SYSTEMATIC ANALYSIS OF RISK ASSESSMENT METHODS AND MODELS IN INFORMATION SECURITY
DOI:
https://doi.org/10.54309/IJICT.2026.25.1.016Keywords:
информационная безопасность, оценка рисков, угрозы, уязвимости, SIEM, OpenVAS, ISO/IEC 27005Abstract
This article comprehensively examines the methods and models of risk assessment in the field of information security. The topic of the study is relevant in the context of modern digital infrastructure, as cyber threats are increasing day by day. The purpose of the work is to systematize the main approaches to assessing information security risks and demonstrate their practical application. The study describes qualitative and quantitative methods, as well as international models such as FAIR, OCTAVE, NIST SP 800-30. In addition, the possibility of automatic risk assessment using tools such as OpenVAS, Metasploit, RiskWatch is demonstrated. Specific technical approaches are presented using scripts written in Python and monitoring systems (Zabbix, SIEM). As a result, the authors justify the need to integrate risk assessment methods into organizational processes in order to form effective management and security strategies. The conclusion notes that artificial intelligence and machine learning technologies will play an important role in this area in the future.
Downloads
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 INTERNATIONAL JOURNAL OF INFORMATION AND COMMUNICATION TECHNOLOGIES

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
https://creativecommons.org/licenses/by-nc-nd/3.0/deed.en