Accession Number:

ADA399229

Title:

OCTAVEsm Criteria, Version 2.0

Descriptive Note:

Final rept.

Corporate Author:

CARNEGIE-MELLON UNIV PITTSBURGH PA SOFTWARE ENGINEERING INST

Report Date:

2001-12-01

Pagination or Media Count:

141.0

Abstract:

Today, we rely on access to digital data that are accessible, dependable, and protected from misuse. Unfortunately, this need for accessible data also exposes organizations to a variety of new threats that can affect their information. The Operationally Critical Threat, Asset, and Vulnerability EvaluationService Mark OCTAVEService Mark enables organizations to understand and address their information security risks. OCTAVE is led by a small, interdisciplinary team of an organizations personnel and focuses on an organizations assets and the risks to those assets. It is a comprehensive, systematic, context-driven, and self-directed evaluation approach. The essential elements of the OCTAVE approach are embodied in a set of criteria that define the requirements for OCTAVE. This report describes the OCTAVE criteria. The goal of this report is to define a general approach for evaluating and managing information security risks. Organizations can then develop methods that are consistent with the OCTAVE criteria.

Subject Categories:

  • Operations Research
  • Computer Systems Management and Standards

Distribution Statement:

APPROVED FOR PUBLIC RELEASE