Managing Information Security Risks The OCTAVE Approach

“Managing Information Security Risks: The OCTAVE Approach” by Christopher J. Alberts, published by Addison-Wesley Professional in 2003, is a comprehensive guide that introduces the OCTAVE method for evaluating information security risk. This edition spans 471 pages and is presented in English. The book outlines how organizations can assess their security practices and technology infrastructure to make informed decisions regarding potential impacts.
Readers will find a detailed exploration of the OCTAVE method, which stands for Operationally Critical Threat, Asset, and Vulnerability Evaluation. The text emphasizes a process-oriented approach to security risk evaluation, making it relevant for various sectors, including the financial industry and the DOD Medical Health System, which have shown interest in adopting this methodology. The authors, who are experts in managing security risks, provide insights into how organizations can effectively navigate the complexities of information management and technology.
Official synopsis Publisher
From the CERT Coordination Center at the SEI, this book describes OCTAVE, a new method of evaluating information security risk.@BULLET = This book is from the CERT Coordination Center and Networked Systems Survivability (NSS) group at the SEI, the Software Engineering Institute at Carnegie Mellon University. @BULLET = There is growing interest in OCTAVE. The DOD Medical Health System is one early adopter and there is also keen interest from the financial sector. @BULLET = The authors are the lead developers of the OCTAVE method and are experts in helping organizations manage their own security risks.@SUMMARY = This is a descriptive and process-oriented book on a new security risk evaluation method, OCTAVE. OCTAVE stands for Operationally Critical Threat, Asset, and Vulnerability Evaluation (SM). An information security risk evaluation helps organizations evaluate organizational practice as well as the installed technology base and to make decisions based on potential impact.@AUTHBIO = Christopher Alberts is a senior member of the technical staff in the Networked Systems Survivability Program (NSS) at the SEI, CERT Coordination Center. He is team leader for security evaluations and OCTAVE. Christopher is responsible for developing information security risk management methods, tools, and techniques. Audrey Dorofee is a senior member of the technical staff in the Survivable Network Management Project in the NSS Program at SEI, CERT Coordination Center. CERT is the original computer security incident response center and is internationally recognized as a leading authoritative organization in this area.
Publisher
Topics
FAQ
What is “Managing Information Security Risks The OCTAVE Approach” about?
Who is the author of “Managing Information Security Risks The OCTAVE Approach”?
When was “Managing Information Security Risks The OCTAVE Approach” published?
What is the ISBN for “Managing Information Security Risks The OCTAVE Approach”?
What are the book details (language, pages, edition)?
