Risk Reduction OverviewReport as inadecuate

Risk Reduction Overview - Download this document for free, or read online. Document in PDF available to download.

1 Rijkswaterstaat Delft 2 Ministry of Defense The Hague

Abstract : The Risk Reduction Overview RRO method presents a comprehensible overview of the coherence of risks, measures and residual risks. The method is designed to support communication between different stakeholders in complex risk management. Seven reasons are addressed why risk management in IT security has many uncertainties and fast changing factors, four for IT security in general and three for large organizations specifically. The RRO visualization has been proven valuable to discuss, optimize, evaluate, and audit a design or a change in a complex environment. The method has been used, evaluated, and improved over the last six years in large government and military organizations. Seven areas in design and decision making are identified in which a RRO is found to be beneficial. Despite the widely accepted need for risk management we believe this is the first practical method that delivers a comprehensive overview that improves communication between different stakeholders.

Keywords : Design Security Residual risk Risk management Security measure Visualization

Author: Hellen Havinga - Olivier Sessink -

Source: https://hal.archives-ouvertes.fr/


Related documents