11.1 What is risk management?11.2 The CIA triad11.2.1 Confidentiality11.2.2 Integrity11.2.3 Availability11.3 Establishing the top threats to an organization11.4 Quantifying the impact of risks11.4.1 Finances11.4.2 Reputation11.4.3 Productivity11.5 Identifying threats and measuring vulnerability11.5.1 The STRIDE threat-modeling framework11.5.2 The DREAD threat-modeling framework11.6 Rapid risk assessment11.6.1 Gathering information11.6.2 Establishing a data dictionary11.6.3 Identifying and measuring risks11.6.4 Making recommendations11.7 Recording and tracking risks11.7.1 Accepting, rejecting, and delegating risks11.7.2 Revisiting risks regularlySummary