Last revised on: 09-Dec-2004

University of Houston

       
One
Two
Three
Four 
Five 
Six 
Seven 
 Eight
 

Eight - Compare and Contrast on NIST 800-30 and OCTAVE methodologies

This assignment is to review the OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation) methodology. Prepare a brief presentation that compares and contrasts OCTAVE with NIST's Risk Management Guide for Information Technology Systems(800-30). As an option, you may compare OCTAVE with both 800-30 and the IAM. Post the document to your web site using a methodology similar to the presentations that we have done previously.

Some useful links: Here is a link to the "Introduction to the OCTAVE Approach". This is a brief overview of the Operationally Critical Threat, Asset, and Vulnerability Evalaution (OCTAVE ) approach for managing information security risks.
http://www.cert.org/octave/approach_intro.pdf

This link is to the sample chapter "Conducting the Risk Assessment" from Managing Information Security Risks: The OCTAVE Approach.
http://www.awprofessional.com/catalog/product.asp?producerid={E167C83D-A98D-03BFAA8A1AE1}

OCTAVE publications page. http://www.cert.org/octave/pubs.html

Slide show page. http://www.meyerweb.com/eric/tools/s5

Presentation