首页
学习
活动
专区
圈层
工具
发布
社区首页 >专栏 >CISSP考试指南笔记:1.13 风险评估和分析

CISSP考试指南笔记:1.13 风险评估和分析

作者头像
血狼debugeeker
发布2020-12-21 11:29:08
发布2020-12-21 11:29:08
9260
举报
文章被收录于专栏:debugeeker的专栏debugeeker的专栏

A risk assessment, which is really a tool for risk management, is a method of identifying vulnerabilities and threats and assessing the possible impacts to determine where to implement security controls.After a risk assessment is carried out, the results are analyzed. Risk analysis is used to ensure that security is cost effective, relevant, timely, and responsive to threats.

A risk analysis has four main goals:

  • Identify assets and their value to the organization.
  • Identify vulnerabilities and threats.
  • Quantify the probability and business impact of these potential threats.
  • Provide an economic balance between the impact of the threat and the cost of the countermeasure.

Risk analysis provides a cost/benefit comparison, which compares the annualized cost of controls to the potential cost of loss.

剩余内容请看本人公众号debugeeker, 链接为CISSP考试指南笔记:1.13 风险评估和分析

本文参与 腾讯云自媒体同步曝光计划,分享自作者个人站点/博客。
原始发表:2020/12/18 ,如有侵权请联系 cloudcommunity@tencent.com 删除
问题归档专栏文章快讯文章归档关键词归档开发者手册归档开发者手册 Section 归档