Article ID: | iaor19912054 |
Country: | United Kingdom |
Volume: | 1 |
Start Page Number: | 121 |
End Page Number: | 130 |
Publication Date: | Apr 1991 |
Journal: | European Journal of Information Systems |
Authors: | Baskerville R. |
Keywords: | information, risk |
Risk analysis is the predominant technique used by information security professionals to establish the feasibility of information systems controls. Yet it fails an essential test of scientfic method-it lacks statistical rigour and is subject to social misuse. Adoption of alternatives from other disciplines, however, proves even more implausible. Indeed, even improved rigour in risk analysis may limit its usefulness. Perhaps risk analysis is misconceived: its ostensible value as a predictive technique is less relevant than its value as an effective communications link between the security and management professionals who must make decisions concerning capital investments in information systems security.