“…Risk management international standards range from general considerations and guidelines for risk management processes (e.g., ISO, 2009aISO, , 2009b, to specific guidelines for the IT sector (e.g., ISO, 2013ISO, , 2011Peltier, 2001), and to CI dependency analysis risk assessment methodologies (e.g., Aung and Watanabe, 2009;De Porcellinis et al, 2009;Haimes et al, 2007;Hokstad et al, 2013;ISO, 2009a;Ntouskas and Polemi, 2012;Theoharidou et al, 2011;Zio and Sansavini, 2011), all the way to sector specific frameworks as, for example, in the maritime sector (e.g., Ntouskas and Polemi, 2012;Polemi and Ntouskas, 2012). Most of these standards specify framework conditions for the risk management process, but do not provide specific methodologies targeted to SC risk assessment.…”