AssessITS: Integrating procedural guidelines and practical evaluation metrics for organizational IT and Cybersecurity risk assessment
Mir Mehedi Rahman, Naresh Kshetri, Sayed Abu Sayeed, Md Masud Rana

TL;DR
AssessITS offers a practical, step-by-step framework for organizations to perform comprehensive IT and cybersecurity risk assessments by integrating standards and practical metrics, enhancing security and decision-making.
Contribution
It introduces 'AssessITS', a novel, actionable methodology that bridges theoretical standards with practical implementation for effective IT risk assessment.
Findings
Provides a systematic, easy-to-adopt risk assessment process
Integrates practical evaluation metrics for asset and threat quantification
Enhances decision-making for risk mitigation strategies
Abstract
In today's digitally driven landscape, robust Information Technology (IT) risk assessment practices are essential for safeguarding systems, digital communication, and data. This paper introduces 'AssessITS', an actionable method designed to provide organizations with comprehensive guidelines for conducting IT and cybersecurity risk assessments. Drawing extensively from NIST 800-30 Rev 1, COBIT 5, and ISO 31000, 'AssessITS' bridges the gap between high-level theoretical standards and practical implementation challenges. The paper outlines a step-by-step methodology that organizations can simply adopt to systematically identify, analyze, and mitigate IT risks. By simplifying complex principles into actionable procedures, this framework equips practitioners with the tools needed to perform risk assessments independently, without too much reliance on external vendors. The guidelines are…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security
