home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.security.misc
- Path: sparky!uunet!paladin.american.edu!howland.reston.ans.net!usc!sol.ctr.columbia.edu!The-Star.honeywell.com!umn.edu!sctc.com!smith
- From: smith@sctc.com (Rick Smith)
- Subject: Re: quantitaive risk analysis
- Message-ID: <1993Jan25.194004.10574@sctc.com>
- Keywords: risk analysis
- Organization: SCTC
- References: <1993Jan22.060220.27585@cs.uow.edu.au>
- Date: Mon, 25 Jan 1993 19:40:04 GMT
- Lines: 9
-
- I haven't seen anything on cost/benefit and computer security risk
- analysis, but there are several US DOD Orange Book derived approaches
- that specify strength of security (actually, Orange Book rating) to
- security risk (actually, range of data sensitivity handled). It's
- documented in the Yellow Book: CSC-STD-003-85, Guidance for Applying
- the TCSEC in Specific Environments.
-
- I remember hearing a couple of papers presenting alternative rating
- approaches at the 1991 NCSC, and they should be in the Proceedings.
-