|
An Introduction To |
||||||||||
Comparing the Two ApproachesBoth qualitative and quantitative approaches to security risk management have their advantages and disadvantages. Certain situations may call for organizations to adopt the quantitative approach. Alternatively, organizations of small size or with limited resources will probably find the qualitative approach much more to their liking. The following table summarizes the benefits and drawbacks of each approach:
Figure 3 - Comparison between 'Qualitative' and 'Quantitative' risk processes In years past, the quantitative approaches seemed to dominate security risk management and this is still prevalent in the US. This has changed recently as more and more practitioners have admitted that strictly following quantitative risk management processes typically results in difficult, long-running projects that see few tangible benefits. This has led to the favouring of qualitative risk assessment |
The Security Practitioner An Introduction to Information Security |
|||||||||