• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer
  • Home
  • Resources
    • Calculators
      • ISO Certification Cost Calculator
      • Cost of Quality Calculator
    • Lowest Cost ISO Services Quote Program
    • Online Gap Checklists
      • ISO 9001 Gap Checklist
        • ISO 9001 Gap Checklist Overview
        • ISO 9001 Gap Checklist Sample
        • ISO 9001 Gap Checklist Dashboard
      • ISO 45001 Gap Checklist
        • 45001 Checklist Gap Checklist Overview
        • ISO 45001 Gap Checklist Sample
        • ISO 45001 Gap Checklist Dashboard
      • ISO 27001 Gap Checklist
        • ISO/IEC 27001 Gap Checklist Overview
        • ISO 27001 Gap Checklist Sample
        • ISO 27001 Gap Checklist Dashboard
    • White Papers
      • AI and Quality Management: Many Questions, Few Answers
      • A Guide to Quality Risk Management
      • ISO 9001 Updates FAQ
      • Integrating ISO 27001 and ISO 9001
    • Job Salary Reports
      • Quality Professionals Salary Report
    • Free Quality Ebook
    • Glossary
  • Articles
    • Environment
    • Cybersecurity
      • Artificial Intelligence
      • Automation
      • Career
      • Certification Management
      • Continuous Improvement
      • Documentation
      • ISO 27001
      • Information Security Mgt. Systems (ISMS)
      • Management
      • Regulatory
      • Risk Management
      • Software
      • Supplier Quality
      • Sustainability
    • Management Systems
    • Manufacturing
    • Quality
      • Artificial Intelligence
      • Automation
      • Career
      • Certification Management
      • Continuous Improvement
      • Cost of Quality
      • Documentation
      • ISO 9001
      • LEAN-6 Sigma
      • Product Safety
      • Quality Management
      • Regulatory
      • Risk Management
      • Root Cause
      • Skills
      • Software
      • Supplier Quality
      • Sustainability
    • Safety
      • Product Safety Certification
      • Risk Management
  • What We Do
    • About Conformance 1
    • Group Purchasing
    • Negotiated Discounts
    • Why Buy Through Us?
  • Products/Services
    • Name Your Fee Training
    • Registrar Directory
    • Software Directory
    • Consultant Directory
  • Online Gap Checklists
    • ISO 9001 Dashboard
    • ISO 45001 Dashboard
    • ISO 27001 Dashboard
  • Contact
    • General Inquiries
    • Ask an ISO Expert
  • Login
    • Login
    • Log Out
Conformance1

Conformance1

Tools for conforming to standards, goals and processes

Book Review: “Measuring and Managing Information Risk”

Leave a Comment Filed Under: Cybersecurity-Management

  • The upcoming second edition of “Measuring and Managing Information Risk” provides a comprehensive guide to measuring and managing information risk using the FAIR methodology, suitable for varied organizational complexities.
  • It combines theoretical insights with practical applications, helping managers make informed decisions based on structured risk assessment methods.
  • The book introduces new chapters on aligning risk programs with standards, automating assessments, and modern quantitative risk techniques.
  • And it offers insights and case studies from diverse industries, balancing accessible writing with expert commentary from industry professionals.

Measuring and Managing Information Risk: A FAIR Approach, Second Edition is a detailed resource for understanding and applying the Factor Analysis of Information Risk (FAIR) methodology, a trusted framework for measuring and managing information risk across various organizational contexts. With over a decade of development and practical application, FAIR has become a cornerstone for assessing risk in complex environments. This edition retains the fundamental concepts of risk measurement, offering a step-by-step approach to equip managers and IT professionals with the tools to make informed, risk-aware business decisions. Notably, the new edition addresses advancements in risk assessment techniques, integrating quantitative methods into security programs that now include the use of security telemetry, external data, and automated assessments.

In addition to a solid grounding in risk theory and calculation, the book covers critical aspects of risk modeling and effective communication within organizations, enabling risk insights to be clearly understood by decision-makers. New chapters expand on practical topics, such as aligning risk programs with regulatory standards, automating assessments, and identifying common red flags in risk measurement. This edition also introduces the FAIR-CAM standard and incorporates insights from industry experts, providing readers with multiple perspectives and case studies from various sectors. These additions make the book an invaluable resource not only for newcomers to the field but also for seasoned professionals seeking structured guidance in implementing or refining IT risk management programs.

Dr. Jack Freund, the book’s author, brings a wealth of experience in IT risk management, specializing in translating complex risk scenarios into accessible insights for business executives. His extensive career spans more than 16 years in technology roles within organizations such as TIAA-CREF, Nationwide Insurance, CVS/Caremark, and Sony Ericsson, where he has consistently focused on enhancing risk assessment processes. Dr. Freund holds a PhD in Information Systems and a variety of industry certifications, including CISSP, CISA, CISM, CRISC, CIPP, and PMP, attesting to his deep expertise in the field. As a Senior Member of organizations like ISSA, IEEE, and ACM, he actively contributes to the industry through writing, teaching, and serving on certification committees. Dr. Freund also authors a regular risk column and has been published in respected industry journals, making him a well-regarded thought leader in IT and risk management. This book reflects his commitment to advancing the field by providing readers with both foundational knowledge and insights into current industry practices.

Read more about the book

Filed Under: Cybersecurity-Management

Reader Interactions

Leave a Reply

You must be logged in to post a comment.

Primary Sidebar

Search

Email Newsletter

News delivered to your inbox

Name(Required)
Newsletter Preferences(Required)
This field is hidden when viewing the form
This field is for validation purposes and should be left unchanged.

Related Items

Help us improve our tool

Have a suggestion for improving our ISO Gap Analysis Checklist? Let us know.

Secondary Sidebar

Categories

Recent Posts

  • Important Role of Thermal Imaging for Condition Monitoring
  • The Top 10 Security Awareness Training Solutions For Business
  • Improving Data Cleaning by Learning From Unstructured Textual Data
  • Operational Key Performance Indicators (KPIs) 2.0: A Smarter Way to Visualize and Use Your Metrics
  • Mastering the 8D Problem-Solving Methodology: A Guide to Root Cause Analysis in Manufacturing

Footer

Important Resources

Cost of Quality Calculator

ISO 9001 Online Gap Analysis

ISO Certification Cost Calculator

Free Quality Ebook

Process Improvement Survey

ISO 9001 Glossary

 

Recent Posts

  • Important Role of Thermal Imaging for Condition Monitoring
  • The Top 10 Security Awareness Training Solutions For Business
  • Improving Data Cleaning by Learning From Unstructured Textual Data
  • Operational Key Performance Indicators (KPIs) 2.0: A Smarter Way to Visualize and Use Your Metrics
  • Mastering the 8D Problem-Solving Methodology: A Guide to Root Cause Analysis in Manufacturing

Search

Contact Us

About Us

Privacy Policy

 

Copyright © 2025 · Conformance1 · Log in