1. International Organization for Standardization. ISO 27002: code of practice for information security controls. ISO, 2013
2. International Organization for Standardization. ISO 27005: information security risk management. ISO, 2011
3. Federal Information Processing Standards. FIPS 65: guideline for automatic data processing risk analysis. US Department of Commerce, National Bureau of Standards, 1979
4. Radack S. Managing information security risk: organization, mission, and information system view. National Institute of Standards and Technology, 2011
5. Stoneburner G, Goguen A, Feringa A. Risk management guide for information technology systems. National Institute of Standards and Technology Special Publication, 2002