Assessing and managing security risk in IT systems a structured methodology

Assessing and Managing Security Risk in IT Systems: A Structured Methodology builds upon the original McCumber Cube model to offer proven processes that do not change, even as technology evolves. This book enables you to assess the security attributes of any information system and implement vastly i...

Descripción completa

Detalles Bibliográficos
Autor principal: McCumber, John, 1956- (-)
Formato: Libro electrónico
Idioma:Inglés
Publicado: Boca Raton, FL : Auerbach Publications 2005.
Edición:1st edition
Materias:
Ver en Biblioteca Universitat Ramon Llull:https://discovery.url.edu/permalink/34CSUC_URL/1im36ta/alma991009627171806719
Tabla de Contenidos:
  • BOOK COVER; HALF-TITLE; SERIES; TITLE; COPYRIGHT; DEDICATION; CONTENTS; FOREWORD; INTRODUCTION; I SECURITY CONCEPTS; 1 USING MODELS; 2 DEFINING INFORMATION SECURITY; 3 INFORMATION AS AN ASSET; 4 UNDERSTANDING THREAT AND ITS RELATION TO VULNERABILITIES; 5 ASSESSING RISK VARIABLES: THE RISK ASSESSMENT PROCESS; II THE McCUMBER CUBE METHODOLOGY; 6 THE McCUMBER CUBE; 7 DETERMINING INFORMATION STATES AND MAPPING INFORMATION FLOW; 8 DECOMPOSING THE CUBE FOR SECURITY ENFORCEMENT; 9 INFORMATION STATE ANALYSIS FOR COMPONENTS AND SUBSYSTEMS; 10 MANAGING THE SECURITY LIFE CYCLE; 11 SAFEGUARD ANALYSIS
  • 12 PRACTICAL APPLICATIONS OF McCUMBER CUBE ANALYSISIII APPENDICES; Appendix A VULNERABILITIES; Appendix B RISK ASSESSMENT METRICS; Appendix C DIAGRAMS AND TABLES; Appendix D OTHER RESOURCES; INDEX