Threat assessment and risk analysis
Martin Lloyd Smith · Computer Fraud & Security Bulletin · 1991
A computer security policy must be based above all else on a sound and accurate assessment of the threats against the computer system and its host organization, together with a proper and sensible analysis of the risks. There is no simple way to avoid this initial effort, and the quality of all subsequent work depends on it.