English

Why 2 times 2 ain't necessarily 4 - at least not in IT security risk assessment

Cryptography and Security 2016-03-14 v1

Abstract

Recently, a novel approach towards semi-quantitative IT security risk assessment has been proposed in the draft IEC 62443-3-2. This approach is analyzed from several different angles, e.g. embedding into the overall standard series, semantic and methodological aspects. As a result, several systematic flaws in the approach are exposed. As a way forward, an alternative approach is proposed which blends together semi-quantitative risk assessment as well as threat and risk analysis.

Keywords

Cite

@article{arxiv.1603.03710,
  title  = {Why 2 times 2 ain't necessarily 4 - at least not in IT security risk assessment},
  author = {Jens Braband},
  journal= {arXiv preprint arXiv:1603.03710},
  year   = {2016}
}

Comments

10 pages, 2 figures, 2 tables, submitted to SICHERHEIT2016