02.07.2014 Views

Introducing OCTAVE Allegro - Software Engineering Institute ...

Introducing OCTAVE Allegro - Software Engineering Institute ...

Introducing OCTAVE Allegro - Software Engineering Institute ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Another significant difference in <strong>OCTAVE</strong>-S is that it is more structured than the <strong>OCTAVE</strong> method.<br />

Security concepts are embedded in the <strong>OCTAVE</strong>-S worksheets and guidance, allowing less<br />

experienced risk and security practitioners to address a broad range of risks with which they may<br />

not have familiarity. A final distinguishing feature of <strong>OCTAVE</strong>-S is that it requires a less extensive<br />

examination of an organization’s information infrastructure. Because small organizations<br />

may not have the resources to obtain and execute vulnerability tools, <strong>OCTAVE</strong>-S was designed to<br />

include a limited examination of infrastructure risks so as to remove a potential barrier to adoption.<br />

1.2.3 <strong>OCTAVE</strong> <strong>Allegro</strong><br />

allegro: (al-leg-ro) adv. In a quick and lively tempo. 5<br />

The <strong>OCTAVE</strong> <strong>Allegro</strong> approach being introduced in this technical report is designed to allow<br />

broad assessment of an organization’s operational risk environment with the goal of producing<br />

more robust results without the need for extensive risk assessment knowledge. This approach differs<br />

from previous <strong>OCTAVE</strong> approaches by focusing primarily on information assets in the context<br />

of how they are used, where they are stored, transported, and processed, and how they are<br />

exposed to threats, vulnerabilities, and disruptions as a result. Like previous methods, <strong>OCTAVE</strong><br />

<strong>Allegro</strong> can be performed in a workshop-style, collaborative setting and is supported with guidance,<br />

worksheets, and questionnaires, which are included in the appendices of this document.<br />

However, <strong>OCTAVE</strong> <strong>Allegro</strong> is also well suited for use by individuals who want to perform risk<br />

assessment without extensive organizational involvement, expertise, or input.<br />

Figure 2:<br />

<strong>OCTAVE</strong> <strong>Allegro</strong> Roadmap<br />

5<br />

WordNet 2.1 Princeton University. March 2, 2007. Dictionary.com: http://dictionary.reference.com/browse/allegro<br />

4 | CMU/SEI-2007-TR-012

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!