Heilmeier's Catechism
When George Heilmeier was the director of ARPA in the mid 1970s, he had a standard set of questions he expected every proposal for a new research program to answer. These have been called the Heilmeier Catechism. It's a good exercise to answer these questions for an individual research project, too, both for yourself and as a way to convey to others what you hope to accomplish. So here they are:
1. What is the problem, why is it hard?
2. How is it solved today?
3. What is the new technical idea; why can we succeed now?
4. What is the impact if successful?
5. How will the program be organized?
6. How will intermediate results be generated?
7. How will you measure progress?
8. What will it cost?
Of course, if you are proposing a small effort, like a class project or MS thesis, some of these questions should be adapted and modified (e.g., #5 and #8).
Version 0.1, created after meeting with Prof. McGill on May 8th. Better be done before mid of June. The list is not in formal reference format. Books
- Against the Gods
- The Black Swan
- The Failure of Risk Management
- Risk Intelligence
Papers
- Kaplan and Garrick, "On the Quantitative Definition of Risk." Risk Analysis, Vol. 1, No. 1.
- Haimes, Y. Y. "Total Risk Management"
- Giovanni, "What is Security"
- Giovanni, "Is Security Utilitarian"
- Giovanni, "Risk and Security, Are They Compatible Concepts?"
- Giovanni, "The Management of Security, How Robust Is the Justification Process"
- Qualitative Risk Assessment, the book chapter
- How useful is quantitative risk assessment
- Kaplan, S., and Garrick, B. J. (1981). “On the Quantitative Definition of Risk.” Risk
Analysis, Vol. 1, No. 1, pp. 11-27. - The decision guidance paper
- Pate-Cornell, E., and Guikema, S. (2002). “Probabilistic Modeling of Terrorist Threats: A
Systems Analysis Approach to Setting Priorities Among Countermeasures.”
Military Operations Research, Vol. 7, No. 4, pp. 5-23. - Frank Knight, Risk, Uncertainty and Profit
- Giovanni, Defining Security
- The politics of security
- McGill, W. L., and Ayyub, B. M. (2007b). “The Meaning of Vulnerability in the Context
of Critical Infrastructure Protection.” in Jackson, E. ed. Critical Infrastructure
Protection: Elements of Risk. George Mason University Critical Infrastructure
Protection Program. - Executive Guide: Information Security Management: Learning From Leading Organizations. (GAO/AIMD-98-68, May 1998)
- Information Security Risk Assessment: Practices of Leading Organizations. GAO/AIMD-00-33
- CERT report
- Windoes of vulnerability, a case study analysis.
- Guidelines for automatic data processing physical security and risk management
- Guideline for the analysis of local area network security
- NIST, risk management guide draft
- AS/NZS 4360:1999 Risk Management
- Information Security is Information RIsk Management
- Wash-1400
-
最新评论