- Discusses all types of corporate risks and practical means of defending against them.
- Security is currently identified as a critical area of Information Technology management by a majority of government, commercial, and industrial organizations.
- Offers an effective risk management program, which is the most critical function of an information security program.
Preface xiii
About the Authors xv
Part I Industry Practices in Risk Management 1
1. Information Security Risk Management Imperatives and Opportunities 3
1.1 Risk Management Purpose and Scope 3
1.1.1 Purpose of Risk Management 3
1.1.2 Text Scope 17
References 24
Appendix 1A: Bibliography of Related Literature 25
2. Information Security Risk Management Defined 33
2.1 Key Risk Management Definitions 33
2.1.1 Survey of Industry Definitions 33
2.1.2 Adopted Definitions 37
2.2 A Mathematical Formulation of Risk 40
2.2.1 What is Risk? A Formal Definition 44
2.2.2 Risk in IT Environments 44
2.2.3 Risk Management Procedures 49
2.3 Typical Threats/Risk Events 56
2.4 What is an Enterprise Architecture? 61
References 65
Appendix 2A: The CISSPforum/ISO27k Implementers Forum Information Security Risk List for 2008 66
Appendix 2B: What is Enterprise Risk Management (ERM)? 71
3. Information Security Risk Management Standards 73
3.1 ISO/IEC 13335 77
3.2 ISO/IEC 17799 (ISO/IEC 27002:2005) 78
3.3l3