Glossary

Accept

a decision made during risk analysis to take no action to address a risk and to accept the consequences should the risk occur.

Access path

ways in which information or services can be accessed via an organization's network.

Action list

a list of actions that people in an organization can take in the near term without the need for specialized training, policy changes, etc. It is essentially a list of near-term action items.

Actor

a property of a threat that defines who or what may violate the security requirements (confidentiality, integrity, availability) of an asset.

Analysis team

an interdisciplinary team, comprising representatives of both the mission-related and information technology areas of the organization, which conducts ...

Get Managing Information Security Risks: The OCTAVESM Approach now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.