CRAMM (CCTA Risk Analysis and Management Method) is a risk management methodology, currently on its fifth version, CRAMM Version 5.0.
CRAMM was created in 1987 by the Central Computer and Telecommunications Agency (CCTA), now renamed into Cabinet Office, of the United Kingdom government.
CRAMM comprises three stages, each supported by objective questionnaires and guidelines. The first two stages identify and analyze the risks to the system. The third stage recommends how these risks should be managed.
The three stages of CRAMM are as follows:
The establishment of the objectives for security by:
One summer day she went away
Gone and left me, she's gone to stay
She's gone, I don't worry
I'm sitting on top of the world
All the summer worked all this fall
Had to take Christmas in my overalls
She's gone, but I don't worry
I'm sitting on top of the world
Going down to the freight yard
Gonna catch me a freight train
Going to leave this town
Worked and got to home
She's gone, but I don't worry