Chapter 35: Risk Management

Sokratis K. Katsikas     Norwegian University of Science and Technology, Gjøvik, Norway

Abstract

Risk management is central to information and cyber security, as it essentially drives all processes and decisions within any security development program. In this chapter, we discuss the concept of risk, how risk is measured, we analyze risk management as a methodology, we briefly present some widely used risk management methods and relevant standards.

Keywords

Risk management; Standards

1. Introduction

Integrating security measures with the operational framework of an organization is neither a trivial nor an easy task. This explains to a large extent the low degree of security that information systems operating in contemporary ...

Get Computer and Information Security Handbook, 4th Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.