

A start-to-finish guide for realistically measuring cybersecurity risk In the newly revised How to Measure Anything in Cybersecurity Risk, Second Edition , a pioneering information security professional and a leader in quantitative analysis methods delivers yet another eye-opening text applying the quantitative language of risk analysis to cybersecurity. In the book, the authors demonstrate how to quantify uncertainty and shed light on how to measure seemingly intangible goals. It's a practical guide to improving risk assessment with a straightforward and simple framework. Advanced methods and detailed advice for a variety of use cases round out the book, which also includes: A new "Rapid Risk Audit" for a first quick quantitative risk assessment. New research on the real impact of reputation damage New Bayesian examples for assessing risk with little data New material on simple measurement and estimation, pseudo-random number generators, and advice on combining expert opinion Dispelling long-held beliefs and myths about information security, How to Measure Anything in Cybersecurity Risk is an essential roadmap for IT security managers, CFOs, risk and compliance professionals, and even statisticians looking for novel new ways to apply quantitative techniques to cybersecurity.
| Country Of Origin | USA |
| Dimensions | 16 x 3.18 x 23.11 cm |
| Edition | 2nd |
| Importer | Bookswagon, 2/13 Ansari Road, Daryaganj, New Delhi 110002, [email protected], 01140159253 |
| Isbn 10 | 1119892309 |
| Isbn 13 | 978-1119892304 |
| Item Weight | 1 kg 50 g |
| Language | English |
| Packer | Bookswagon, 2/13 Ansari Road, Daryaganj, New Delhi 110002, [email protected], 01140159253 |
| Print Length | 345 pages |
| Publication Date | 11 April 2023 |
| Publisher | John Wiley & Sons Inc |
User
Best book
amazing bookgood sellermust buy for risk management
User
Required reading for security and risk professionals
The cybersecurity profession is rich in data and the boardroom is desperate for meaningful risk analysis, but our traditional ways of communicating risk doesn't use the data and favors vague phrases to communicate the message. This book aims to remedy this problem and does so masterfully.Many readers will need to un-learn some habits in order to embrace risk measurement, but the authors make a solid case for why the traditional qualitative risk register isn't adequate for the modern landscape. I personally had to read some sections more than once, which is a complement to the authors. Some of the best books I read involve some struggle and "How to Measure Anything in Cybersecurity Risk" is easily among the top ten books in this profession I've read.I'll further add that I'm not often a five star sort of reviewer, thinking often the truth lies in middle but this book is the exception to the rule. If you work in cybersecurity and want to improve your decision making ability this book is for you.
User
Covers Bayesian Statistical Analysis Applied to Cyber Security
I was hoping for some practical new ideas for methods of exploring and quantifying likelyhood and impact.This book provides a DEEP dive into Bayesian Statistical analysis, but it spends the first half of itself going into why it's needed and what is wrong with current subjective methods. I already knew what was wrong and why, that's why I bought the book.The techniques described will require a complete refit of what you are doing at a computational level, plus a complete mindshift away from normative practice.Disappointed ....
User
Illuminante! Chiarissimo!
The book is really interesting, with a very reader-friendly approach, as it is accessible to anyone who has the curiosity to learn more about cyber risk assessment. Reading this book was even fun for me because of the opportunity it gave me to be introduced to statistical laws.
User
Bridges tech and business
Cyber Risk Quantification is a very helpful topic to complement a security program
User
Puede mejorar en próximas ediciones
Muchas ideas de este libro por muy innovadoras que suenen no se desarrollan a una profundidad profesional. A veces el autor evita explicar tópicos esenciales que promete el libro porque sencillamente ni él mismo domina la materia o porque le interesa que muerdas el anzuelo de consultoría.
Trustpilot
3 days ago
4 days ago