Abstract
Though it is apparent that some of information security risks are caused from contractor side incidents, inter-organizational risk assessment is often difficult. This paper proposes a risk evaluation method named "Interface Response Method" which can analyze, without disclosure of detailed information from those participants, such cases where multiple organizations are cooperating. Specifically, it is a mathematical algorithm which focuses only on the events occurred at boundaries among organizations and extract enough information from them. This method is an application of Qualitative Sensitivity Analysis proposed in our previous work.