Risk Assessment for Dummies
Steve Mash · Computer Fraud & Security · 2002
Undertaking a complete risk assessment of the information held within an organization is not trivial, particularly if compliance to a standard such as ISO 17799 is sought. For some companies, particularly in the small-to-medium enterprise (SME) range, there may be no appropriately skilled employees and the costs of hiring a consultant may be see as prohibitive. Yet the risks to which these companies are exposed are just as real and potentially destructive as those faced by larger organizations. This dilemma can be solved by applying an off-the-shelf cost effective product that will enable anyone, irrespective of any security knowledge, to identify and address the risks and vulnerabilities