Disclaimer: The opinions of the columnists are their own and not necessarily those of their employer.

Tag Archives: subjective

6 Theories of Probability and 6 Reasons Why They Matter to ISRA

– While probably everyone would agree that information security risk analysis (ISRA) is shot through with appeals to probability, very few non-academic discussions of ISRA provide any sort of rigorous analysis of what “probability” means. (See Alberts and Dorofee 2003 for a notable…

The Difference between Quantitative and Qualitative Risk Analysis and Why It Matters (Part 2)

– Objective vs. Subjective Approaches: Strengths and Weaknesses As we have seen, quantitative risk analyses can be subjective and qualitative risk analyses can be objective. The purpose of this slide is to summarize and discuss some of the advantages and disadvantages of both the objective and…