Information Security Risk Assessment Exploration and Practice

Author: Zhang Jianzhuang, Meng Yaping
Publisher:
Publish Date: 2005-06-01
Features: Risk assessment should be centered on the organization, studying the relationship between organizational goals and information security. Starting from the goal of meeting organizational objectives, this book conducts research on the objectives, methods, and engineering implementation of information security risk assessment, which becomes the main line the entire book. The book mainly includes several parts: the conceptual level (what is risk assessment), the methodological level (what risk assessment does), and the operational level (how to conduct risk assessment). At the same time, at the end of the book, it explains practical activities related to preliminary explorations of risk analysis methods, raises the issue of whether universally applicable risk assessment methods need to meet horizontal and vertical comparison requirements, and discusses factors for evaluating risk assessment methods (such as efficiency, observability, and repeatability) for further exploration and reflection. This book can serve as a reference for leaders and decision-makers in organizational informatization-related fields, as well as for those who wish to engage in information security risk assessment services.

📌 Related Posts