Bulletin of Cherkasy State Technological University

ISSN 2306-4412
E-ISSN 2708-6070

  • Home
  • Articles & Issues
    • Current
    • All Issues
  • About
    • Aims and Scope
    • Editorial Board
    • Indexing
  • For Authors
    • Submission Terms and Author's Rights
    • Formatting Guidelines
    • Peer Review Process
    • Funding Policy
  • Ethics & Policies
    • Publication Ethics
    • Conflict of Interest
    • Open Access & Archiving Policy
    • Complaints Policy
    • Privacy Statement
    • Corrections and Retractions
    • Anti-plagiarism Policy
    • Generative AI Policy
  • Contacts
Submit an article
en
  • Українська

Article

Download article

Analysis of methods and means to implement a risk-oriented approach in the context of providing enterprise information security

Т. Savelieva, Оlena Panasko, О. Prigodyuk

Received 30.11.2017, Revised 13.02.2018, Accepted 10.03.2018

Abstract

The article is devoted to the actual problem of the present – the information security development on the base of risk-oriented approach for solving the problems of information security management for an enterprise. Modern business development trends require the need for risk management. The authors research methods and tools that allow to implement a risk-oriented approach in the context of providing enterprise information security and to analyze and evaluate information risks of information security system. The paper considers a series of the tools representatives, most commonly used in this area, and analyzes several risk assessment methodologies, in particular CRAMM (UK) – the methodology for analysis and risk management, OCTAVE for assessing assets and vulnerability of information security, etc., and a series of regulatory documents, among which NIST SP800-30 (risk management in information technology system); ISO/IEC 27005:2011 (information security risk management methods); ENISA (information security risk assessment) and many others. The analysis of the software advantages and disadvantages for the determination and assessment of information security risks (CRAMM, CORAS, Risk Watch, OCTAVE, Oracle Crystal Ball) is presented and a number of recommendations according to the feasibility of using the considered software and management documentation taking into account relevant requirements and criteria of enterprises and organizations is formed

Keywords:

information technologies; information security; threats; vulnerability; information risks; risk assessment

https://doi.org/10.24025/2306-4412.1.2018.153279

Retrieved from Volume 23, No. 1, 2018

Pages 81-89

Share
Facebook
Twitter
LinkedIn
Email
Telegram
Viber
WhatsApp
  • 1,558 Views
  • Read article
References Suggested citation

References

References in the process of publication

Suggested citation

Savelieva, Т. , Panasko, O., & Prigodyuk , O. (2018). Analysis of methods and means to implement a risk-oriented approach in the context of providing enterprise information security . Bulletin of Cherkasy State Technological University, 23(1), 81-89. https://doi.org/10.24025/2306-4412.1.2018.153279

18006, Ukraine, Cherkasy, 460, Shevchenko Blvd.

info@bulletin-chstu.com.ua

  • Contacts
  • Home
  • All Issues

© 2026 Bulletin of Cherkasy State Technological University