Show simple item record

dc.contributor.authorBaskerville, Richard
dc.contributor.editorD W Straub
dc.contributor.editorS Goodman
dc.contributor.editorR Baskerville
dc.date.accessioned2017-01-30T11:10:40Z
dc.date.available2017-01-30T11:10:40Z
dc.date.created2015-07-16T07:04:23Z
dc.date.issued2008
dc.identifier.citationBaskerville, R. 2008. Strategic Information Security Risk Management, in Straub, D. and Goodman, S. and Baskerville, R. (ed), Information Security: Policy, Processes, and Practices, pp. 112-122. Armonk: M E Sharpe.
dc.identifier.urihttp://hdl.handle.net/20.500.11937/9138
dc.description.abstract

Risk management entails more than traditional risk analysis or risk assessment. These traditional tools are limited in fundamental ways, such as the lack of reliable frequency data about past risk events and the relative rarity of many kinds of risk that must still be managed. Risk management involves four types of risk treatments: self-protection, risk transfer, self-insurance, and risk avoidance This chapter introduces an approach to risk management in which the risks and risk treatments are strategically managed using a portfolio approach. With a portfolio approach, different risk portfolios are managed through a portfolio of risk treatments.

dc.publisherM E Sharpe Inc
dc.titleStrategic Information Security Risk Management
dc.typeBook Chapter
dcterms.source.titleInformation Security: Policy, Processes, and Practices
dcterms.source.isbn9780765617187
dcterms.source.placeNA
dcterms.source.chapter11
curtin.departmentSchool of Information Systems
curtin.accessStatusFulltext not available


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record