8. Risk analysis
Risk analysis is the second stage in risk assessment.
Risk analysis: process used to understand the nature and determine the level of risk (ISO/IEC 27000, § 3.6.3).
ISO/IEC 27000 has identified three main factors in the definition of information security.
Information security: protecting the confidentiality, integrity and availability of information (ISO/IEC 27000, § 3.28).
These factors are used to determine the strength of the impacts (consequences) suffered by each asset. Figure
4...
You do not have access to this resource.
Exclusive to subscribers. 97% yet to be discovered!
Already subscribed?
Log in!
Ongoing reading
Risk analysis