Title :
WorldCIS-2013: Keynote speaker 1
Author :
Wiley, Jeffrey J.
Author_Institution :
Internal Revenue Service (IRS), USA
Abstract :
Summary form only given. This presentation discusses Risk-based Information Security as the follow-on to a checklist, compliance-based approach to information security. The presentation begins with an overview of the principles of information security and then covers risk concepts and risk management, including risk assessment, ratings and loss calculations. Next, the discussion turns to the two different information security approaches and the current methodologies to follow while using a risk-based approach. I provide a contrast and comparison of the methodologies and conclude by providing some useful takeaways for those in attendance to begin using immediately.
Keywords :
risk management; security of data; information security risk management; risk assessment; risk based information security; risk concepts;
Conference_Titel :
Internet Security (WorldCIS), 2013 World Congress on
Conference_Location :
London
DOI :
10.1109/WorldCIS.2013.6751004