Model-Driven Risk Analysis The CORAS Approach

The term “risk” is known from many fields, and we are used to references to contractual risk, economic risk, operational risk, legal risk, security risk, and so forth. We conduct risk analysis, using either offensive or defensive approaches to identify and assess risk. Offensive approaches are conce...

Full description

Bibliographic Details
Main Authors: Lund, Mass Soldal, Solhaug, Bjørnar (Author), Stølen, Ketil (Author)
Format: eBook
Language:English
Published: Berlin, Heidelberg Springer Berlin Heidelberg 2011, 2011
Edition:1st ed. 2011
Subjects:
Online Access:
Collection: Springer eBooks 2005- - Collection details see MPG.ReNa
LEADER 03134nmm a2200349 u 4500
001 EB000384176
003 EBX01000000000000000237228
005 00000000000000.0
007 cr|||||||||||||||||||||
008 130626 ||| eng
020 |a 9783642123238 
100 1 |a Lund, Mass Soldal 
245 0 0 |a Model-Driven Risk Analysis  |h Elektronische Ressource  |b The CORAS Approach  |c by Mass Soldal Lund, Bjørnar Solhaug, Ketil Stølen 
250 |a 1st ed. 2011 
260 |a Berlin, Heidelberg  |b Springer Berlin Heidelberg  |c 2011, 2011 
300 |a XVI, 460 p  |b online resource 
653 |a Security Science and Technology 
653 |a Electronic data processing / Management 
653 |a Technological innovations 
653 |a Innovation and Technology Management 
653 |a Security systems 
653 |a Data protection 
653 |a Data and Information Security 
653 |a IT Operations 
700 1 |a Solhaug, Bjørnar  |e [author] 
700 1 |a Stølen, Ketil  |e [author] 
041 0 7 |a eng  |2 ISO 639-2 
989 |b Springer  |a Springer eBooks 2005- 
028 5 0 |a 10.1007/978-3-642-12323-8 
856 4 0 |u https://doi.org/10.1007/978-3-642-12323-8?nosfx=y  |x Verlag  |3 Volltext 
082 0 |a 004.068 
520 |a The term “risk” is known from many fields, and we are used to references to contractual risk, economic risk, operational risk, legal risk, security risk, and so forth. We conduct risk analysis, using either offensive or defensive approaches to identify and assess risk. Offensive approaches are concerned with balancing potential gain against risk of investment loss, while defensive approaches are concerned with protecting assets that already exist. In this book, Lund, Solhaug and Stølen focus on defensive risk analysis, and more explicitly on a particular approach called CORAS. CORAS is a model-driven method for defensive risk analysis featuring a tool-supported modelling language specially designed to model risks. Their book serves as an introduction to risk analysis in general, including the central concepts and notions in risk analysis and their relations. The authors’ aim is to support risk analysts in conducting structured and stepwise risk analysis. To this end, the book is divided into three main parts. Part I of the book introduces and demonstrates the central concepts and notation used in CORAS, and is largely example-driven. Part II gives a thorough description of the CORAS method and modelling language. After having completed this part of the book, the reader should know enough to use the method in practice. Finally, Part III addresses issues that require special attention and treatment, but still are often encountered in real-life risk analysis and for which CORAS offers helpful advice and assistance. This part also includes a short presentation of the CORAS tool support. The main target groups of the book are IT practitioners and students at graduate or undergraduate level. They will appreciate a concise introduction into the emerging field of risk analysis, supported by a sound methodology, and completed with numerous examples and detailed guidelines