Why 2 times 2 ain't neccessarily 4 - at least not in IT security risk assessment
Autor(en):
Zusammenfassung
Recently, a novel approach towards semi-quantitative IT security risk assessment has been proposed in the draft IEC 62443-3-2. This approach is analyzed from several different angles, e.g. embedding into the overall standard series, semantic and methodological aspects. As a result, several systematic flaws in the approach are exposed. As a way forward, an alternative approach is proposed which blends together semi-quantitative risk assessment as well as threat and risk analysis.
- Vollständige Referenz
- BibTeX
Braband, J.,
(2016).
Why 2 times 2 ain't neccessarily 4 - at least not in IT security risk assessment.
In:
Meier, M., Reinhardt, D. & Wendzel, S.
(Hrsg.),
Sicherheit 2016 - Sicherheit, Schutz und Zuverlässigkeit.
Bonn:
Gesellschaft für Informatik e.V..
(S. 1-10).
@inproceedings{mci/Braband2016,
author = {Braband, Jens},
title = {Why 2 times 2 ain't neccessarily 4 - at least not in IT security risk assessment},
booktitle = {Sicherheit 2016 - Sicherheit, Schutz und Zuverlässigkeit},
year = {2016},
editor = {Meier, Michael AND Reinhardt, Delphine AND Wendzel, Steffen} ,
pages = { 1-10 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
author = {Braband, Jens},
title = {Why 2 times 2 ain't neccessarily 4 - at least not in IT security risk assessment},
booktitle = {Sicherheit 2016 - Sicherheit, Schutz und Zuverlässigkeit},
year = {2016},
editor = {Meier, Michael AND Reinhardt, Delphine AND Wendzel, Steffen} ,
pages = { 1-10 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
Haben Sie fehlerhafte Angaben entdeckt? Sagen Sie uns Bescheid: Feedback abschicken
Mehr Information
ISBN: 978-3-88579-650-3
ISSN: 1617-5468
Datum: 2016
Sprache:
(en)
(en)
Typ: Text/Conference Paper

