Security Basics mailing list archives

RE: Risk methodologies


From: "Huyser, Brad [IDCU]" <Brad.Huyser () iacudiv state ia us>
Date: Tue, 10 Apr 2007 08:25:52 -0500

Two of them that I can think of right are the OCATAVE-S
(http://www.cert.org/octave/osig.html) and the STAR methodology
(http://security.vt.edu/playitsafe/index.php)


Brad 


-----Original Message-----
From: listbounce () securityfocus com [mailto:listbounce () securityfocus com]
On Behalf Of offset
Sent: Monday, April 09, 2007 2:50 PM
To: security-basics () securityfocus com
Subject: Risk methodologies

I'm currently researching Risk methodologies (more aligned with IT
risk).

I know of the NIST publication sp800-30.  Are there any other
resources/papers that I could research to get different perspectives?

Thanks in advance,
offset


Current thread: