The substantial usage of information and communication
devices, and the increasing interconnectivity among systems
and organizations, is exposing organizations for
security risk and vulnerabilities, including intentional
threat that would be associated to sabotage and vandalism.
Therefore, there is a growing interest in applying
risk analysis and risk management to eliminate security
problems and protect networks.
Security Risk management is an ongoing process of
identifying these risks and implementing planes to address
them and risk assessment is the part of the ongoing
risk management process that assigns relative priorities
for mitigation plans and implementation [1]. Thus, a risk
assessment framework is needed with an approach for
categorizing and sharing information about the security
risks of the information technology infrastructure. Furthermore,
to establish useful framework for risk analysis
we have to clearly identify the risks, it is not sufficient to
refer to probabilities and expected values [2]. This paper
will evaluate different frameworks that are being in use
and then will develop an enhanced framework that will
improve the outcome of the existing security risk assessment
frameworks.
1.1. Overview of Vulnerabilities and Securi