Blog powered by TypePad

« MetriCon software security metrics track | Main | Bulletproofing your SOA »

Combining risk and effectiveness assessment to make risk management decisions

More from MetriCon, check out Bryan Ware's presentation The hard choices are deciding between projects within a sector and between # 2 and # 3.

Risk High 2 Discount for low effectiveness 1 Best investments
Low 4. Apply minimal funding 3. Incentivize high effectiveness
Low High
Effectiveness

This ties to Fred Cohen's work on medium assurance problems.

Comments

The comments to this entry are closed.