Information Security Risk Assessment: Practices of Leading Organizations: a Supplement to GAO's May 1998 Executive Guide to Information Security Management.

Abstract

This guide is intended to help federal managers implement an ongoing information security risk assessment process by providing examples, or case studies, of practical risk assessment procedures that have been successfully adopted by four organizations known for their efforts to implement good risk assessment practices. More importantly, it identifies, based on the case studies, factors that are important to the success of any risk assessment program, regardless of the specific methodology employed.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Nov 01, 1999
Accession Number
ADA396615

Entities

Organizations

  • United States Government Accountability Office

Tags

Communities of Interest

  • Cyber

DTIC Thesaurus Topics

  • Authentication
  • Business Administration
  • Case Studies
  • Computer Access Control
  • Computers
  • Electronic Mail
  • Geographic Regions
  • Information Operations
  • Information Security
  • Information Systems
  • Risk
  • Risk Analysis
  • Risk Management
  • Security
  • Systems Engineering
  • Unauthorized Disclosure
  • Vulnerability

Fields of Study

  • Computer science

Readers

  • Defense Acquisition Program Management