I'm pretty confident that impact is defined in NIST SP 800-53. That document covers a lot of the core security controls and concepts, so that's my best guess.
Okay, let me break this down. Quantitative risk assessment uses numerical data and analysis, while qualitative is more descriptive. Semi-quantitative seems to be a middle ground, so I'll focus on understanding that approach in more detail.
Developing an error budget policy with stakeholders sounds like a good proactive approach. That could help set clear expectations and guidelines for when to prioritize reliability over new features.
upvoted 0 times
...
Log in to Pass4Success
Sign in:
Report Comment
Is the comment made by USERNAME spam or abusive?
Commenting
In order to participate in the comments you need to be logged-in.
You can sign-up or
login
Salena
4 months agoBrigette
4 months agoMacy
4 months agoTeri
4 months agoErin
4 months agoTeresita
5 months agoSommer
5 months agoDominic
5 months agoHerschel
5 months agoCasie
5 months agoSarina
5 months agoWilda
5 months agoKendra
5 months ago