Phd TIM8301.. Appraise risk Analysis, Frameworks, and Models
Appraise Risk Analysis, Frameworks, and Models
Abstract
This paper investigates the relationship between Information Systems (IS) integration and the use of cybersecurity countermeasures using an adopted exposure to risk perspective which considers both the probability of a risk through vulnerability points theory and the impact of the risk if it occurs. Based on an economic analysis of survey sample of 9, 721 French firms, the study finds that higher degrees of system integration entail higher degrees of cybersecurity usage; whereas previously, it was thought that system integration would reduce the number of vulnerabilities and thus the need for cybersecurity countermeasures, we find that the more that the more the system is integrated, the greater the use of self-protective cybersecurity countermeasures.
We theorize that this finding comes from the elimination of many uncontrollable vulnerabilities and the presence of fewer but controllable, vulnerability points. This finding holds both for internal and external integration but is stronger in the latter case. Moreover, results show that internal dynamism is positively correlated with cybersecurity countermeasures. Our reasoning applies to cybersecurity in terms of self-protective security measures.
Defining Risk Appetite
One of the greatest challenges facing technology risk managers is the concept of risk appetite. The release of the revised Committee of Sponsoring Organizations (COSO) Enterprise Risk Management -- ERTM framework. The COSO ERM framework’s glossary defines “risk” as “the possibility that events will occur and affect the achievement of strategy and business objectives” and “risk appetite” as “the types and amount of risk, on a broad level, an organization is willing to accept in pursuit of value. Companies accept to achieve business objectives and strategies; they must have an online presence and leverage technology to drive efficient and competitive service delivery strategies. These same technologies, however, can also cause significant damage to an entity’s reputation and lead to lawsuits.