Proposing framework for comparative evaluation of information security risk assessment methods (Case of study: Iranian Research Institute for Information Science and Technology (IranDoc))

Document Type : Original Article


1 Assistant Professor,،Iranian Research Institute for Information Science and Technology (IranDoc)،Tehran, Iran

2 Ph.D.,Iranian Research Institute for Information Science and Technology (IranDoc)Tehran, Iran


One of the key actions in information security management is information security risk management, the main stage of which is known as "information security risk assessment". So far, various methods, standards and frameworks have been formed for this purpose. The main question that has been considered in this study is that despite this range of information security risk assessment methods, how should an organization choose and implement the appropriate method for its goals and situation. In order to answer this question, in this research, first, an evaluation framework consisting of 13 evaluation criteria was designed in two categories: the nature of the method and the adaptation of the method to the organizational situation. Then, based on this framework, 18 well-known information security risk assessment methods were evaluated in the organizational case of Iranian Research Institute for Information Science and Technology (IranDoc). The results of this evaluation showed that the proposed framework has the required validity. Based on these results, the ISO 27005 standard was recognized as the most appropriate method of information security risk assessment in the investigated case. At the end, based on these results and in line with further development and validation of the presented framework, suggestions were presented.


Volume 12, Issue 2 - Serial Number 46
number 46, summer 2023
September 2024
  • Receive Date: 04 March 2024
  • Revise Date: 20 July 2024
  • Accept Date: 08 August 2024
  • Publish Date: 31 August 2024