. For most of the respondents, the contribution of the multiplicative term is statistically insignificant. Practical Implications – The inability or unwillingness to see risk as a product of probability and severity suggests that procedural support (e.g. risk matrices) has a role to play in the risk assessment

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

The Assessment of Perceived Risk of Chemical-related Illness Among Inhabitant Community Adjacent to an Industrial Unit

The perceived risk is assessed in order to conduct subjective evaluation of individual or community of probability of occurrence of accidents, crashes, and way of exposure to the related consequences. Although such estimation may not comply with what it occurs in real situation since this part is totally related to psychological aspect and at the same time it should be incorporated in planning ...

متن کامل

Delphi application in solicitation of qualitative risk factors for estimation of a perceived probability of default: Case of Karafarin Bank

Unreliability of financial statements in Iran has urged this country’s financial services industry management to manipulate practices by which they could gain reliable risk scores for borrowers. This research extracts the most influential qualitative factors that would impact the default of a business relationship borrower. Solicitation of the factors is done through Delphi methodology. The mea...

متن کامل

Dependence of Default Probability and Recovery Rate in Structural Credit Risk Models: Empirical Evidence from Greece

The main idea of this paper is to study the dependence between the probability of default and the recovery rate on credit portfolio and to seek empirically this relationship. We examine the dependence between PD and RR by theoretical approach. For the empirically methodology, we use the bootstrapped quantile regression and the simultaneous quantile regression. These methods allow to determinate...

متن کامل

نقش اعتقادات بهداشتی در انجام رفتارهای پیشگیری کننده از دیابت نوع 2 در افراد در معرض خطر

Background: Diabetes mellitus is an important health problem that leads to severe complications, is the cause of early death, and is showing an increase in frequency. Development of positive health behaviors is extremely important for prevention of diabetes in at high- risk individuals. This study aims to identify the relationship between health beliefs and diabetes preventive behaviors in indi...

متن کامل

Factors Affecting Social Commerce and Exploring the Mediating Role of Perceived Risk (Case Study: Social Media Users in Isfahan)

Owing to the ever-increasing prevalence of social media use, social commerce has become an important part of e-commerce. This study endeavors to explore the impact of social media quality and social support on the social commerce (SC) intention directly and through the variable of perceived risk. The sample included 214 social media users in Isfahan collected through simple random sampling meth...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • Inf. & Comput. Security

دوره 24  شماره 

صفحات  -

تاریخ انتشار 2016