In this study, we employ system dynamics to analyze the information systems security assessment. Specifically, we build the casual loop diagram with a set of identified factors, and then construct the SD model to reveal the risk assessment model. However, the factors identified in this paper are based upon existing efforts of information systems security assessment, which means the factors identification could be limited. In future works, we would explore comprehensive factors analysis and then extend our SD model.