310
Views
2
CrossRef citations to date
0
Altmetric
Articles

GIRA: a general model for incident risk analysis

, &
Pages 191-208 | Received 05 Apr 2017, Accepted 29 Jun 2017, Published online: 11 Sep 2017
 

Abstract

Most existing risk analysis methods focus on analysing risks that a system might face throughout its life. However, there is no explicit method for risk analysis during incidents. Approaches such as bow-ties and attack trees provide reliable information about triggers and escalation of incidents, but do not cover risk evaluation. Risk matrices include the entire risk analysis process; however, their risk evaluation approach is oversimplified. This paper presents a General Model for Incident Risk Analysis, which formalises the incident risk analysis process through an influence diagram. Our aim is to provide a decision support model that generates reliable risk information and enhances incident risk evaluation.

Notes

1. For instance, in cybersecurity, following the McCumber Cube (McCumber Citation1991), we can express consequences as changes in the availability, integrity or confidentiality of data.

2. Although this node represents a decision, it is not modelled as a decision node because we are not analysing that decision.

Reprints and Corporate Permissions

Please note: Selecting permissions does not provide access to the full text of the article, please see our help page How do I view content?

To request a reprint or corporate permissions for this article, please click on the relevant link below:

Academic Permissions

Please note: Selecting permissions does not provide access to the full text of the article, please see our help page How do I view content?

Obtain permissions instantly via Rightslink by clicking on the button below:

If you are unable to obtain permissions via Rightslink, please complete and submit this Permissions form. For more information, please visit our Permissions help page.