Selection and Application of Appropriate Analytical Methods Needed to Assess the Risks Reducing the Security of the Protected System

J. Reitšpís, Martin Mašľan, Ihor Britchenko
{"title":"Selection and Application of Appropriate Analytical Methods Needed to Assess the Risks Reducing the Security of the Protected System","authors":"J. Reitšpís, Martin Mašľan, Ihor Britchenko","doi":"10.30525/2256-0742/2021-7-3-1-8","DOIUrl":null,"url":null,"abstract":"Risk assessment is one of the prerequisites for understanding its causes and possible consequences. We base our risk assessment on the principles described in the European standard EN 31000 - Risk Management Process. This standard comprehensively describes the continuous activities that are necessary in managing risks and minimizing their possible adverse effects on the operation of the system under investigation. In this activity, it is necessary to first identify the existing risks, then analyze and evaluate the identified risks. In the analysis of existing risks, it is possible to use both qualitative and quantitative analytical methods, or combine them. We use qualitative methods in cases where we do not have a sufficient amount of input information, these are more subjective. Quantitative methods are more accurate, but also more demanding on input information and time. The choice of a suitable analytical method is a basic prerequisite for knowledge of risks and their evaluation. The values of individual risks obtained in this way are the basis for determining the measures that are necessary to minimize them, i.e., to adjust them to an acceptable level. The draft measures are always based on the value of the individual components used to calculate the risk number, as well as on the value of the asset , which needs to be protected. Appropriately chosen analytical methods are one of the basic prerequisites for the consistent application of the principles of risk management, as a continuous process aimed at increasing the overall security of the system under study. In the article, the author describes the procedures used in risk assessment, as well as specific analytical methods that can be used in working with risks. The aim of identifying risk factors is to create a list of events that could cause undesirable disruption to ongoing processes. At this stage, we define all the risks that will be subsequently analyzed and evaluated. When identifying, we can use methods such as, e.g. SWOT, PHA (Preliminary Hazard Analysis) or CA (Checklist Analysis). Methods suitable for determining the causes and creating scenarios for the course of a risk event are ETA (Event Tree Analysis) or FTA (Fault Tree Analysis). The basic analysis of the system can be performed using the FMEA method (Failure Mode and Effect Analysis), which provides a numerical risk assessment. By comparison with the numerical value of the risk that we are willing to accept, we obtain 2 groups of risks. Acceptable, which will be given regular attention and unacceptable, which we will focus on in risk management and we will try to minimize its negative affect on the functioning of the system under study.","PeriodicalId":284021,"journal":{"name":"International Political Economy: Investment & Finance eJournal","volume":"90 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-06-25","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Political Economy: Investment & Finance eJournal","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.30525/2256-0742/2021-7-3-1-8","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Risk assessment is one of the prerequisites for understanding its causes and possible consequences. We base our risk assessment on the principles described in the European standard EN 31000 - Risk Management Process. This standard comprehensively describes the continuous activities that are necessary in managing risks and minimizing their possible adverse effects on the operation of the system under investigation. In this activity, it is necessary to first identify the existing risks, then analyze and evaluate the identified risks. In the analysis of existing risks, it is possible to use both qualitative and quantitative analytical methods, or combine them. We use qualitative methods in cases where we do not have a sufficient amount of input information, these are more subjective. Quantitative methods are more accurate, but also more demanding on input information and time. The choice of a suitable analytical method is a basic prerequisite for knowledge of risks and their evaluation. The values of individual risks obtained in this way are the basis for determining the measures that are necessary to minimize them, i.e., to adjust them to an acceptable level. The draft measures are always based on the value of the individual components used to calculate the risk number, as well as on the value of the asset , which needs to be protected. Appropriately chosen analytical methods are one of the basic prerequisites for the consistent application of the principles of risk management, as a continuous process aimed at increasing the overall security of the system under study. In the article, the author describes the procedures used in risk assessment, as well as specific analytical methods that can be used in working with risks. The aim of identifying risk factors is to create a list of events that could cause undesirable disruption to ongoing processes. At this stage, we define all the risks that will be subsequently analyzed and evaluated. When identifying, we can use methods such as, e.g. SWOT, PHA (Preliminary Hazard Analysis) or CA (Checklist Analysis). Methods suitable for determining the causes and creating scenarios for the course of a risk event are ETA (Event Tree Analysis) or FTA (Fault Tree Analysis). The basic analysis of the system can be performed using the FMEA method (Failure Mode and Effect Analysis), which provides a numerical risk assessment. By comparison with the numerical value of the risk that we are willing to accept, we obtain 2 groups of risks. Acceptable, which will be given regular attention and unacceptable, which we will focus on in risk management and we will try to minimize its negative affect on the functioning of the system under study.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
评估降低被保护系统安全性的风险所需的适当分析方法的选择和应用
风险评估是了解其原因和可能后果的先决条件之一。我们的风险评估基于欧洲标准EN 31000 -风险管理过程中描述的原则。本标准全面描述了管理风险和最小化其对所调查体系运行可能产生的不利影响所必需的持续活动。在这个活动中,首先要识别存在的风险,然后对识别出来的风险进行分析和评价。在对现有风险的分析中,可以同时使用定性和定量分析方法,或者两者结合使用。在没有足够输入信息的情况下,我们使用定性方法,这些方法更主观。定量方法更准确,但对输入信息和时间的要求也更高。选择合适的分析方法是了解风险及其评估的基本前提。以这种方式获得的个别风险值是确定必要措施的基础,以尽量减少风险,即将其调整到可接受的水平。这些措施草案总是基于用于计算风险数的单个组件的价值,以及需要保护的资产的价值。适当选择的分析方法是一贯应用风险管理原则的基本先决条件之一,是一个旨在增加所研究系统的全面安全的持续过程。在文章中,作者描述了在风险评估中使用的程序,以及在处理风险时可以使用的具体分析方法。识别风险因素的目的是创建一个事件列表,这些事件可能会对正在进行的过程造成不期望的中断。在这个阶段,我们定义了所有的风险,这些风险随后将被分析和评估。在识别时,我们可以使用诸如SWOT, PHA(初步危害分析)或CA(检查表分析)等方法。适用于确定风险事件发生原因和创建场景的方法有ETA(事件树分析)和FTA(故障树分析)。系统的基本分析可以使用FMEA(失效模式和影响分析)方法进行,该方法提供了数值风险评估。通过与我们愿意接受的风险数值的比较,我们得到了两组风险。可接受的,我们将经常予以注意;不可接受的,我们将在风险管理中集中注意,我们将尽量减少其对所研究系统运作的负面影响。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
The Impact of Socioemotional Wealth on Corporate Reporting Readability in a Multinational Family-Controlled Firm Stock Ownership of Federal Judges and its Impact on Corporations Place-Based Policies and the Geography of Corporate Investment Foreign bias in equity portfolios: Informational advantage or familiarity bias? Quantifying the Impact of Impact Investing
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1