Access "The real information security risk equation"
This article is part of the May 2010 issue of How to watch over your data with effective database activity monitoring
Risk management is a fundamental requirement of information security. Without it, the safety of the information or system cannot be assured. In information security, risk is a variable that must be understood in order to best create cost-effective solutions to minimize negative risks with minimal impact to usability and cost. Risks are often uncertain, misunderstood, and can change based on circumstances. Risk management provides a way for you to understand and handle risks that are optimal for security, IT, and the business. It creates a common language to identify, assess, and understand potential threats and vulnerabilities while identifying means for mitigating, accepting, or avoiding the risk. However, one of the reasons we have difficulty in translating risks to our users is that many security practitioners maintain an unrealistic view of risk because we use an overly complex risk equation. It typically contains variables for threats, vulnerabilities, and mitigation. This isn't how people naturally think. Security guru Bruce Schneier described this ... Access >>>
Access TechTarget
Premium Content for Free.
What's Inside
Features
-
-
Database activity monitoring keeps watch over your data
by Adrian Lane, Contributor
Database activity monitoring can help with security and compliance by tracking everything going on in the database.
-
OWASP Top 10 vulnerabilities list adds risk to equation
OWASP Top 10 vulnerabilities list adds risk to methodology used to categorize coding errors.
-
Database activity monitoring keeps watch over your data
by Adrian Lane, Contributor
-
-
Microsoft Windows 7 security features
by Beth Quinlan
Microsoft Windows 7 security aims to improve security without the headaches of Vista.
-
The banking malware scourge
Criminals are using the Zeus banking Trojan and other malware to hijack online business banking accounts.
-
Microsoft Windows 7 security features
by Beth Quinlan
-
Columns
-
Four steps toward a plan for a career in information security
by Lee Kushner and Mike Murray
Having a long-term goal for a career in information security isn't enough. Here are four key steps for planning for a career in information security.
-
The real information security risk equation
by Ron Woerner
A simplified information security risk equation helps translate information security risk to users.
-
Cybersecurity bill lacks details
The Rockefeller-Snowe cybersecurity bill has potential but raises a lot of questions.
-
Four steps toward a plan for a career in information security
by Lee Kushner and Mike Murray
More Premium Content Accessible For Free
Next-generation firewalls play by new rules
E-Zine
Firewalls started their journey to the next generation at about the same time as the Star Trek TV series. While the products have advanced with ...
Developing your endpoint security management transition plan
E-Handbook
This TechGuide will help you develop your endpoint security management transition plan. Articles focus on overcoming the challenges of Web-based ...
Unlock new pathways to network security architecture
E-Zine
Network security architecture is showing its age at many organizations. With new technology, different data types, and use of multi-generations of ...
Security Management Strategies for the CIO