In this study, we employ system dynamics to analyze the information systems security
assessment. Specifically, we build the casual loop diagram with a set of identified factors, and
then construct the SD model to reveal the risk assessment model. However, the factors identified in this paper are based upon existing efforts of information systems security
assessment, which means the factors identification could be limited. In future works, we
would explore comprehensive factors analysis and then extend our SD model.