Risk is a cost of doing business. The question is, "What are the risks, and what are their costs?" Knowing the vulnerabilities and threats that face your organization's information and systems is the first essential step in risk management.
Information Security Risk Analysis shows you how to use cost-effective risk analysis techniques to identify and quantify the threats--both accidental and purposeful--that your organization faces. The book steps you through the qualitative risk analysis process using techniques such as PARA (Practical Application of Risk Analysis) and FRAP (Facilitated Risk Analysis Process)
Although it is called information security risk analysis, this books also covers the adjacent physical risks.
Even if you don't agree with the techniques, it will expose you to the language used in the formal risk management domains.
Mr Peltier is a speaker at many conferences and I am sure he is up to date on the current state of affairs. This book was published in 2001 and represents the state of the art back then.