
Information Security Risk Analysis, Second Edition
Thomas R. Peltier(Author)
Auerbach (Publisher)
2nd Edition
Published on 26. April 2005
Book
Hardback
360 pages
978-0-8493-3346-0 (ISBN)
Article exhausted; check for reprint
Description
The risk management process supports executive decision-making, allowing managers and owners to perform their fiduciary responsibility of protecting the assets of their enterprises. This crucial process should not be a long, drawn-out affair. To be effective, it must be done quickly and efficiently.
Information Security Risk Analysis, Second Edition enables CIOs, CSOs, and MIS managers to understand when, why, and how risk assessments and analyses can be conducted effectively. This book discusses the principle of risk management and its three key elements: risk analysis, risk assessment, and vulnerability assessment. It examines the differences between quantitative and qualitative risk assessment, and details how various types of qualitative risk assessment can be applied to the assessment process. The text offers a thorough discussion of recent changes to FRAAP and the need to develop a pre-screening method for risk assessment and business impact analysis.
Information Security Risk Analysis, Second Edition enables CIOs, CSOs, and MIS managers to understand when, why, and how risk assessments and analyses can be conducted effectively. This book discusses the principle of risk management and its three key elements: risk analysis, risk assessment, and vulnerability assessment. It examines the differences between quantitative and qualitative risk assessment, and details how various types of qualitative risk assessment can be applied to the assessment process. The text offers a thorough discussion of recent changes to FRAAP and the need to develop a pre-screening method for risk assessment and business impact analysis.
More details
Edition
2nd New edition
Language
English
Place of publication
London
United Kingdom
Publishing group
Taylor & Francis Ltd
Target group
Professional and scholarly
CIOs, MIS managers, infosec management and administrators, business continuity planners, systems admins, network managers and administrators, facility security management and staff
Edition type
New edition
Illustrations
109 s/w Tabellen, 20 s/w Abbildungen
109 Tables, black and white; 20 Illustrations, black and white
Dimensions
Height: 235 mm
Width: 156 mm
Weight
658 gr
ISBN-13
978-0-8493-3346-0 (9780849333460)
Copyright in bibliographic data and cover images is held by Nielsen Book Services Limited or by the publishers or by their respective licensors: all rights reserved.
Schweitzer Classification
Other editions
New editions

Thomas R. Peltier
Information Security Risk Analysis
Book
03/2010
3rd Edition
Taylor & Francis
€187.60
Shipment within 15-20 days
Previous edition
Thomas R. Peltier
Information Security Risk Analysis
Book
01/2001
1st Edition
CRC Press
€56.94
Article exhausted; check for reprint
Person
Content
INTRODUCTION
Frequently asked questions
Conclusion
RISK MANAGEMENT
Overview
Risk Management as Part of the Business Process
Employee Roles and Responsibilities
Information Security Life Cycle
Risk Analysis Process
Risk Assessment
Cost-Benefit Analysis
Risk Mitigation
Final Thoughts
RISK ASSESSMENT PROCESS
Introduction
Risk Assessment Process
Information Is an Asset
Risk Assessment Methodology
Final Thoughts
QUANTITATIVE VERSUS QUALITATIVE RISK
ASSESSMENT
Introduction
Quantitative and Qualitative Pros and Cons
Qualitative Risk Assessment Basics
Qualitative Risk Assessment Using Tables
The 30-Minute Risk Assessment
Conclusion
OTHER FORMS OF QUALITATIVE RISK ASSESSMENT
Introduction
Hazard Impact Analysis
Questionnaires
Single Time Loss Algorithm
Conclusion
FACILITATED RISK ANALYSIS AND ASSESSMENT
PROCESS (FRAAP)
Introduction
FRAAP Overview
Why The FRAAP Was Created
Introducing the FRAAP to Your Organization
Conclusion
VARIATIONS ON THE FRAAP
Overview
Infrastructure FRAAP
Conclusion
MAPPING CONTROLS
Controls Overview
Creating Your Controls List
Control List Examples
BUSINESS IMPACT ANALYSIS (BIA)
Overview
Creating a BIA Process
CONCLUSION
Appendix A: Sample Risk Assessment Management Summary Report
Appendix B: Terms and Definitions
Appendix C: Bibliography
Frequently asked questions
Conclusion
RISK MANAGEMENT
Overview
Risk Management as Part of the Business Process
Employee Roles and Responsibilities
Information Security Life Cycle
Risk Analysis Process
Risk Assessment
Cost-Benefit Analysis
Risk Mitigation
Final Thoughts
RISK ASSESSMENT PROCESS
Introduction
Risk Assessment Process
Information Is an Asset
Risk Assessment Methodology
Final Thoughts
QUANTITATIVE VERSUS QUALITATIVE RISK
ASSESSMENT
Introduction
Quantitative and Qualitative Pros and Cons
Qualitative Risk Assessment Basics
Qualitative Risk Assessment Using Tables
The 30-Minute Risk Assessment
Conclusion
OTHER FORMS OF QUALITATIVE RISK ASSESSMENT
Introduction
Hazard Impact Analysis
Questionnaires
Single Time Loss Algorithm
Conclusion
FACILITATED RISK ANALYSIS AND ASSESSMENT
PROCESS (FRAAP)
Introduction
FRAAP Overview
Why The FRAAP Was Created
Introducing the FRAAP to Your Organization
Conclusion
VARIATIONS ON THE FRAAP
Overview
Infrastructure FRAAP
Conclusion
MAPPING CONTROLS
Controls Overview
Creating Your Controls List
Control List Examples
BUSINESS IMPACT ANALYSIS (BIA)
Overview
Creating a BIA Process
CONCLUSION
Appendix A: Sample Risk Assessment Management Summary Report
Appendix B: Terms and Definitions
Appendix C: Bibliography