5 月 11 日(四) 16:30 - 17:00 7F 701H
介紹 FAIR 風險分析如何應用於 ISMS (ISO27005) 風險管理框架
簡報連結

Risk management without “Risk Analysis” is like driving in the dark without lights. It is like a person who has the knowledge and skill to drive a car but without direction and visibility to the danger along the way. Similarly, organizations often headstrong into implementing cyber risk management programs without clear visibility into their risks landscape. Oftentimes, Risk Analysis is done based on the subjectivity of the IT and cybersecurity professionals, which can vary from person to person and limit to the technology component. Furthermore, to make risk management even more difficult, as cybersecurity is a young industry, there is no agreement on the definition of risk, i.e. vulnerabilities, threat agents, CVE, or IOC. Therefore, risk analysis is inconsistent, risk decisions are misled, and risk appetite is misaligned. FAIR is a Risk Analysis methodology, an add-on component, to address consistency and repeatability in the Risk Management and ISMS processes.

  • FORUM | 資安治理論壇
  • LOCATION | 臺北南港展覽二館 7F 701H
  • LEVEL | 中階
  • SESSION TYPE | 現場演講
  • LANGUAGE | 中文
  • SESSION TOPIC | Cyber Risk Quantification Risk Analysis ISO 27005