[unisog] Risk analysis

Micheal Cottingham micheal.cottingham at sv.vccs.edu
Wed Feb 15 21:29:13 GMT 2006

I'm working on a paper to present to my boss, and am curious if anybody
has done any risk analysis or has any thoughts on it. I have Insider
Threat in front of me right now (great book so far) and he uses the
equation: Risk = (threat x vulnerabilities x probability x impact) /
countermeasures where countermeasures is: accept the risk, reduce the
risk, transfer the risk. What I'm looking for is if anybody has given
this much thought. For example, are different values placed on students
as opposed to faculty? Perhaps you split faculty and staff in to
different categories and drill down more. Or do you lump them all together?


