1. INTRODUCTION
The rapid growth of society's dependence upon
Information Technology (IT) has precipitated a growing
apprehension about the security and reliability of this fragile
infrastructure [1]. Organisations and individuals always find
themselves under pressure to stay abreast with the current
technology in order to run their businesses or their lives
whereby their IT systems are open to the Internet [2]. There is
a tremendous amount of innovation involved with technology
which introduces a great deal of complexity within the IT
environment; resulting in a significant number of IT security
risks [3]. IT security is a complex topic and evolves almost as
fast as technology does [2].
While research in IT security has started giving importance
to IT security risk management, the focus is still on the
development of procedural guidelines and a few semiautomated
methods [2]. Several issues remain unsolved
including the need of sophisticated formalisation in the risk
management reasoning [2]. In order to bridge this existing
gap, IT security risk should be considered as just another risk
that needs to be managed alongside all other business risks,
rather than treating it as an independent technical concern [6].
For these reasons, a robust IT security risk management
process is required in order to manage IT security risks to a
tolerable level [3][6]. This paper therefore presents a process
that was employed to defme the proposed IT Security Risk
Based (ITSRB) approach, which may used as a blueprint as
well as a mechanism that can be applied by organisations to
respond to IT security risk better.
This paper is divided into four sections. Section two
presents a summarised view of a comparative analysis of five
best practice frameworks chosen for this research. The
frameworks were chosen because they inherently possess
some of the important attributes which are deemed as vital for
the definition of the proposed ITSRB approach. Section three
presents the attributes derived from the best practice
frameworks discussed in section two, with the objective of
building up the foundation of the ITSRB approach. Section
four presents the proposed ITSRB approach including its
structure and features. Section five concludes this paper by
highlighting important aspects that were used to defme the
ITSRB approach as well as the current challenges that the
discussed frameworks possess, addressed by the ITSRB
approach. The last section presents the references which were
used in this paper.