Chapter 1. Managing Information Security Risks

It is easy to overlook the fact that information security affects an entire organization. But ultimately, it is a business problem whose solution involves more than deploying information technology such as firewalls and virus patches. Some surveys on security incidents and breaches have indicated that the majority of security breaches occur from the inside, not from the notorious teenage attackers trying to get in from the outside. More recent surveys indicate that the majority of attacks do come from outside. There are yet other indicators that the most costly attacks come from the inside, even though the highest frequency of attacks come from the outside. With little consistency in the information ...

Get Managing Information Security Risks: The OCTAVESM Approach now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.