
Assessing and Managing Security Risk in IT Systems
A Structured Methodology
John McCumber(Author)
Auerbach (Publisher)
1st Edition
Published on 12. August 2004
Book
Hardback
288 pages
978-0-8493-2232-7 (ISBN)
Description
Assessing and Managing Security Risk in IT Systems: A Structured Methodology builds upon the original McCumber Cube model to offer proven processes that do not change, even as technology evolves. This book enables you to assess the security attributes of any information system and implement vastly improved security environments.
Part I delivers an overview of information systems security, providing historical perspectives and explaining how to determine the value of information. This section offers the basic underpinnings of information security and concludes with an overview of the risk management process.
Part II describes the McCumber Cube, providing the original paper from 1991 and detailing ways to accurately map information flow in computer and telecom systems. It also explains how to apply the methodology to individual system components and subsystems.
Part III serves as a resource for analysts and security practitioners who want access to more detailed information on technical vulnerabilities and risk assessment analytics. McCumber details how information extracted from this resource can be applied to his assessment processes.
Part I delivers an overview of information systems security, providing historical perspectives and explaining how to determine the value of information. This section offers the basic underpinnings of information security and concludes with an overview of the risk management process.
Part II describes the McCumber Cube, providing the original paper from 1991 and detailing ways to accurately map information flow in computer and telecom systems. It also explains how to apply the methodology to individual system components and subsystems.
Part III serves as a resource for analysts and security practitioners who want access to more detailed information on technical vulnerabilities and risk assessment analytics. McCumber details how information extracted from this resource can be applied to his assessment processes.
More details
Language
English
Place of publication
London
United Kingdom
Publishing group
Taylor & Francis Ltd
Target group
Professional and scholarly
Academic and Professional Practice & Development
Product notice
sewn/stitched
Cloth over boards
Illustrations
35 s/w Abbildungen, 16 s/w Tabellen
16 Tables, black and white; 35 Illustrations, black and white
Dimensions
Height: 242 mm
Width: 160 mm
Thickness: 21 mm
Weight
540 gr
ISBN-13
978-0-8493-2232-7 (9780849322327)
Copyright in bibliographic data and cover images is held by Nielsen Book Services Limited or by the publishers or by their respective licensors: all rights reserved.
Schweitzer Classification
Other editions
Additional editions

E-Book
08/2004
Auerbach
€101.99
Available for download

E-Book
08/2004
Auerbach
€101.99
Available for download
Person
John McCumber
Content
SECURITY CONCEPTS. Using models. Defining information security. Information as an asset. Understanding threat and its relation to vulnerabilities. Assessing risk variables: The risk assessment process. THE MCCUMBER CUBE METHODOLOGY. The McCumber Cube. Determining information states and mapping information flow. Decomposing the cube for security enforcement. Information state analysis for components and subsystems. Managing the security life cycle. Safeguard analysis. Practical applications of McCumber Cube Analysis. APPENDICES.