Guide for Conducting Risk Assessments: NIST Special Publication 800-30, Revision 1
暫譯: 風險評估指南:NIST 特別出版物 800-30,第 1 版

U.S. Department of Commerce

  • 出版商: CreateSpace Independ
  • 出版日期: 2012-09-30
  • 售價: $730
  • 貴賓價: 9.5$694
  • 語言: 英文
  • 頁數: 100
  • 裝訂: Paperback
  • ISBN: 1497468159
  • ISBN-13: 9781497468153
  • 海外代購書籍(需單獨結帳)

商品描述

This document provides guidance for conducting risk assessments of federal informational systems and organizations, amplifying the guidance in Special Publication 800-39. This document provides guidance for carrying out each of the steps in the risk assessment process (i.e., preparing for the assessment, conducting the assessment, communicating the results of the assessment, and maintaining the assessment) and how risk assessments and other organizational risk management processes complement and inform each other. It also provides guidance to organizations on identifying specific risk factors to monitor on an ongoing basis, so that organizations can determine whether risks have increased to unacceptable levels (i.e., exceeding organizational risk tolerance) and different courses of action should be taken.

商品描述(中文翻譯)

本文件提供有關進行聯邦資訊系統和組織風險評估的指導,擴展了《特殊出版物 800-39》中的指導內容。本文件提供了風險評估過程中每個步驟的執行指導(即,準備評估、進行評估、傳達評估結果以及維護評估),並說明風險評估與其他組織風險管理流程如何相輔相成、互相告知。它還為組織提供了識別需持續監控的特定風險因素的指導,以便組織能夠判斷風險是否已增加到不可接受的水平(即,超過組織的風險容忍度),並應採取不同的行動方案。