An Integrated Information Security Risk Assessment (IISRA) Approach
摘要
Organizations are placing more and more emphasis on information security. Organizations rely substantially on information technology as digitalization progresses and new technologies are adopted quickly. Information security breaches can have a variety of negative effects on a company’s operations, finances, reputation, and legal standing. At the international level, small and medium organizations account for more than 90% of the business economy. Based on the significant economic contribution that small and medium organizations make, it would be reasonable to assume that they would effectively implement cyber security measures. Attackers are now focusing on small and medium organizations as an easy target because many of them lack the resources or knowledge to secure their networks and information resources. Small and medium organizations continue to be targets of cyberattacks despite the existence of well-known safeguards. In this research paper, we have developed an Integrated Information Security Risk Assessment (IISRA) Framework to implement the appropriate measurement in order to eliminate or minimize the impact that various security related threats and vulnerabilities might have on an organization.