User Risk (Hardcover)
Dr James W. Howell, Jr
Sold by Grand Eagle Retail, Bensenville, IL, U.S.A.
AbeBooks Seller since October 12, 2005
New - Hardcover
Condition: New
Ships within U.S.A.
Quantity: 1 available
Add to basketSold by Grand Eagle Retail, Bensenville, IL, U.S.A.
AbeBooks Seller since October 12, 2005
Condition: New
Quantity: 1 available
Add to basketHardcover. What happens after a system is authorized?The controls have been assessed. The vulnerabilities have been documented. The security plan is complete. The Authorizing Official accepts the residual risk, and the system receives its Authorization to Operate.Then people begin making decisions.Users respond to suspicious messages. Administrators grant privileges. Engineers decide when to patch. Security teams interpret alerts. Leaders approve exceptions. Under pressure, people make choices that can preserve the effectiveness of security controls or quietly undermine them.Yet one critical variable remains largely unmeasured: Human Judgment.User Risk: The Missing Variable in the Risk Management Framework challenges cybersecurity leaders to reconsider what they know about risk after authorization.Drawing on more than 30 years of cybersecurity leadership experience, Dr. James W. Howell Jr. introduces User Risk as a measurable operational variable that influences control effectiveness, Operational Trust, and mission assurance.Building on the NIST Risk Management Framework, the book introduces original concepts including Operational Trust, Behavioral Evidence, User Risk Indicators, and the User Risk Measurement Lifecycle. Together, they provide a structured approach for examining how human decisions affect security controls during real-world operations.Through analysis of major cyber incidents, governance principles, and practical application, User Risk exposes the gap between demonstrating that controls are implemented and understanding what happens when people must operate them under pressure, ambiguity, and competing mission demands.Written for Authorizing Officials, CIOs, CISOs, RMF practitioners, cybersecurity professionals, auditors, risk managers, and executive leaders responsible for consequential risk decisions.If we measure every other dimension of cybersecurity risk, why wouldn't we measure the people whose decisions ultimately determine whether trust is preserved? What happens to cybersecurity risk after the ATO is signed? User Risk examines the missing variable: human behavior. Written for AOs, CIOs, CISOs, and RMF practitioners, it shows how human decisions influence trust and control effectiveness. This item is printed on demand. Shipping may be from multiple locations in the US or from the UK, depending on stock availability.
Seller Inventory # 9798994382646
What happens after a system is authorized?
The controls have been assessed. The vulnerabilities have been documented. The security plan is complete. The Authorizing Official accepts the residual risk, and the system receives its Authorization to Operate.
Then people begin making decisions.
Users respond to suspicious messages. Administrators grant privileges. Engineers decide when to patch. Security teams interpret alerts. Leaders approve exceptions. Under pressure, people make choices that can preserve the effectiveness of security controls or quietly undermine them.
Yet one critical variable remains largely unmeasured: Human Judgment.
User Risk: The Missing Variable in the Risk Management Framework challenges cybersecurity leaders to reconsider what they know about risk after authorization.
Drawing on more than 30 years of cybersecurity leadership experience, Dr. James W. Howell Jr. introduces User Risk as a measurable operational variable that influences control effectiveness, Operational Trust, and mission assurance.
Building on the NIST Risk Management Framework, the book introduces original concepts including Operational Trust, Behavioral Evidence, User Risk Indicators, and the User Risk Measurement Lifecycle. Together, they provide a structured approach for examining how human decisions affect security controls during real-world operations.
Through analysis of major cyber incidents, governance principles, and practical application, User Risk exposes the gap between demonstrating that controls are implemented and understanding what happens when people must operate them under pressure, ambiguity, and competing mission demands.
Written for Authorizing Officials, CIOs, CISOs, RMF practitioners, cybersecurity professionals, auditors, risk managers, and executive leaders responsible for consequential risk decisions.
If we measure every other dimension of cybersecurity risk, why wouldn't we measure the people whose decisions ultimately determine whether trust is preserved?
"About this title" may belong to another edition of this title.
We guarantee the condition of every book as it¿s described on the Abebooks web sites. If you¿ve changed
your mind about a book that you¿ve ordered, please use the Ask bookseller a question link to contact us
and we¿ll respond within 2 business days.
Books ship from California and Michigan.
Orders usually ship within 2 business days. All books within the US ship free of charge. Delivery is 4-14 business days anywhere in the United States.
Books ship from California and Michigan.
If your book order is heavy or oversized, we may contact you to let you know extra shipping is required.
| Order quantity | 6 to 16 business days | 6 to 14 business days |
|---|---|---|
| First item | US$ 0.00 | US$ 0.00 |
Delivery times are set by sellers and vary by carrier and location. Orders passing through Customs may face delays and buyers are responsible for any associated duties or fees. Sellers may contact you regarding additional charges to cover any increased costs to ship your items.