Home / annualized rate of occurrence aro / Effective Risk Analysis - NIST

Effective Risk Analysis - NIST - annualized rate of occurrence aro


Effective Risk Analysis - NIST-annualized rate of occurrence aro

Effective Risk Analysis
Thomas R. Peltier, CISSP
Driving eBusiness PerformanceSM
Abstract
Effective Risk Analysis
? The dictionary defines RISK as "someone or something that
creates or suggests a hazard". It is one of the many costs of
doing business or providing a service today.
? Information security professionals know and understand that
nothing ever runs smoothly for very long. Any manner of
internal or external hazard or risk can cause a well running
organization to lose competitive advantage, miss a deadline,
or suffer embarrassment. As security professionals,
management looks to us to provide a method that allows for
the systematic review of risk, threats, hazards and concerns
and provide cost-effective measures to lower risk to an
acceptable level. This session will review the current
practical application of cost-effective risk analysis.
8/1/00 Copyright?2000 Netigy Corporation. All Rights Reserved 2
Effective Risk Analysis
? Frequently Asked Questions
- Why should a risk analysis be conducted?
- When should a risk analysis be conducted?
- Who should conduct the risk analysis?
- How long should a risk analysis take?
- What can a risk analysis analyze?
- What can the results of a risk analysis tell an
organization?
- Who should review the results of a risk analysis?
- How is the success of the risk analysis measured?
8/1/00 Copyright?2000 Netigy Corporation. All Rights Reserved 3