ABSTRACT

When properly conducted, risk analysis enlightens, informs, and illuminates, helping management organize their thinking into properly prioritized, cost-effective action. Poor analysis, on the other hand, usually results in vague programs with no clear direction and no metrics for measurement. Although there is plenty of information on risk analysis

chapter 3|30 pages

Risk Analysis Skills and Tools

chapter 5|16 pages

Asset Characterization and Identification

chapter 6|10 pages

Criticality and Consequence Analysis

chapter 7|30 pages

Threat Analysis

chapter 8|20 pages

Assessing Vulnerability

chapter 9|14 pages

Estimating Probability

chapter 10|18 pages

The Risk Analysis Process

chapter 11|12 pages

Prioritizing Risk

chapter 12|10 pages

Security Policy Introduction

chapter 13|20 pages

Security Policy and Countermeasure Goals

chapter 14|14 pages

Developing Effective Security Policies

chapter 15|16 pages

Countermeasure Goals and Strategies

chapter 16|42 pages

Types of Countermeasures

chapter 17|14 pages

Countermeasure Selection and Budgeting Tools

chapter 18|20 pages

Security Effectiveness Metrics

chapter 19|26 pages

Cost-Effectiveness Metrics

chapter 20|18 pages

Writing Effective Reports