Skip to main content
BookintermediatePaid

Managing Cyber Risk

by Ariel Evans · Ariel Evans

Ariel Evans presents a three-part framework covering understanding, quantifying, and mitigating cyber risk, using ROLF (reputational, operational, legal, financial) analysis. Readers learn quantitative and qualitative methods for corporate risk oversight, prioritization, and resilience planning.

Visit resource

This link may earn us a small commission at no extra cost to you. Affiliate disclosure

More resources on Cybersecurity Governance

WebsiteFree

nist.gov/cyberframework

Official NIST Cybersecurity Framework hub explaining the CSF and how to use it for risk-based cybersecurity programs. It provides the framework core (Identify, Protect, Detect, Respond, Recover), implementation guidance, profiles, mappings to other standards, and downloadable resources.

WebsiteFree

SANS Institute Governance Papers

A searchable library of free SANS Institute white papers on cybersecurity governance topics such as policy development, risk management, and compliance frameworks, written by practitioners and reviewed through the SANS Reading Room submission process.

WebsiteFree

ISACA Cybersecurity Resources

ISACA's hub for cybersecurity governance resources, including white papers, the annual State of Cybersecurity workforce survey, training courses, and certification guidance for audit, risk, and information security professionals.

PodcastFree

CISO Series Podcast

Discussions, tips, and debates from security practitioners and vendors on how to work better together to improve security for themselves and everyone else.

WebsiteFree

isaca.org

ISACA is a global professional association focused on information governance, cybersecurity, risk management, and IT audit. It provides guidance, frameworks (notably COBIT), research, and training, plus certifications like CISA, CISM, and CGEIT to support cybersecurity governance and IT assurance.

BookPaid

Cybersecurity Program Development for Business

Chris Moschovitis, a cybersecurity consultant, walks business executives through building a cybersecurity program from risk assessment to governance roles and responsibilities, using plain language and case studies. Readers learn to evaluate organizational risk and make practical mitigation decisions.

See all Cybersecurity Governance resources →