The Main OCTAVE principles are as follows:
- Core Information Security Risk Evaluation Principles
- Self-directed
- The organisation takes responsibility for the evaluation
- The organisation makes the decisions
- Flexible / adaptable in the face of...
- Changes to best practices
- Evolution of known threats
- Technical weaknesses
- A defined process
- Responsibilities are set out and assigned to people
- How activities should be performed is documented
- Standards are set for documentation/artefacts : tools, worksheets, catalogues etc.
- A continuous process over time
- Self-directed
- General Risk Management Principles (general principles beyond InfoSec)
- Forward looking – proactive
- Identify future asset that may be significant
- New classes of threat
- Focus on critical few
- Resources are always constrained
- Avoid spreading effort too thinly
- Integrated management
- Information security as routine consideration for general business strategy
- Forward looking – proactive
- Organisational / Cultural Principles
- Open Communication
- Information sharing : avoidance of blame/judgment
- Global perspective
- Consult widely and integrate all views
- Widen perspective to organisational goals
- Based on teamwork
- Open Communication
0 comments:
Post a Comment