International Journal on Advances in Security, vol 11 no 1 & 2, year 2018, http://www.iariajournals.org/security/ 91 RMDM – Further Verification of the Conceptual ICT Risk-Meta-Data-Model Verified with the underlying Risk Models of COBIT for Risk and COSO ERM 2017 Martin Latzenhofer 1 2 Gerald Quirchmayr 2 1 Center for Digital Safety & Security 2 Multimedia Information Systems Research Group Austrian Institute of Technology Faculty of Computer Science, University of Vienna Vienna, Austria Vienna, Austria email:
[email protected] email:
[email protected] Abstract— The aim of this article is to introduce an approach to initialize and re-establish the risk management that integrates the different models and methods currently frameworks and related processes each time. It is evident that applied for risk management in information and these parameters result in a smaller degree of reusability of a communication technologies (ICT). These different risk given risk management process and less comparability of the management approaches are usually bound to the organization information obtained from it. where they are applied, thus staying quite specific for a given When interpreting this problem as a pure ICT issue, an setting. Consequently, there is no possibility to compare or explicit ICT solution is required. This leads to the main reuse risk management structures because they are individual research question of this paper, i.e., whether it is possible to solutions. In order to establish a common basis for working develop a common risk management model, which is with different underlying risk models, a metamodeling approach from the area of disaster recovery is used.