In this paper, we present and discuss a framework for security risk management, focusing on the selection of a management strategy for decision-making on security measures in particular. The framework provides guidance on the selection of a suitable type of management strategy for various types of decision-making contexts. An Information and Communication Technology case study is used to illustrate the practical implications of the framework.
Abrahamsen, Eirik Bjorheim; Kenneth Pettersen; Terje Aven; Mareile Kaufmann & Tony Rosqvist (2015) A framework for selection of strategy for management of security measures, Journal of Risk Research 20 (3): 404–417.