Reusing Risk Analysis Results -- An Extension for the CORAS Risk Analysis Method

This paper shows how the results of CORAS risk analysis can be reused and combined. It introduces new models, diagram types and procedures as an extension of the CORAS method. Taking risk analysis artifacts generated for the individual base components as input, probability values for unwanted incidents of complex systems can be calculated if the relations between these artifacts are modeled correctly. Initially developed for the S Network, a trustworthy repository, this extension is predestined for analyzing large scale systems consisting of heterogeneous components, which no single analyst team could handle.