Question:
"Do you have any quantitative method for evaluating inherent risk, during a risk assessment ? I use a qualitative one that use the results of brainstorming session with head of function."
My Answer:
The quantitative risk assessment is still an open problem in the information security academic research. ( http://archive.cra.org/reports/trustworthy.computing.pdf )
Although there has been some work since 2003 on this challenge, I think that it still exist today and it is a very difficult problem to solve.
No comments:
Post a Comment