Ανάλυση του εργαλείου CRAMM
Master Thesis
Author
Δημοσχάκης, Λουλούδης
Date
2011-02-28View/ Open
Subject
Διαχείριση κινδύνου -- Πληροφοριακά συστήματα ; Πληροφοριακά συστήματα -- Μέτρα ασφαλείας ; Πληροφοριακά συστήματα -- Διοίκηση και οργάνωσηAbstract
Facing the emerging challenges of the Internet era, managers and information security professionals inbusiness and government should manage specific risks to their organizations to ensure efficient operations. This paper explains basic components of risk analysis and management processes and mentions different methodologies and approaches. It then describes and discusses CRAMM, as an automated tool based on qualitativerisk assessment methodology, by going through the stages of a CRAMM review. At last, a risk analysis for a practical implementation scenario in a corporate network, is carried out, using CRAMM tool. The Information System of NEC Unified Solutions Company is the model on which i build the whole study.