Enhancing Information Security Risk Management for Organizations

AuthorsSubir Kochar, Sachin Goyal, Ratish Agarwal, Mahesh Pawar


Abstract - Risk is defined as the uncertainty of results which can be either positive opportunity or a threat for the organization. The research will start from introduction of risks, impact of risk, Risk Factors, Type of Risks. Risk management which is a critical area is then focused for assessing, optimizing risks. A major part in risk management is risk assessment and analysis which derives data for decision making. Risk management is summarized including the different phases of it including risk identification, assessment and mitigation. A glimpse of desirable characteristics of an ideal risk management is also mentioned. After that problem like no identification procedure for critical controls, problem with management of dynamic risks and selection of existing methodology are discussed. The research will go through the comparative framework of existing methodologies for easing selection and also Talks about ISO 27005 and COBIT framework for overcoming the problems.


Risk Management, Risk Assessment, Risk Identification, Risk Mitigation, COBIT.