6 Administrative Data Gathering

Each of the next three chapters is dedicated to the topic (or security risk assessment phase) of data gathering. The topic of data gathering is a large one and encompasses many activities and security controls. In Chapter 5, the Review, Interview, Inspect, Observe, Test (RIIOT) data gathering method was introduced as a method of organizing, describing, and managing the data gathering effort. The RIIOT approach provides the organizational structure to discussions regarding the application of data gathering techniques for administrative, physical, and technical security controls. This large topic has been divided into three groups—administrative (Chapter 6), technical (Chapter 7), and physical (Chapter 8)—to facilitate ...

Get The Security Risk Assessment Handbook, 3rd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.