AssessITS : Integrating Procedural Guidelines and Practical Evaluation Metrics for Organizational IT and Cybersecurity Risk Assessment — Oak Academic Publishing
Research ArticleOpen AccessGoogle Scholar indexed
AssessITS : Integrating Procedural Guidelines and Practical Evaluation Metrics for Organizational IT and Cybersecurity Risk Assessment
School of Business & Technology, Emporia State University, Emporia, KS, USA
,
Department of Cybersecurity, Rochester Institute of Technology, Rochester, NY, USA
,
College of Business, Florida Atlantic University, Boca Raton, FL, USA
,
School of Business & Technology, Emporia State University, Emporia, KS, USA
1 School of Business & Technology, Emporia State University, Emporia, KS, USA
2 Department of Cybersecurity, Rochester Institute of Technology, Rochester, NY, USA
3 College of Business, Florida Atlantic University, Boca Raton, FL, USA
4 School of Business & Technology, Emporia State University, Emporia, KS, USA
In today’s digitally driven landscape, robust Information Technology (IT) risk assessment practices are essential for safeguarding systems, digital communication, and data. This paper introduces “ AssessITS ,” an actionable method designed to provide organizations with comprehensive guidelines for conducting IT and cybersecurity risk assessments. Drawing extensively from NIST 800-30 Rev 1, COBIT 5, and ISO 31000, “ AssessITS ” bridges the gap between high-level theoretical standards and practical implementation challenges. The paper outlines a step-by-step methodology that organizations can simply adopt to systematically identify, analyze, and mitigate IT risks. By simplifying complex principles into actionable procedures, this framework equips practitioners with the tools needed to perform risk assessments independently, without too much reliance on external vendors. The guidelines are developed to be straightforward, integrating practical evaluation metrics that allow for the precise quantification of asset values, threat levels, vulnerabilities, and impacts on confidentiality, integrity, and availability. This approach ensures that the risk assessment process is not only comprehensive but also accessible, enabling decision-makers to implement effective risk mitigation strategies customized to their unique operational contexts. “ AssessITS ” aims to enable organizations to enhance their IT security strength through practical, actionable guidance based on internationally recognized standards.
Goman, M. (2019) Current State of IT Risk Analysis in Management Frameworks: Is It Enough? 2019 60 th International Scientific Conference on Information Technology and Management Science of Riga Technical University , Riga, 10-11 October 2019, 1-5. https://doi.org/10.1109/itms47855.2019.8940653
Benaroch, M., Chernobai, A. and Goldstein, J. (2012) An Internal Control Perspective on the Market Value Consequences of IT Operational Risk Events. International Journal of Accounting Information Systems , 13, 357-381. https://doi.org/10.1016/j.accinf.2012.03.001
Bernard, P. (2012) COBIT 5: A Management Guide. Van Haren Publishing.
Goman, M. (2021) An Extended Analysis of Risk Management Concepts in IT Management Frameworks. 2021 International Conf erence on Info rmation Res ources M ana g e m en t , Linz, 19-21 May 2021, 28. https://aisel.aisnet.org/confirm2021/28
Rodríguez-Calero, M.A., Blanco-Mavillard, I., Morales-Asencio, J.M., Fernández-Fernández, I., Castro-Sánchez, E. and de Pedro-Gómez, J.E. (2020) Defining Risk Factors Associated with Difficult Peripheral Venous Cannulation: A Systematic Review and Meta-Analysis. Heart & Lung , 49, 273-286. https://doi.org/10.1016/j.hrtlng.2020.01.009
European Union Agency for Cybersecurity (2022) Risk Management Standards: Analysis of Standardization Requirements in Support of Cybersecurity Policy.
Saleh, M.S. and Alfantookh, A. (2011) A New Comprehensive Framework for Enterprise Information Security Risk Management. Applied Computing and Informatics , 9, 107-118. https://doi.org/10.1016/j.aci.2011.05.002
Aven, T. (2016) Risk Assessment and Risk Management: Review of Recent Advances on Their Foundation. European Journal of Operational Research , 253, 1-13. https://doi.org/10.1016/j.ejor.2015.12.023
Gadyatskaya, O., Harpes, C., Mauw, S., Muller, C. and Muller, S. (2016) Bridging Two Worlds: Reconciling Practical Risk Assessment Methodologies with Theory of Attack Trees. In: Lecture Notes in Computer Science , Springer, 80-93. https://doi.org/10.1007/978-3-319-46263-9_5
NIST (2012) Guide for Conducting Risk Assessments. https://csrc.nist.gov/pubs/sp/800/30/r1/final
ISO (2018) Risk Management Guidelines . https://www.iso.org/standard/65694.html
Ganin, A.A., Quach, P., Panwar, M., Collier, Z.A., Keisler, J.M., Marchese, D., et al . (2017) Multicriteria Decision Framework for Cybersecurity Risk Assessment and Management. Risk Analysis , 40, 183-199. https://doi.org/10.1111/risa.12891
Tsiodra, M., Panda, S., Chronopoulos, M. and Panaousis, E. (2023) Cyber Risk Assessment and Optimization: A Small Business Case Study. IEEE Access , 11, 44467-44481. https://doi.org/10.1109/access.2023.3272670
Shaikh, F.A. and Siponen, M. (2023) Information Security Risk Assessments Following Cybersecurity Breaches: The Mediating Role of Top Management Attention to Cybersecurity. Computers & Security , 124, Article 102974. https://doi.org/10.1016/j.cose.2022.102974
Elmarady, A.A. and Rahouma, K. (2021) Studying Cybersecurity in Civil Aviation, Including Developing and Applying Aviation Cybersecurity Risk Assessment. IEEE Access , 9, 143997-144016. https://doi.org/10.1109/access.2021.3121230
Alexandre, R.C.J., Martins, L.E.G. and Gorschek, T. (2023) Cybersecurity Risk Assessment for Medium-Risk Drones: A Systematic Literature Review. IEEE Aerospace and Electronic Systems Magazine , 38, 28-43. https://doi.org/10.1109/maes.2023.3251969
Kshetri, N., Rahman, M.M., Sayeed, S.A. and Sultana, I. (2024) Cryptoran: A Review on Cryptojacking and Ransomware Attacks W.R.T. Banking Industry—Threats, Challenges, & Problems. 2024 2 nd International Conference on Advancement in Computation & Computer Technologies , Gharuan, 2-3 May 2024, 523-528. https://doi.org/10.1109/incacct61598.2024.10550970
Kshetri, N., Mishra, R., Rahman, M.M. and Steigner, T. (2024) Hnmblock: Blockchain Technology Powered Healthcare Network Model for Epidemiological Monitoring, Medical Systems Security, and Wellness. 2024 12 th International Symposium on Digital Forensics and Security , San Antonio, 29-30 April 2024, 1-8. https://doi.org/10.1109/isdfs60797.2024.10527226
Kshetri, N., Sultana, I., Rahman, M.M. and Shah, D. (2024) DefTesPY: Cyber Defense Model with Enhanced Data Modeling and Analysis for Tesla Company via Python Language. https://arxiv.org/abs/2407.14671
National Institute of Standards and Technology (2018) Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy (NIST Special Publication 800-37 Revision 2). U.S. Department of Commerce. https://csrc.nist.gov/pubs/sp/800/37/r2/final
Fernandes, A., Almeida, R. and Mira da Silva, M. (2020) A Flexible Method for COBIT 2019 Process Selection. https://aisel.aisnet.org/amcis2020/strategic_uses_it/strategic_uses_it/3
Foley, E.B. (2019) Preparing for a Disputed Presidential Election: An Exercise in Election Risk Assessment and Management. Loyola University Chicago Law Journal , 51, Article No. 309.
Pritika, P., Shanmugam, B. and Azam, S. (2023) Risk Assessment of Heterogeneous Iomt Devices: A Review. Technologies , 11, Article No. 31. https://doi.org/10.3390/technologies11010031
Devos, Y., Elliott, K.C., Macdonald, P., McComas, K., Parrino, L., Vrbos, D., et al . (2019) Conducting Fit-for-Purpose Food Safety Risk Assessments. EFSA Journal , 17, e170707. https://doi.org/10.2903/j.efsa.2019.e170707
Kandasamy, K., Srinivas, S., Achuthan, K. and Rangan, V.P. (2020) IoT Cyber Risk: A Holistic Analysis of Cyber Risk Assessment Frameworks, Risk Vectors, and Risk Ranking Process. EURASIP Journal on Information Security , 2020, Article No. 8. https://doi.org/10.1186/s13635-020-00111-0
Zografopoulos, I., Ospina, J., Liu, X. and Konstantinou, C. (2021) Cyber-Physical Energy Systems Security: Threat Modeling, Risk Assessment, Resources, Metrics, and Case Studies. IEEE Ac cess , 9, 29775-29818. https://doi.org/10.1109/access.2021.3058403
Radanliev, P., De Roure, D.C., Nicolescu, R., Huth, M., Montalvo, R.M., Cannady, S., et al . (2018) Future Developments in Cyber Risk Assessment for the Internet of Things. Computers in In dustry , 102, 14-22. https://doi.org/10.1016/j.compind.2018.08.002
Center for Internet Security (2018) CIS Risk Assessment Method. https://www.cisecurity.org/insights/white-papers/cis-ram-risk-assessment-method