July 5, 2022, 11:44 a.m. | /u/Tertel9000

cybersecurity www.reddit.com

When conducting infosec risk assessments, we're struggling with evaluating the impact of the risk/threat in question on confidentiality, integrity and availability, respectively.

Looking for a ressource or similar providing inspiration for defining impact categories (i.e. low, medium, high etc.) for each of the CIA areas - similar to those that states that "high impact equals cost of 2M" - How does one define what "high" impact to confidentiality etc. equals?


Thanks!

assessment cia cybersecurity impact risk risk assessment

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Security Operations Manager (f/d/m), 80-100%

@ Alpiq | Lausanne, CH

Project Manager - Cyber Security

@ Quantrics Enterprises Inc. | Philippines

Sr. Principal Application Security Engineer

@ Gen | DEU - Tettnang, Kaplaneiweg

(Senior) Security Architect Car IT/ Threat Modelling / Information Security (m/f/x)

@ Mercedes-Benz Tech Innovation | Ulm

Information System Security Officer

@ ManTech | 200AE - 375 E St SW, Washington, DC