<?xml version="1.0" encoding="UTF-8"?><xml><records><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>27</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Venelin Georgiev</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">A Two-Level Model for Describing the Risk Profile in Formulating Policy and Developing Security Capabilities</style></title><secondary-title><style face="normal" font="default" size="100%">IT4Sec Reports</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">context</style></keyword><keyword><style  face="normal" font="default" size="100%">Risk</style></keyword><keyword><style  face="normal" font="default" size="100%">risk management</style></keyword><keyword><style  face="normal" font="default" size="100%">risk profile assessment</style></keyword><keyword><style  face="normal" font="default" size="100%">scenario</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2015</style></year><pub-dates><date><style  face="normal" font="default" size="100%">June 2015</style></date></pub-dates></dates><number><style face="normal" font="default" size="100%">129</style></number><publisher><style face="normal" font="default" size="100%">Institute of Information and Communication Technologies</style></publisher><pub-location><style face="normal" font="default" size="100%">Sofia</style></pub-location><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">The risk assessment/management concept is widely used in security research due to its universality, but also because of the active nature and sense of precautionary management, implemented on its basis. The security risk profile can be described and studied at different levels of security, which poses the question how researchers should choose the appropriate model for identifying, evaluating and developing strategies to mitigate the risk. The article raises the question whether the use risk profiles for the purposes of policy formulation, at one level of security, and capacity building at another, can introduce errors in decision making. As a possible tool to eliminate such errors the author proposes the use of a two-stage model for the description and study of the risk profile, which includes a contextual and a specific level of the discourse.</style></abstract></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Todor Tagarev</style></author><author><style face="normal" font="default" size="100%">Venelin Georgiev</style></author><author><style face="normal" font="default" size="100%">Valeri Ratchev</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">A Taxonomy of Essential Services</style></title><secondary-title><style face="normal" font="default" size="100%">Radioelectronic and Computer Systems</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">Comprehensive approach</style></keyword><keyword><style  face="normal" font="default" size="100%">Critical Infrastructure</style></keyword><keyword><style  face="normal" font="default" size="100%">Planning</style></keyword><keyword><style  face="normal" font="default" size="100%">risk management</style></keyword><keyword><style  face="normal" font="default" size="100%">security policy</style></keyword><keyword><style  face="normal" font="default" size="100%">threats</style></keyword><keyword><style  face="normal" font="default" size="100%">Uncertainty</style></keyword><keyword><style  face="normal" font="default" size="100%">Vulnerabilities</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2012</style></year><pub-dates><date><style  face="normal" font="default" size="100%">May 2012</style></date></pub-dates></dates><publisher><style face="normal" font="default" size="100%">Radioelectronic and Computer Systems 6(58)</style></publisher><pub-location><style face="normal" font="default" size="100%">Sevastopol, Ukraine</style></pub-location><pages><style face="normal" font="default" size="100%">191-196</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">Communities, countries and alliances cannot be efficient in preparing to meet diverse threats to their security within traditional organizational stovepipes. The boundaries between ‘internal’ and ‘external’ threats are getting fuzzier, and the vulnerabilities of governments, businesses and communities feed on each other, while the comprehensive approach is gaining traction in ever more security fields. The implementation of the comprehensive approach poses a number of methodological challenges. While it clearly requires coordination of various capabilities of a multitude of actors, it is less apparent which is the suitable organising concept. This paper takes as a starting point the concept of ‘essential services’ and suggests a taxonomy, that would allow to treat threats, vulnerabilities and risk in a common comprehensive framework. The taxonomy has been developed with a specific purpose in mind, and thus refers to European Essential Services (EES). We nevertheless reason that it can be replicated to support decision making at other levels, e.g. in national security policy making and planning. </style></abstract><issue><style face="normal" font="default" size="100%">58</style></issue></record></records></xml>