Adapting Your Process to Include Cyber Opportunities
摘要
In Chapter 10 , I introduced the ECRM Process based on “Managing Information Security Risk” (NIST Special Publication 800-39)2 and the four basic steps, each informing the other steps. To summarize, they are frame risk, assess risk, respond to risk, and monitor risk.