IA OM® as an Enterprise Risk Management Metric
David R., W. Wendy · InTech eBooks · 2012
Security Risk Management Systems. 4 The definition of risk provided by the NIST is: "A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically a function of: (i) the adverse impacts that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence.[Note: Information system-related security risks are those risks that arise from the loss of confidentiality, integrity, or availability of information or information systems and reflect the potential adverse impacts to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation]" [17].