Managing risk exposure
Ray Stanton, Bill Rann · Computer Fraud & Security · 2006
Measuring and analysing risk comes naturally to IT security professionals. The expression ‘risk assessment’ has the comfortable ring of familiarity about it, since it forms the basis for any successful implementation of security measures. Ensuring that IT systems have a level of protection that is commensurate with the level, likelihood and consequence of any threat they face is an essential part of the security professional's role.