Chapter 4. Preparing for OCTAVE

As we pointed out in Chapter 3, you need to prepare before you can successfully conduct an organizationwide information security risk evaluation like the OCTAVE Method. The objective of preparing for the evaluation is to build a solid foundation for coordinating and executing all subsequent evaluation activities. This chapter examines the activities that need to be undertaken to prepare for the OCTAVE Method.


4.1 Overview of Preparation

4.2 Obtain Senior Management Sponsorship of OCTAVE

4.3 Select Analysis Team Members

4.4 Select Operational Areas to Participate in OCTAVE

4.5 Select Participants

4.6 Coordinate Logistics

4.7 Sample Scenario

