A security consultant is asked to evaluate risks using a scenario-based approach rather than asset-based. Which methodology best fits this requirement?
-
A
OCTAVE Allegro
-
B
Threat-centric risk assessment
-
C
Quantitative asset valuation
-
D
Control gap analysis