Information Security Risk Analysis will allow any organization to implement risk management techniques that will prove to be cost effective. Using the PARA (Practical Application of Risk Analysis) process the book examines the qualitative risk analysis process and then provides tested variations on the methodology. The PARA process can be used by information security professionals, project managers, auditing, physical security, facilities management, or any organization that needs to determine what direction the organization must take on a specific issue.
Although it is called information security risk analysis, this books also covers the adjacent physical risks.
Even if you don't agree with the techniques, it will expose you to the language used in the formal risk management domains.
Mr Peltier is a speaker at many conferences and I am sure he is up to date on the current state of affairs. This book was published in 2001 and represents the state of the art back then.