Risk Reduction Overview

Abstract : The Risk Reduction Overview (RRO) method presents a comprehensible overview of the coherence of risks, measures and residual risks. The method is designed to support communication between different stakeholders in complex risk management. Seven reasons are addressed why risk management in IT security has many uncertainties and fast changing factors, four for IT security in general and three for large organizations specifically. The RRO visualization has been proven valuable to discuss, optimize, evaluate, and audit a design or a change in a complex environment. The method has been used, evaluated, and improved over the last six years in large government and military organizations. Seven areas in design and decision making are identified in which a RRO is found to be beneficial. Despite the widely accepted need for risk management we believe this is the first practical method that delivers a comprehensive overview that improves communication between different stakeholders.
Complete list of metadatas

Cited literature [12 references]  Display  Hide  Download

https://hal.inria.fr/hal-01403999
Contributor : Hal Ifip <>
Submitted on : Monday, November 28, 2016 - 11:27:14 AM
Last modification on : Tuesday, November 29, 2016 - 1:04:50 AM
Long-term archiving on : Tuesday, March 21, 2017 - 12:12:21 AM

File

978-3-319-10975-6_18_Chapter.p...
Files produced by the author(s)

Licence


Distributed under a Creative Commons Attribution 4.0 International License

Identifiers

Citation

Hellen Havinga, Olivier Sessink. Risk Reduction Overview. International Cross-Domain Conference and Workshop on Availability, Reliability, and Security (CD-ARES), Sep 2014, Fribourg, Switzerland. pp.239-249, ⟨10.1007/978-3-319-10975-6_18⟩. ⟨hal-01403999⟩

Share

Metrics

Record views

125

Files downloads

66