The Open Group Security Forum has recently published two documents in the risk management area that are worth taking note of. The first is a Risk Taxonomy Standard. This standard fills a gap among the many risk management frameworks that are out there, it is definitely worth a look.

In addition, the Open Group Security Forum has also produced a technical guide, Requirements for Risk Assessment Methodologies. This document will be posted here in the next few days.

Both are freely available. If you are interested in the risk management subject area, The Security Forum has additional work ongoing in this area, and we would welcome your input and participation. Among our future risk management projects are cookbooks showing how to use the risk taxonomy standard with frameworks such as COSO ERM, Octave, and other risk frameworks.

Jim