INFORMATION SECURITY AND RISK MANAGEMENT.

The article focuses on information security and risk management. The perceived composite risk (PCR) is a composite metric that focuses on the aspects of information security risk including expected loss, expected severe loss, and standard deviation of the loss. Moreover, it provides the user powerfu...

Descripción completa

Detalles Bibliográficos
Publicado en:Communications of the ACM Vol. 51; no. 4; pp. 64 - 69
Autores principales: BODIN, LAWRENCE D., GORDON, LAWRENCE A., LOEB, MARTIN P.
Formato: Artículo
Publicado: Association for Computing Machinery Apr2008
Materias:
Acceso en línea:Ver este registro en EBSCOhost
Descripción
Sumario:The article focuses on information security and risk management. The perceived composite risk (PCR) is a composite metric that focuses on the aspects of information security risk including expected loss, expected severe loss, and standard deviation of the loss. Moreover, it provides the user powerful tools for examining proposals for enhancement of an organization's information security system. Meanwhile, it is recommended to use Analytic Hierarchy Process (AHP) in determining the weights in the PCR.