• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. Risk variance. Towards a definition of varying outcomes of IT security risk assessment
 
  • Details
  • Full
Options
2022
Conference Paper
Title

Risk variance. Towards a definition of varying outcomes of IT security risk assessment

Abstract
Assessing IT-security risks in order to achieve adequate and efficient protection measures has become the core idea of various industry practices and regulatory frameworks in the last five years. Some research however suggests that the practice of assessing IT security risks may be subject to varying outcomes depending on personal, situational and contextual factors. In this contribution we first provide a definition of risk variance as the variation of risk assessment outcomes due to individual traits, the processual environment, the domain of the assessor, and possibly the target of the assessed risk. We then present the outcome of an interview series with 9 decision makers from different companies that aimed at discussing whether risk variance is an issue in their risk assessment procedures. Finally, we elaborate on the generalizability of the concept of risk variance, despite the low sample size in light of varying risk assessment procedures discussed in the interviews. We find that risk variance could be a general problem of current risk assessment procedures.
Author(s)
Kurowski, Sebastian  
Fraunhofer-Institut für Arbeitswirtschaft und Organisation IAO  
Schunck, Christian Heinrich
Fraunhofer-Institut für Arbeitswirtschaft und Organisation IAO  
Mainwork
Open Identity Summit 2022  
Conference
Open Identity Summit 2022  
Open Access
File(s)
Download (262.13 KB)
Rights
CC BY-SA
DOI
10.18420/OID2022_08
10.24406/publica-r-418527
Language
English
Fraunhofer-Institut für Arbeitswirtschaft und Organisation IAO  
Keyword(s)
  • Risk Analysis

  • Risk Assessment

  • Risk Management

  • IT-Security

  • Information Security

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024