Information Security Risk Assessment: Practices of Leading Organizations. November, 1999
Issued By: GAO - Effective Date: 11.01.1999, 379.521K, PDF
Abstract: This guide is intended to help federal managers implement an ongoing information security risk assessment process by providing examples, or case studies, of practical risk assessment procedures that have been successfully adopted by four organizations known for their efforts to implement good risk assessment practices. It identifies, based on the case studies, factors that are important to the success of any risk assessment program, regardless of the specific methodology employed.




