The rest of this paper is organized as follows. In section 2 we reviewed the literature of
information security analysis. We discussed the information security assessment process,
quantitative security risk analysis method (including Expect Annual Loss or Estimated Annual
Cost) and the process of IT risk assessment in section 3. In section 4, we explained the future
research for information risk analysis issues; a future research direction may be development and
application of soft computing and hybrid model for information security analysis. In section 5, A
Practical advice for evaluation information security risk based on AHP and fuzzy comprehensive
evaluation is discussed. We detail examine the steps of AHP and fuzzy comprehensive
evaluation method. Section 6 is conclusion