Metrics analysis of risk profile: A perspective on business aspects

Risk analysis is process to identify and develop profile of risk. Most risk analysis procedures focuses in technical perspectives, whereas business perspective is less involved. Business impacts are very important to be considered because it is related to business continuity of organization. Therefore, identification of business aspects is needed to be done so that aspects can be used as metrics in risk analysis of IT security threats. This paper proposes metrics of risk analysis in IT security threats based on business aspects. Methods for validating business aspects as metrics are literature analysis, linear regression analysis, correlation analysis and significancy analysis. The defined metrics will be used to develop risk analysis procedure in future work so it is expected to result better output in risk profile.