Information-Centric Approach – Typically methodologies utilize a technology-centric approach. This approach is seen in industry in Common Criteria[2] and the (deprecated) Orange Book[3]. These methods of evaluating an information system for risk are excellent, but are unable to adapt gracefully as technology changes and matures, often resulting in large overhead costs to appropriately reevaluate the environment.The information-centric approach concerns itself with the informational assets and views the technology elements, along with policies and procedures and human factors (read training and awareness) as security measures to adequately secure the assets. The creator of the methodology, John McCumber, produces strong points of the technology independence of the approach by showing that it can be appropriately applied to Napolean and his field generals, an information system environment completely void of modern technology.