Government agencies and companies can have their information security management system (ISMS) certified based on different standards. It should be noted that the scope and coverage of the applied standards may differ. For example, the scope of a certification based on the IT-Grundschutz published by the German Federal Office for Information Security (BSI) may focus on the core processes of the company, whereas ISO/IEC 27001 considers the complete structures.
The ISMS-standards require a risk analysis, although the described procedure and the focus of the content are different. Financial and human resources for authorities and companies should be minimized for the maintenance of the ISMS and IRM. Procedures, frameworks and processes should be created for everyone to standardize the ISMS and IRM.
The aim of this master thesis is to find or define normatively valid methods and processes for a unified information risk management (IRM) of both areas of application that can be measured based on economic criteria.
For the further evaluation of the artifact or research, a generally applicable process for the standardization of the IRM for several scopes of application should be created.