Introduction to Security Risk Assessment and Management

David L. Russell, Pieter C. Arlow · 2015

Security risk analysis is fundamental to the security of any organization. It is essential in ensuring that controls and expenditure are fully commensurate with the risks to which the organization is exposed. The basic framework for risk management is a cost-associated function where the general sequence starts with identification of the assets at risk, evaluation of the likelihood of their occurrence, development of a cost and a probability associated with the occurrence of an event, and estimation of the costs to reduce the risk. Fundamental to the understanding of risk are the concepts of vulnerabilities, assets, and threats. This chapter discusses some of the theories around risk management and develops a threat scenario, and then presents the risk management analysis. It describes the several methods used for pairing vulnerability and threat data. It also illustrates how the four types of controls that are critical countermeasures for vulnerabilities work.

Read the paper · More papers on PaperTik