A modular approach to computer security risk management
Robert P. Campbell, GERALD A. SANDS · 1979 International Workshop on Managing Requirements Knowledge (MARK) · 1979
Risk management is concerned with the identification, measurement, control and minimization of impact of uncertain events upon organizations that depend upon automated operations.11It is an analytical process with a large number of variables, many of which are unique to the environment under consideration. For this reason, there has not yet been developed within general state-of-the-art a single methodology broadly applicable to all risk management environments.1,10