0%

A start-to-finish guide for realistically measuring cybersecurity risk

In the newly revised How to Measure Anything in Cybersecurity Risk, Second Edition, a pioneering information security professional and a leader in quantitative analysis methods delivers yet another eye-opening text applying the quantitative language of risk analysis to cybersecurity. In the book, the authors demonstrate how to quantify uncertainty and shed light on how to measure seemingly intangible goals. It's a practical guide to improving risk assessment with a straightforward and simple framework.

Advanced methods and detailed advice for a variety of use cases round out the book, which also includes:

  • A new "Rapid Risk Audit" for a first quick quantitative risk assessment.
  • New research on the real impact of reputation damage
  • New Bayesian examples for assessing risk with little data
  • New material on simple measurement and estimation, pseudo-random number generators, and advice on combining expert opinion

Dispelling long-held beliefs and myths about information security, How to Measure Anything in Cybersecurity Risk is an essential roadmap for IT security managers, CFOs, risk and compliance professionals, and even statisticians looking for novel new ways to apply quantitative techniques to cybersecurity.

Table of Contents

  1. Cover
  2. Title Page
  3. Copyright
  4. Dedication
  5. Foreword for the Second Edition
  6. Acknowledgments
  7. Preface
  8. Introduction
  9. PART I: Why Cybersecurity Needs Better Measurements for Risk
  10. PART II: Evolving the Model of Cybersecurity Risk
  11. PART III: Cybersecurity Risk Management for the Enterprise
  12. APPENDIX A: Selected Distributions
  13. APPENDIX B: Guest Contributors
  14. Index
  15. End User License Agreement
34.239.150.167