Information security risk management model: A state of the art review

Authors

  • Mauro Nestor Zevallos Morales Universidad Nacional Mayor de San Marcos, Facultad de Ingeniería de Sistemas e Informática. Lima, Peru

DOI:

https://doi.org/10.15381/rpcs.v2i2.17103

Keywords:

Risk, risk management, information security, ISO / IEC 27001

Abstract

Both public and private organizations are going through dynamic scenarios with the emergence and inrush of new information technologies, making an increasingly intensive use of information. When analyzing the processes and interrelationships of these organizations with the information resources they access, it is essential to consider the new risks to which organizations are exposed. This requires developing risk management strategies that facilitate the analysis, identification and treatment of the risks associated with information assets in order to find ways to minimize the negative impact. In this scenario, the use of risk management models that simplify and systematize these tasks are useful.

The present study includes a review of the literature referring to risk management frameworks, models and methodologies, to identify the activities, elements and components to develop for the development of a risk management model oriented to information security, which allows covering issues related to information security, cybersecurity and compliance with the particular requirements of the organization for the development of a model aligned to the needs and requirements of an organization.

Downloads

Published

2020-02-28

Issue

Section

Review

How to Cite

Information security risk management model: A state of the art review. (2020). Revista Peruana De Computación Y Sistemas, 2(2), 43-60. https://doi.org/10.15381/rpcs.v2i2.17103