-
作者Gary Stoneburner@NIST, Alice Goguen@NIST, Alexis Feringa@NIST
-
简介
Risk is a function of the likelihood of a given threat-source’s exercising a particular potential vulnerability, and the resulting impact of that adverse event on the organization. Risk is the net negative impact of the exercise of a vulnerability, considering both the probability and the impact of occurrence. Risk management is the process of identifying risk, assessing risk, and taking steps to reduce risk to an acceptable level. This guide provides a foundation for the development of an effective risk management program, containing both the definitions and the practical guidance necessary for assessing and mitigating risks identified within IT systems. The ultimate goal is to help organizations to better manage IT-related mission risks
The risk assessment methodology encompasses nine primary steps, which are described in Sections 3.1 through 3.9
- Step 1System Characterization (Section 3.1)
- Step 2Threat Identification (Section 3.2)
- Step 3Vulnerability Identification (Section 3.3)
- Step 4Control Analysis (Section 3.4)
- Step 5Likelihood Determination (Section 3.5)
- Step 6Impact Analysis (Section 3.6)
- Step 7Risk Determination (Section 3.7)
- Step 8Control Recommendations (Section 3.8)
- Step 9Results Documentation (Section 3.9)
-
提示本站仅做资料的整理和索引,转载引用请注明出处
相关推荐
-
2016-02-24 16:25:03
-
2016-03-24 14:54:42
-
2016-03-17 03:05:08
-
2016-03-16 04:16:40
附件下载
-
Risk.Management.Guide.for.Information.Technology.Systems.sp800.30.pdf