%0 Conference Proceedings %T Mapping between Classical Risk Management and Game Theoretical Approaches %+ Gjøvik University College (GUC) %A Rajbhandari, Lisa %A Snekkenes, Einar, Arthur %Z Part 2: Work in Progress %< avec comité de lecture %( Lecture Notes in Computer Science %B 12th Communications and Multimedia Security (CMS) %C Ghent, Belgium %Y Bart Decker %Y Jorn Lapon %Y Vincent Naessens %Y Andreas Uhl %I Springer %3 Communications and Multimedia Security %V LNCS-7025 %P 147-154 %8 2011-10-19 %D 2011 %R 10.1007/978-3-642-24712-5_12 %K Game theory %K Risk management %K Equilibrium %K Strategies %Z Computer Science [cs] %Z Computer Science [cs]/Networking and Internet Architecture [cs.NI]Conference papers %X In a typical classical risk assessment approach, the probabilities are usually guessed and not much guidance is provided on how to get the probabilities right. When coming up with probabilities, people are generally not well calibrated. History may not always be a very good teacher. Hence, in this paper, we explain how game theory can be integrated into classical risk management. Game theory puts emphasis on collecting representative data on how stakeholders assess the values of the outcomes of incidents rather than collecting the likelihood or probability of incident scenarios for future events that may not be stochastic. We describe how it can be mapped and utilized for risk management by relating a game theoretically inspired risk management process to ISO/IEC 27005. This shows how all the steps of classical risk management can be mapped to steps in the game theoretical model, however, some of the game theoretical steps at best have a very limited existence in ISO/IEC 27005. %G English %Z TC 6 %Z TC 11 %2 https://inria.hal.science/hal-01596184/document %2 https://inria.hal.science/hal-01596184/file/978-3-642-24712-5_12_Chapter.pdf %L hal-01596184 %U https://inria.hal.science/hal-01596184 %~ IFIP-LNCS %~ IFIP %~ IFIP-TC %~ IFIP-TC11 %~ IFIP-TC6 %~ IFIP-CMS %~ IFIP-LNCS-7025