ABSTRACT

There are a number of ways to identify, analyze, and assess risk, and there is considerable discussion of “risk” in the media and among information security professionals. But, there is little real understanding of the process and metrics of analyzing and assessing risk. Certainly everyone understands that “taking a risk” means “taking a chance,” but a risk or chance of what is often not so clear.