
Risk Management ◾ 53
You will want to agree on the definitions of the business attributes to be used
as these will become your review elements. For many risk assessments, we have
examined integrity, confidentiality, and availability. Recently, a group of my fel-
low information security professionals and I examined the idea of which attri-
butes should be examined. For years, we concentrated on examining the threats
associated with the security triad on confidentiality, integrity, and availability
(CIA).
Although CIA is a traditional form of risk assessment, it is important to under-
stand that there are other business attributes that can be used ...