Abstract – The information society is increasingly dependent
Information Systems Security Management (ISMS) and
knowledge of the security risks associated with its assets value.
However, very few risk analysis methodologies have been raised
as to create systems to analyze risks in a quick and economical,
and which in turn can leave this system dynamically update. This
paper presents a new methodology, called MARISMA, aimed at
carrying out a risk analysis simplified and dynamic, which is
valid for all companies, including SMEs, and to provide solutions
to the problems identified during the application of the scientific
method "Action Research". This methodology is being applied
directly to real cases, thus achieving a constant improvement of
its processes.