%0 Conference Proceedings %T Risk Reduction Overview %+ Rijkswaterstaat [Delft] %+ Ministry of Defense [The Hague] %A Havinga, Hellen, Janine %A Sessink, Olivier, Theobald %Z Part 2: 4th International Workshop on Security and Cognitive Informatics for Homeland Defense (SeCIHD 2014) %< avec comité de lecture %( Lecture Notes in Computer Science %B International Cross-Domain Conference and Workshop on Availability, Reliability, and Security (CD-ARES) %C Fribourg, Switzerland %Y Stephanie Teufel %Y Tjoa A Min %Y Ilsun You %Y Edgar Weippl %I Springer %3 Availability, Reliability, and Security in Information Systems %V LNCS-8708 %P 239-249 %8 2014-09-08 %D 2014 %R 10.1007/978-3-319-10975-6_18 %K Design %K Security %K Residual risk %K Risk management %K Security measure %K Visualization %Z Computer Science [cs] %Z Humanities and Social Sciences/Library and information sciencesConference papers %X The Risk Reduction Overview (RRO) method presents a comprehensible overview of the coherence of risks, measures and residual risks. The method is designed to support communication between different stakeholders in complex risk management. Seven reasons are addressed why risk management in IT security has many uncertainties and fast changing factors, four for IT security in general and three for large organizations specifically. The RRO visualization has been proven valuable to discuss, optimize, evaluate, and audit a design or a change in a complex environment. The method has been used, evaluated, and improved over the last six years in large government and military organizations. Seven areas in design and decision making are identified in which a RRO is found to be beneficial. Despite the widely accepted need for risk management we believe this is the first practical method that delivers a comprehensive overview that improves communication between different stakeholders. %G English %Z TC 5 %Z TC 8 %Z WG 8.4 %Z WG 8.9 %2 https://inria.hal.science/hal-01403999/document %2 https://inria.hal.science/hal-01403999/file/978-3-319-10975-6_18_Chapter.pdf %L hal-01403999 %U https://inria.hal.science/hal-01403999 %~ SHS %~ IFIP-LNCS %~ IFIP %~ IFIP-TC %~ IFIP-TC5 %~ IFIP-WG %~ IFIP-TC8 %~ IFIP-LNCS-8708 %~ IFIP-CD-ARES %~ IFIP-WG8-4 %~ IFIP-WG8-9