Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Management
[Top] [All Lists]

RE: Information Risk Management

Subject: RE: Information Risk Management
Date: Thu, 16 Jun 2005 16:43:37 +0530
Hi,

 

NIST Special Publication 800-30, Risk Management Guide for Information
Technology Systems 

 

csrc.nist.gov/publications/nistpubs/800-30/sp800-30.pdf    

 

is a good resource for Risk Management.

 

Cheers

 

Nitin Nair

  _____  

From: alan_willcox@vanguard.com [mailto:alan_willcox@vanguard.com] 
Sent: Wednesday, June 15, 2005 11:09 PM
To: Karan Saberwal
Cc: John Blackley; security-management@securityfocus.com
Subject: Re: Information Risk Management

 


At the risk of sounding like a broken record, the ISF Standard of Good
Practice (free at http://www.isfsecuritystandard.com/) goes into lots of
detail on information risk management, specifically in sections CI54, CB53,
NW44, SM33, and SD35. (ISF Members get lots of additional research and
practical tools.)

<Prev in Thread] Current Thread [Next in Thread>