Sunday, March 14, 2010

The Quantitative Risk Assessment

Question:
"Do you have any quantitative method for evaluating inherent risk, during a risk assessment ? I use a qualitative one that use the results of brainstorming session with head of function."

My Answer:
The quantitative risk assessment is still an open problem in the information security academic research. ( http://archive.cra.org/reports/trustworthy.computing.pdf )

Although there has been some work since 2003 on this challenge,  I think that it still exist today and it is a very difficult problem to solve.

No comments: