CRAMM
CRAMM (CCTA Risk Analysis and Management Method) is a risk management methodology, currently on its fifth version, CRAMM Version 5.0.
History
CRAMM was created in 1987 by the Central Computer and Telecommunications Agency (CCTA), now renamed into Cabinet Office, of the United Kingdom government.
Methodology
CRAMM comprises three stages, each supported by objective questionnaires and guidelines. The first two stages identify and analyze the risks to the system. The third stage recommends how these risks should be managed.
The three stages of CRAMM are as follows:
Stage 1
The establishment of the objectives for security by:
Defining the boundary for the study;
Identifying and valuing the physical assets that form part of the system;
Determining the 'value' of the data held by interviewing users about the potential business impacts that could arise from unavailability, destruction, disclosure or modification;
Identifying and valuing the software assets that form part of the system.
Stage 2