Transcription of Introducing OCTAVE Allegro: Improving the Information ...
{{id}} {{{paragraph}}}
Introducing OCTAVE Allegro: Improving the Information Security Risk Assessment Process Richard A. Caralli James F. Stevens Lisa R. Young William R. Wilson May 2007 TECHNICAL REPORT CMU/SEI-2007-TR-012 ESC-TR-2007-012 CERT Program This report was prepared for the SEI Administrative Agent ESC/XPK 5 Eglin Street Hanscom AFB, MA 01731-2100 The ideas and findings in this report should not be construed as an official DoD position. It is published in the interest of scientific and technical Information exchange. This work is sponsored by the Department of Defense.
3 Introducing OCTAVE Allegro 17 3.1 OCTAVE Allegro Methodology 17 3.1.1 Step 1 - Establish Risk Measurement Criteria 17 3.1.2 Step 2 - Develop an Information Asset Profile 18 3.1.3 Step 3 - Identify Information Asset Containers 18 3.1.4 Step 4 - Identify Areas of Concern 18 3.1.5 Step 5 - Identify Threat Scenarios 19
Domain:
Source:
Link to this page:
Please notify us if you found a problem with this document:
{{id}} {{{paragraph}}}