Methods and means of analysis of risks of the information security of the enterprise

Methods and means of assessing information security risks are considered. The main problems that arise in the process of performing the analysis of the security of an enterprise in the field of information security are shown. A brief review of the existing instrumental solutions to the problems of a...

Full description

Bibliographic Details
Main Authors: Damir Faritovich Fayzulayev, Boris Borisovich Morozov
Format: Article
Language:English
Published: Moscow Engineering Physics Institute 2017-07-01
Series:Bezopasnostʹ Informacionnyh Tehnologij
Subjects:
Online Access:https://bit.mephi.ru/index.php/bit/article/view/267
id doaj-a8852667ed9548778ae54e71c1b00918
record_format Article
spelling doaj-a8852667ed9548778ae54e71c1b009182020-11-24T22:21:09ZengMoscow Engineering Physics Institute Bezopasnostʹ Informacionnyh Tehnologij2074-71282074-71362017-07-01243727710.26583/bit.2017.3.09267Methods and means of analysis of risks of the information security of the enterpriseDamir Faritovich Fayzulayev0Boris Borisovich Morozov1Astrakhan State UniversityAstrakhan State UniversityMethods and means of assessing information security risks are considered. The main problems that arise in the process of performing the analysis of the security of an enterprise in the field of information security are shown. A brief review of the existing instrumental solutions to the problems of assessing the risks of information security organizations engaged in various fields of activity is given. The main advantages and disadvantages of methods for risk assessment and software based on these techniques are analyzed. The results of the review are presented, conclusions are made regarding the shortcomings of methods and tools, and the question of the optimal correlation of such concepts as the breadth of applicability of methods and software tools and reliability, accuracy and adequacy of information security risk assessment are considered. We propose new additional stages of risk analysis that allow improving existing methods and eliminating the shortcomings identified during the review.https://bit.mephi.ru/index.php/bit/article/view/267CORASCRAMMMicrosoft Security Assessment Tool (MSAT)OCTAVERiskWatchGRIFinformation security analysisanalysis and assessment of IS risksinformation securitymethods and means of IS risk assessment
collection DOAJ
language English
format Article
sources DOAJ
author Damir Faritovich Fayzulayev
Boris Borisovich Morozov
spellingShingle Damir Faritovich Fayzulayev
Boris Borisovich Morozov
Methods and means of analysis of risks of the information security of the enterprise
Bezopasnostʹ Informacionnyh Tehnologij
CORAS
CRAMM
Microsoft Security Assessment Tool (MSAT)
OCTAVE
RiskWatch
GRIF
information security analysis
analysis and assessment of IS risks
information security
methods and means of IS risk assessment
author_facet Damir Faritovich Fayzulayev
Boris Borisovich Morozov
author_sort Damir Faritovich Fayzulayev
title Methods and means of analysis of risks of the information security of the enterprise
title_short Methods and means of analysis of risks of the information security of the enterprise
title_full Methods and means of analysis of risks of the information security of the enterprise
title_fullStr Methods and means of analysis of risks of the information security of the enterprise
title_full_unstemmed Methods and means of analysis of risks of the information security of the enterprise
title_sort methods and means of analysis of risks of the information security of the enterprise
publisher Moscow Engineering Physics Institute
series Bezopasnostʹ Informacionnyh Tehnologij
issn 2074-7128
2074-7136
publishDate 2017-07-01
description Methods and means of assessing information security risks are considered. The main problems that arise in the process of performing the analysis of the security of an enterprise in the field of information security are shown. A brief review of the existing instrumental solutions to the problems of assessing the risks of information security organizations engaged in various fields of activity is given. The main advantages and disadvantages of methods for risk assessment and software based on these techniques are analyzed. The results of the review are presented, conclusions are made regarding the shortcomings of methods and tools, and the question of the optimal correlation of such concepts as the breadth of applicability of methods and software tools and reliability, accuracy and adequacy of information security risk assessment are considered. We propose new additional stages of risk analysis that allow improving existing methods and eliminating the shortcomings identified during the review.
topic CORAS
CRAMM
Microsoft Security Assessment Tool (MSAT)
OCTAVE
RiskWatch
GRIF
information security analysis
analysis and assessment of IS risks
information security
methods and means of IS risk assessment
url https://bit.mephi.ru/index.php/bit/article/view/267
work_keys_str_mv AT damirfaritovichfayzulayev methodsandmeansofanalysisofrisksoftheinformationsecurityoftheenterprise
AT borisborisovichmorozov methodsandmeansofanalysisofrisksoftheinformationsecurityoftheenterprise
_version_ 1725771883432902656