Risk Management - Risk Assessment MethodsInventory of Risk Management / Risk Assessment MethodsENISA has generated an inventory of Risk Management / Risk Assessment methods. A total 13 methods have been considered. Each method in the inventory has been described through a template. The template used consists of 21 attributes that describe characteristics of a method. The structure of the template and the meaning of each attribute can be found here. The methods considered have been selected by the ENISA ad hoc Working Group on technical and policy aspects of Risk Assessment and Risk Management [ENISA-WG]. The inventory of methods is not exhaustive. Due to the composition of the ENISA Working Group (experts from eight EU member states) as well as the time available, only a limited number of methods were addressed. Therefore, these pages do not contain a complete list of methods and standards dealing with IT risks. Specific methods were deliberately excluded from the survey:
However, as the inventory is an open list, additional methods will be included in the future. For this purpose, ENISA is currently developing a process for submission of additional methods through standardization bodies/vendors, etc., as well as a process to update existing inventory entries. The information included in the inventory of methods has been assessed by the experts of the ENISA Working Group in 2005 and reflects the status of the assessed methods at that time. In cases of newer releases it might be the case that some of the method properties described in the templates do not correspond to the current version. Through recurring assessments this information will be permanently updated. | |