Quantitative vs Qualitative Risk Analysis: Metrics and OCTAVE
Quantitative vs Qualitative Risk Analysis: Metrics and OCTAVE
Quantitative Risk Analysis
Quantitative risk analysis, as described by Kim & Solomon (2014), attempts to describe risk in financial terms and put a dollar value on all the elements of risk. The quantitative risk is numerically based data and has a financial data objective.
One disadvantage to the quantitative analysis method is that many risks have values that are challenging to size as Kim & Solomon (2014) point out. These consist of reputation and the availability of countermeasures. Exact numbers can be challenging to define, particularly the cost of the impact of future events.
Qualitative Risk Analysis
Qualitative risk analysis, as described by Kim & Solomon (2014), defines a risk scenario and then figures out the influence of the event would have on the organization operations. The qualitative scenario-based data is scenario-oriented subjective. To make this happen one needs to discuss with the business unit heads who know what would occur if a disaster were to strike their departments. This allows the organizations business units and technical professionals to recognize the ripple effects of an event on other departments or operations. The process of gathering information from these experts is called the delphi qualitative technique as Kim & Solomon (2014) points out.
Quantitative and Qualitative Security Metrics
Many of the quantitative metrics are technical and derived from Information Technology systems as Brotby (2009) discusses. Examples of quantitative performance metrics are packets dropped by a firewall or processor bandwidth utilization.
For many management activities, qualitative metrics are likely to be more useful than available quantitative measures for managing a security program as Brotby (2009) declares. Examples of qualitative metrics are in the form of aesthetics or client satisfaction metrics or the use of best industry practices.
Choosing OCTAVE for the Work Setting
The Operationally Critical Threat, Asset, and Vulnerability Evaluatio (OCTAVE) security risk assessment method would be chosen for use at the current work setting since Landol (2016) identifies this method for large organization and have run tools of their own. OCTAVE is also good with multilayered hierarchies, organizations that run there own computer equipment and vulnerability assessment tools.
References
Brotby, W. K. (2009). Information security management metrics . Auerbach Publications.
Kim, D., & Solomon, M. G. (2014). Fundamentals of information systems security (2nd ed.). Jones & Bartlett Learning.
Landoll, D. (2016). The security risk assessment handbook (2nd ed.). CRC Press.