Risk analysis needs some complex steps of information security risk assessment process. It
required doing comprehensive and integrated analysis for risk identification, estimation and
evaluation. In organization, quantitative and qualitative analysis methods are two fundamental
methods to use for analysis of risk on which assets are exposed. But there have some
disadvantages for information risk assessment methods (see Table 1).