ABSTRACT

For the purposes of this book, the information security risk assessment process is de‹ned as follows:

Security Risk Assessment-An objective analysis of the e¤ectiveness of the current security controls that protect an organization’s assets and a determination of the probability of losses to those assets.