Actions

Difference between revisions of "OCTAVE (Operationally Critical Threat, Asset and Vulnerability Evaluation)"

(Created page with "The '''Operationally Critical Threat, Asset, and Vulnerability Evaluation (OCTAVE)''' is a framework for identifying and managing information security risks. It defines a comp...")
 
Line 1: Line 1:
 
The '''Operationally Critical Threat, Asset, and Vulnerability Evaluation (OCTAVE)''' is a framework for identifying and managing information security risks. It defines a comprehensive evaluation method that allows an [[Organization|organization]] to identify the information assets that are important to the mission of the organization, the threats to those assets, and the vulnerabilities that may expose those assets to the threats. By putting together the information assets, threats, and vulnerabilities, the organization can begin to [[Information Risk Management (IRM)|understand what information is at risk]]. With this understanding, the organization can design and implement a protection strategy to reduce the overall risk exposure of its information assets.<ref>Definition - What is OCTAVE (Operationally Critical Threat, Asset and Vulnerability Evaluation) [https://resources.sei.cmu.edu/library/asset-view.cfm?assetid=13473 CMU.edu]</ref>
 
The '''Operationally Critical Threat, Asset, and Vulnerability Evaluation (OCTAVE)''' is a framework for identifying and managing information security risks. It defines a comprehensive evaluation method that allows an [[Organization|organization]] to identify the information assets that are important to the mission of the organization, the threats to those assets, and the vulnerabilities that may expose those assets to the threats. By putting together the information assets, threats, and vulnerabilities, the organization can begin to [[Information Risk Management (IRM)|understand what information is at risk]]. With this understanding, the organization can design and implement a protection strategy to reduce the overall risk exposure of its information assets.<ref>Definition - What is OCTAVE (Operationally Critical Threat, Asset and Vulnerability Evaluation) [https://resources.sei.cmu.edu/library/asset-view.cfm?assetid=13473 CMU.edu]</ref>
 +
 +
 +
===See Also===
 +
[[IT_Governance|IT Governance]]<br />
 +
[[ITIL_(Information_Technology_Infrastructure_Library)|ITIL]]<br />
 +
[[Val_IT_Framework|Val IT]]<br />
 +
[[Risk_IT_Framework|Risk IT]]<br />
 +
[[Factor Analysis of Information Risk (FAIR)]]<br />
 +
[[COBIT (Control Objectives for Information and Related Technology)]]<br />
 +
[[Business_Model_for_Information_Security_(BMIS)|Business Model for Information Security (BMIS)]]<br />
 +
[[Committee_of_Sponsoring_Organizations_of_the_Treadway_Commission_(COSO)|COSO]]<br />
 +
[[Capability_Maturity_Model_Integration_(CMMI)|CMMI]]<br />
 +
[[IT_Assurance_Framework_(ITAF)|IT Assurance Framework (ITAF)]]<br />
 +
[[IT_Governance_Framework|IT Governance Framework]]<br />
 +
[[ICT_Investment_Framework|ICT Investment Framework]]<br />
 +
[[IT_Investment_Management_Framework_(ITIM)|Information Technology Investment Management (ITIM)]]<br />
 +
[[The Open Group Architecture Framework (TOGAF)|The Open Group Architecture Framework (TOGAF®)]]
 +
 +
 +
===References===
 +
<references/>

Revision as of 18:38, 18 December 2019

The Operationally Critical Threat, Asset, and Vulnerability Evaluation (OCTAVE) is a framework for identifying and managing information security risks. It defines a comprehensive evaluation method that allows an organization to identify the information assets that are important to the mission of the organization, the threats to those assets, and the vulnerabilities that may expose those assets to the threats. By putting together the information assets, threats, and vulnerabilities, the organization can begin to understand what information is at risk. With this understanding, the organization can design and implement a protection strategy to reduce the overall risk exposure of its information assets.[1]


See Also

IT Governance
ITIL
Val IT
Risk IT
Factor Analysis of Information Risk (FAIR)
COBIT (Control Objectives for Information and Related Technology)
Business Model for Information Security (BMIS)
COSO
CMMI
IT Assurance Framework (ITAF)
IT Governance Framework
ICT Investment Framework
Information Technology Investment Management (ITIM)
The Open Group Architecture Framework (TOGAF®)


References

  1. Definition - What is OCTAVE (Operationally Critical Threat, Asset and Vulnerability Evaluation) CMU.edu