Network security experts discuss how to determine what’s important in your organization’s assets. The key is defining relative value of assets and how easy it is to replace them. If assets have few security controls or reside in an area that is easy to get to (such as Internet-facing servers), the criticality of its issues increases. The next step involves evaluating the ease of attacking these critical assets. Be brutally honest about that, because it will enable you to focus on brittle areas as needed as needed.”]
Source: http://www.securosis.com/blog/fact-based-network-security-defining-risk

