Abstract:
The article considers the issues of the risk management in the respective nodes of the SIEM-system for the organization goals in real time, for the recommendations of the information security in the enterprise information systems. Risk calculations are based on the objective assessments of the realization probability of adverse events, the predictions of damage value from security information violation. The recommendation offers to include the organization of effective choice of means on information resources security under financial restrictions for purchasing the means.
Keywords:risk assessment; information security; information resources; information system; adverse events; objective assessments; damages.