These papers discuss the subject of risk assessment and were written over the period September 1997 to July 2000.
Thus they are of historic interest only.
One of the problems that we have faced is how to engage senior non-IT
management on this subject. We have a solution, which we devised in earnest over the period September 2001
to November 2003. It starts with events and impacts and is very
effective. You may see an example of it in our Integrated Management System demonstrator.
As another word of warning - be very wary of risk assessment methods that do not result in treatement of risk and the identification of controls. After all, that is the actually the purpose of conducting the risk assessment in the first place |