Risk
摘要
Unwanted events, such as attempts to breach the security policy of an IT system, may appear with very different frequencies and have very different consequences. Risk analysis is used to determine which possible events are the most serious, so that most effort should go into preventing them. This chapter explains the meaning of objective risk, and gives an introduction to the discipline of risk management – the ways in which risk can be reduced in an IT system by introducing countermeasures.