Software Engineering Institute Carnegie Mellon

RSS  

Managing Information Security Risks: The OCTAVE Approach

Christopher Alberts
Audrey Dorofee

OCTAVE enables any organization to develop security priorities based on the organization's particular business concerns. This approach provides a coherent framework for aligning security actions with overall objectives. Managing Information Security Risks, written by the developers of OCTAVE, is the complete and authoritative guide to its principles and implementations. The book provides a systematic way to evaluate and manage information security risks, illustrates the implementation of self-directed evaluations, and shows how to tailor evaluation methods to different types of organizations.

More information about this book is available at InformIT, the online presence of the publisher Addison-Wesley Professional.

book cover

Additional Author Publications

Christopher Alberts
Audrey Dorofee
transparent transparent

 

Related SEI Program

Dynamic Systems

 

Related Projects

Mission Success in Complex Environments

 

Related Publications

Executive Overview of SEI MOSAIC: Managing for Success Using a Risk-Based Approach

Common Elements of Risk

Mission Assurance Analysis Protocol (MAAP): Assessing Risk in Complex Environments

Defining Incident Management Processes for CSIRTs: A Work in Progress

 

 

 

 

transparent transparenttransparent transparent