Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Management
[Top] [All Lists]

RE: Risk Assessment Modelling

Subject: RE: Risk Assessment Modelling
Date: Mon, 9 Aug 2004 13:33:06 -0400
Encierro Solutions specializes in Operations Risk Management Software
solutions for banks and credit unions.

The Matador system enables banks to comply with the latest Information
Security Risk Assessment guidelines. The Matador software contains
pre-written risk management scripts with which consultants can help banks
assess and mitigate risks in the quickest, most cost-effective manner. The
system addresses all Information Security areas, including IT, facilities,
third party service providers, and physical records. The system has received
the approval of both OCC and FDIC. 
 
In addition to enabling banks to comply with the Information Security Risk
Assessment guidelines, the Matador system assists in the implementation of
an overall Information Security Risk Management program that is integrated
into a bank's operations. Utilizing the software, banks can assign personnel
to various risk management activities,  prepare a variety of risk management
reports, and view historical data. This system enables banks to view their
risk situation at any given point in time. The Matador system provides
assurance to Senior Management and the Board that a safe and sound risk
management practice is operational in the bank, protecting the best interest
of the bank and its customers.

There are also modules to assist banks and credit unions in the task of
Vendor/Third Party Risk Management and Business Continuity Planning.  

Brief PowerPoint presentation -
http://www.encierro.biz/infosecurity/first.ppt

Sample Screens -
http://www.encierro.biz/screens/screens.htm

Sample Reports -
http://www.encierro.biz/reports/reports.htm

Other information -
http://www.encierro.biz/infosecurity/matadorannounce.doc
http://www.encierro.biz/infosecurity/formalapproach.doc
http://www.encierro.biz/infosecurity/matadordescription.doc

Corporate Web Site -
http://www.encierro.biz/

-----Original Message-----
From: atlantis 1 [mailto:atlantis1@fastmail.fm] 
Sent: Monday, August 09, 2004 8:28 AM
To: security-management@securityfocus.com
Subject: Risk Assessment Modelling



Hi,

I am currently working on a Risk Assessment Model as part of my
organisation's initiative to prepare for a BS7799 Certification.

I have gone through NIST 800-30 and OCTAVE and am accordingly developing an
excel based quasi quantitative model which takes into account threats,
impact, probabilities of occurence in analysing risk.

I would like to know whether there are any standard software that can help
me in doing a risk assessment exercise. I have heard about CRAMM, but have
not had an opportunity to use/evaluate it. Any inputs on any good software
applications in the field of Risk Assessment would be much appreciated.

Thanks in advance for your help.

Regards.
Andrew

<Prev in Thread] Current Thread [Next in Thread>