Tutorial C: Selecting Information Security Risk Assessment Methods and Tools — A Use-Case Approach
Monday, 17 September 2007
08:00-08:45
sec8i_G3.pdfsec8i_g3.ppt
Speaker: Tom Scholtz
Location: Westbourne 1, Level -1
Session Type: Pre-Conference Tutorial
Track: Track 3

Tom ScholtzLeading organizations understand that effective risk assessment depends on the ability to manage a toolbox of assessment techniques, and to apply the most appropriate technique on a case by case basis.
Key Issues:
  • How should enterprises characterize the use cases for information security risk assessment?
  • How should enterprises select appropriate risk assessment methods and tools?
  • How can enterprises formalize risk assessment experience and learning?