Information System Security Engineering

This section contains various material on the subject of information system security engineering and risk management. The scope of "information system" includes what is currently known as "cyber-physical systems" as well as the more general term "cyber system" (since the word "Cyber", like a quantum bit, means both nothing and everything at the same time).



Teaching Aids

Threat and Risk Assessment

  • Threat Actor Categories. A capability scale for broadly describing threat actors. There are many equivalent scales and a few are mapped. This scale is based on that found in Table 5 of ITSG-33 published by the Communications Security Establishment.