Risk Assessment Quantification for Bring Your Own Device Based on Practical Viewpoints

  • Teruo Endo Osaka Shoin Women’s University
  • Shigeaki Tanimoto Chiba Institute of Technology
  • Motoi Iwashita Chiba Institute of Technology
  • Toru Kobayashi Nagasaki University
  • Hiroyuki Sato The University of Tokyo
  • Atsushi Kanai Hosei University
Keywords: BYOD, Risk Assessment, Risk Breakdown Structure, Risk Matrix, Risk Value


In recent years, the companies which introduce Bring Your Own Device (BYOD) which utilizes a personal smart phone and tablet for business are increasing in number. However, there are risks, such as information leakage of business information, an employee's personal information, etc., for the private terminal utilization instead of business use. These risks were exhaustively identified in our previous study, but based on qualitative assessment results. In order to make risk countermeasures more realistic, further quantitative evaluation is needed. Therefore, in this paper, we have added new cost risk factors for BYOD from a practical viewpoint to the risk analysis results of previous study. Furthermore, based on the results, a quantitative evaluation was conducted to verify its effectiveness. For the evaluation, the risk factor values were estimated using a risk calculation formula used in the field of information security management systems (ISMS). Thus, the combined effect of the BYOD risk measures proposed in the previous study and the cost risk measures added in this study clarified that it was possible to reduce the risk by about 56%. The results of this quantitative risk assessment are expected to help make the future use of BYOD safer and secure for companies.


