This book presents real solutions for assessing cybersecurity risk by skillfully applying the quantitative language of risk analysis to information security. It simplifies the complexity of quantifying uncertainty and sheds light on matters with little data or seemingly intangible goals--and dispels long-held beliefs about cybersecurity practices as well as provides authoritative guidance to solving problems by measuring risk. The book provides practical guide to better risk assessment by describing a very simple quantitative solution, building on it with more advanced methods, and providing detailed advice for choosing the one that best fits the reader's needs.
New to this edition will be a new case example, some new simple measurement/estimation methods (e.g., pseudo-random number generator and the new methods for combining expert opinion), and a discussion of some objections to quantitative methods. In addition two new chapters will be added: (1) advanced Bayesian methods and (2) practical roll-out of a program from ground zero to maturity.This title hasn’t been rated yet...be the first!