I. D. Sánchez-García, T. S. Feliu, J. Calvo-Manzano
{"title":"Unraveling the establishment of residual risk in cybersecurity","authors":"I. D. Sánchez-García, T. S. Feliu, J. Calvo-Manzano","doi":"10.1109/CIMPS57786.2022.10035673","DOIUrl":null,"url":null,"abstract":"This paper addresses the background, concepts, related variables, and current problems related to the calculation of Residual Risk (RR) in cybersecurity management systems. The objective of this paper is to clarify the concept of residual risk and identify the main problems that prevent the establishment of an adequate residual risk calculation at the organizational level and to provide possible solutions to this problem that will serve as a starting point for both practitioners and researchers in measuring the effectiveness of the countermeasures applied.","PeriodicalId":205829,"journal":{"name":"2022 11th International Conference On Software Process Improvement (CIMPS)","volume":"136 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-10-19","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 11th International Conference On Software Process Improvement (CIMPS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CIMPS57786.2022.10035673","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
This paper addresses the background, concepts, related variables, and current problems related to the calculation of Residual Risk (RR) in cybersecurity management systems. The objective of this paper is to clarify the concept of residual risk and identify the main problems that prevent the establishment of an adequate residual risk calculation at the organizational level and to provide possible solutions to this problem that will serve as a starting point for both practitioners and researchers in measuring the effectiveness of the countermeasures applied.