Attachment is the great fabricator of illusions; reality can be attained only by someone who is detached.
Simone Weil, 1909–1943
Risk analysis is a much discussed area in the information security field for several reasons. First, risk analysis is core to understanding the state of information security that exists within the company. The process of risk analysis uncovers how well the control environment is protecting the information assets. Second, risk analysis helps organizations target the information security expenditures where they are most needed and are used to allocate funds to the appropriate security controls. Finally, risk analysis and management is very subjective in nature and tends to ...