51,50 €*
He holds a BS in CIS, master's in telecommunication and project management, a PhD in information systems, and the CISSP, CISA, CISM, CRISC, CIPP, and PMP certifications. Jack is a visiting professor at DeVry University and a senior member of the ISSA, IEEE, and ACM. Jack chairs a CRISC subcommittee for ISACA and has participated as a member of the Open Group's risk analyst certification committee. Jack's writings have appeared in the ISSA Journal, Bell Labs Technical Journal, Columbus CEO magazine, and he currently writes a risk column for @ISACA. You can follow all Jack's work and writings at riskdr.com.
In 2007, he was selected as a finalist for the Information Security Executive of the Year, Central United States, and in 2012 was honored with the CSO Compass award for leadership in risk management. He is also the author and creator of the Factor Analysis of Information Risk (FAIR) framework. Currently, Jack is co-founder and president of CXOWARE, Inc.
Using the factor analysis of information risk (FAIR) methodology developed over ten years and adopted by corporations worldwide, Measuring and Managing Information Risk provides a proven and credible framework for understanding, measuring, and analyzing information risk of any size or complexity. Intended for organizations that need to either build a risk management program from the ground up or strengthen an existing one, this book provides a unique and fresh perspective on how to do a basic quantitative risk analysis. Covering such key areas as risk theory, risk calculation, scenario modeling, and communicating risk within the organization, Measuring and Managing Information Risk helps managers make better business decisions by understanding their organizational risk.
Chapter 1: Introduction
Chapter 2: Basic Risk Concepts
Chapter 3: The FAIR Risk Ontology
Chapter 4: FAIR Terminology
Chapter 5: Measurement
Chapter 6: Analysis Process
Chapter 7: Interpreting Results
Chapter 8: Risk Analysis Examples
Chapter 9: Thinking about Risk Scenarios Using FAIR
Chapter 10: Common Mistakes
Chapter 11: Controls
Chapter 12: Risk Management
Chapter 13: Information Security Metrics
Chapter 14: Implementing Risk Management