Dynamicity
Prior to defining the security controls of an IT system, it is
essential to enumerate the threats to the system in question in
order to help system architects or designers to develop realistic
and meaningful security requirements [27]. It is important to
implement a risk approach that is vigorous so that risk can be
treated in a proactive manner [26]. IT is dynamic and for this
reason IT security threats also change quite often [28].
Therefore in order to achieve this principle it is important to
define an approach that will periodically cater for the changing
threats of the IT environment through a continuous monitoring
exercise [22].
The above attributes, are the rudimentary and sourced from
the various literature but are not all-inclusive enough to fully
defme an IT security risk management approach proposed by
this research. The next section defines the proposed IT
security risk management approach that is based on the
discussed attributes.