0% found this document useful (0 votes)
4 views90 pages

Cyb 303 Lecture - I

The document outlines the course CYB 303 - Cybersecurity Risks Analysis, Challenges and Mitigation, focusing on principles of information security risk management including risk identification, assessment, and mitigation strategies. It details various frameworks such as NIST RMF, ISO/IEC 27005, and COBIT, emphasizing the importance of structured risk management processes. Additionally, it covers types of risks, components of risk, and methodologies for threat modeling to enhance organizational security.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views90 pages

Cyb 303 Lecture - I

The document outlines the course CYB 303 - Cybersecurity Risks Analysis, Challenges and Mitigation, focusing on principles of information security risk management including risk identification, assessment, and mitigation strategies. It details various frameworks such as NIST RMF, ISO/IEC 27005, and COBIT, emphasizing the importance of structured risk management processes. Additionally, it covers types of risks, components of risk, and methodologies for threat modeling to enhance organizational security.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

300 Level- BSc.

Cybersecurity

Kulugh Victor Emmanuel


Department of Computer Science, Bingham
University, Karu, Nigeria

CYB 303 – Cybersecurity Risks Analysis, Challenges and Mitigation


Course Objectives
This course introduces you to the principles and practices of information
security risk analysis and management. It covers risk identification, assessment,
mitigation, and monitoring techniques, as well as frameworks, standards, and
tools used in the field. Students will learn how to apply risk management
strategies to protect information assets and ensure compliance with relevant
regulations.
Objectives
❖ Understand the fundamental concepts of information security risk.
❖ Identify and assess risks to information systems.
❖ Apply risk analysis methodologies and tools.
❖ Design and implement risk mitigation strategies.
❖ Align risk management practices with legal, regulatory, and organizational
frameworks.
❖ Develop risk management plans and communicate findings to stakeholders.
Course Outline
▪ Introduction to Information Security Risk ▪ Risk Evaluation and Prioritization
Management
Determining risk levels, setting risk appetite and tolerance,
Definitions, types of risk, components of risk (threats, prioritizing mitigation efforts
vulnerabilities, impacts) ▪ Risk Treatment and Mitigation Strategies
▪ Risk Management Frameworks and Standards Options such as avoidance, reduction, transfer, and
Overview of NIST RMF, ISO/IEC 27005, COBIT acceptance
▪ Security Controls and Countermeasures
▪ Risk Identification
Types of controls: technical, administrative, and physical;
Techniques for identifying assets, threats, vulnerabilities; control effectiveness
introduction to threat modeling
▪ Risk Monitoring and Review
▪ Qualitative Risk Assessment
Continuous risk assessment, metrics, dashboards, and
Risk matrices, risk ranking, expert-based assessments improvement strategies
▪ Quantitative Risk Assessment ▪ Legal, Ethical, and Regulatory Considerations
Calculating Annualized Loss Expectancy (ALE), Single GDPR, HIPAA, NDPR, and other legal frameworks
Loss Expectancy (SLE), exposure factor impacting risk management

▪ Risk Analysis Tools and Techniques ▪ Developing a Risk Management Plan


Writing risk registers, communication plans, and presenting
Overview of OCTAVE, FAIR, and hands-on use of risk
risk assessments
assessment tools
Introduction to Information Security Risk Management

▪ Information is a critical asset in modern organizations.

▪ The protection of information and information systems


from various risks is essential to ensure business
continuity, data integrity, confidentiality, and legal
compliance.

▪ Information security risk management provides a


structured approach to identifying, assessing, and
mitigating risks to information assets.
Introduction to Information Security Risk Management
Risk: The potential for loss or damage when a threat exploits a
vulnerability in an information asset. It is often expressed as a
combination of the likelihood of an event and its consequences
(Impact).
Information Security Risk: The risk associated with the unauthorized
access, use, disclosure, disruption, modification, or destruction of
information or information systems.

Risk Management: A systematic process of identifying, assessing,


treating, and monitoring risks. The goal is to reduce the
likelihood and/or impact of adverse events on information
assets.
Introduction to Information Security Risk Management – Types of Risk

Understanding different types of risk helps in developing appropriate mitigation


strategies. In the context of information security, risks can be categorized as:

❖ Strategic Risk
▪ Related to long-term organizational goals and decisions.
▪ Example: A decision to adopt a new cloud platform without thorough security
evaluation.

❖ Operational Risk
▪ Originates from failed internal processes, systems, or human errors.
▪ Example: Accidental deletion of files due to poor backup procedures.

❖ Compliance or Legal Risk


▪ Results from violations of laws, regulations, or standards.
▪ Example: Failure to comply with data protection laws like GDPR or NDPR.
Introduction to Information Security Risk Management – Types of Risk – cont’d

❖ Financial Risk
▪ Involves monetary loss due to security breaches.
▪ Example: A ransomware attack resulting in financial extortion or business
downtime.

❖ Reputational Risk
▪ Affects the organization’s image or public trust.
▪ Example: A data breach becoming public and leading to loss of customer
confidence.

❖ Technical/Cybersecurity Risk
▪ Specific to threats that exploit weaknesses in IT infrastructure.
▪ Example: SQL injection vulnerability exploited by hackers.
Introduction to Information Security Risk Management – Components of Risk

To fully understand a security risk, we must consider its five key


components:

▪ Assets - A digital assets are data, system, or technology resource with


value to an organization and must be protected as part of
cybersecurity risk management. They include items such as hardware
and network equipment, databases, software applications,
intellectual property, cloud storage, customer information, and digital
infrastructure.

▪ Threats - A threat is any event or entity that can potentially exploit a


vulnerability in an asset to cause harm. Examples: Natural threats
(e.g., floods, earthquakes); Technical threats (e.g., malware, system
failures) and Human threats (e.g., insider attacks, social engineering)
Introduction to Information Security Risk Management – Components of Risk – cont’d

▪ Vulnerabilities - A vulnerability is a flaw or weakness in a system, process,


or control that can be exploited by a threat. Examples: Outdated software;
Poor access control; Weak passwords and Misconfigured network devices

▪ Impacts - Impact refers to the consequence of a threat exploiting a


vulnerability in an asset. Examples: Confidentiality breach (e.g., data leak);
Integrity violation (e.g., unauthorized data alteration; Availability
disruption (e.g., denial of service) and Financial and reputational loss.

▪ likelihood - refers to the probability that a specific threat will successfully


exploit a vulnerability and cause harm to an organization’s digital assets or
operations. It measures how often or how easily an adverse event—such as a
data breach, malware infection, or insider attack—might occur, given
existing controls and threat conditions.
Risk Management Frameworks and Standards
Risk management frameworks and standards provide structured
methodologies that guide organizations in managing information security
risks systematically and consistently. These frameworks are essential in
aligning security practices with business objectives, regulatory requirements,
and industry best practices.

Importance of Risk Management Frameworks


▪ Consistency: Provide standardized approaches to identifying and
mitigating risks.
▪ Compliance: Help meet legal and regulatory obligations (e.g., GDPR,
HIPAA, NDPA’23).
▪ Efficiency: Streamline risk processes and reduce redundant efforts.
▪ Integration: Align risk management with governance, business strategy,
and IT operations.
NIST Risk Management Framework (RMF)
Developed by National Institute of Standards and Technology (USA)
Key Reference: NIST SP 800-37 (Rev. 2)
Purpose
The NIST RMF provides a structured and repeatable process for integrating information
security, privacy, and risk management into the system development life cycle.

Core Steps of NIST RMF


▪ Prepare – Establish context, resources, and risk appetite.
▪ Categorize – Define system types and information sensitivity.
▪ Select – Choose appropriate security controls based on risk and impact.
▪ Implement – Apply and configure selected controls.
▪ Assess – Evaluate if controls are correctly implemented and effective.
▪ Authorize – Senior officials determine if risk is acceptable to operate.
▪ Monitor – Continuously assess control effectiveness and respond to changes.
(Refer to the NIST SP 800-37 (Rev. 2) document shared in the class for details of each of these steps.)

Key Features
❖ Emphasizes continuous monitoring and risk-based decision-making.
❖ Widely used in U.S. federal agencies and increasingly adopted by private institutions.
ISO/IEC 27005
Published by International Organization for Standardization (ISO) and International
Electrotechnical Commission (IEC)
Key Reference: ISO/IEC 27005:2018, ISO/IEC 27005:2022
Purpose
Provides guidelines for information security risk management to support the requirements of an
Information Security Management System (ISMS) based on ISO/IEC 27001.
Risk Management Process (Based on ISO 27005):
▪ Risk Context Establishment – Define scope, objectives, and criteria.
▪ Risk Identification – Identify assets, threats and vulnerabilities.
▪ Risk Analysis – Assess likelihood and consequences of threats exploiting vulnerabilities.
▪ Risk Evaluation – Compare risks with risk criteria to prioritize.
▪ Risk Treatment – Apply controls to reduce, avoid, transfer, or accept risks.
▪ Risk Acceptance and Communication – Decide which risks are acceptable and communicate
findings.
▪ Risk Monitoring and Review – Ensure the risk environment is continuously observed.
(Refer to the ISO/IEC 27005:2022 document shared in the class for details of each step)
Key Features
❖ Supports qualitative and quantitative risk assessment.
❖ Integrated with ISO/IEC 27001, making it ideal for organizations implementing an ISMS.
❖ Adaptable to various organizational sizes and sectors.
COBIT (Control Objectives for Information and Related Technologies)
Developed by ISACA (Information Systems Audit and Control Association)
Latest Version: COBIT 2019
Purpose
COBIT is a comprehensive framework for the governance and management of enterprise IT,
including risk management.
COBIT’s Risk Perspective Includes
▪ Aligning IT risk management with overall enterprise governance.
• Identifying risk categories: IT-related risks, compliance risks, and strategic risks.
• Establishing goals and metrics for measuring IT risk management effectiveness.
Relevant COBIT Components
• Governance and Management Objectives – Includes DSS04 (Manage Continuity) and APO12
(Manage Risk).
• Performance Management – Uses maturity models to evaluate risk processes.
• Process Enablers – Help design and implement controls for IT-related risk.
Key Features:
• Strong emphasis on business alignment and strategic governance.
• Suitable for enterprise-level IT governance, not just technical risk management.
• Often used in audit and compliance contexts.
Comparative Summary
Aspect NIST RMF ISO/IEC 27005 COBIT
Information system- Enterprise IT
Focus ISMS-level risk
level risk governance and risk

Prescriptive, step- Flexible, guideline-


Approach Governance-driven
based based
Region/Use Predominantly U.S. International Global
ISO/IEC 27001 Business strategy
Integration NIST SP 800 series
family and compliance

Enterprises,
Government, Broad (finance,
Industry Adoption auditors,
healthcare telecom, etc.)
consultants
Risk Identification

Risk identification is the foundational step in the risk management


process. It involves discovering and documenting the information
assets that need protection, the threats they face, and the
vulnerabilities that could be exploited. Effective identification
enables accurate risk assessment and efficient mitigation planning.

Objectives of Risk Identification


▪ To understand what needs to be protected (assets)
▪ To determine what could harm these assets (threats)
▪ To discover weaknesses that could be exploited by the threats
(vulnerabilities)
▪ To lay the groundwork for further risk analysis and treatment
Assets Identification
Assets are anything of value to the organization, and they may be tangible or
intangible. Asset identification helps prioritize what needs protection.

Types of Assets
▪ Information Assets: Databases, documents, source code, customer data
▪ Hardware Assets: Servers, routers, laptops, mobile devices
▪ Software Assets: Applications, operating systems, development tools
▪ Personnel: Employees, contractors, system administrators
▪ Reputation and Intellectual Property: copyrighted works, patents, trademarks,
trade secrets, industrial designs, etc.,

Identification Techniques
▪ Asset Inventory Audits: Use of automated tools to discover and list assets.
▪ Interviews and Questionnaires: Consulting department heads or IT staff.
▪ Review of System Architecture: Mapping data flows and system components.
▪ Classification Schemes: Tagging assets by sensitivity, criticality, or compliance
relevance.
Information Asset Inventory creation (contd.)
▪ Potential asset attributes – (hardware/software)
• Name
• Asset tag
• IP address
• MAC address
• asset type
• Serial number
• manufacturer name
• Manufacturer’s model or part number
• Software version, update revision, or FCO number
• Physical location, logical location
• Controlling entity
Fault Condition Occurrence (FCO) number, which is a code used to identify and track specific types of errors or faults that
occur within a system. These numbers help in diagnosing and resolving problems more efficiently. FCOs are often related to
system17 failures, errors, or anomalies detected during operation.
Information Asset Inventory creation (contd.)
Identifying people, procedures and data assets. Sample
attributes for people, procedures, and data assets

▪ People
• Position name/number/ID
• Supervisor name/number/ID
• Security clearance level
• Special skills

18
Information Asset Inventory creation (contd.)
• Sample attributes for people, procedures, and
data assets (cont’d.)

▪ Procedures
• Description
• Intended purpose
Software/hardware/networking elements to
which it is tied
• Location where it is stored for reference
• Location where it is stored for update
purposes
19
Information Asset Inventory creation (contd.)
• Sample attributes for people, procedures, and data
assets (cont’d.)

▪ Data
• Classification
• Owner/creator/manager
• Size of data structure
• Data structure used
• Online or offline
• Location
20 • Backup procedures
Assets Ranking: Classification and Categorization Assets
▪ Determine the values of assets
▪ Prioritize according to value

• Determine/refine an asset classification scheme


• A classification scheme categorizes information assets based on
their sensitivity, security needs
• Each category designates the level of protection needed for a
particular information asset
• Some asset types, such as personnel, may require an alternative
classification scheme
• Classification categories must be comprehensive and mutually
exclusive
21
Assessing Values for Information Assets
• Assign a relative value: Comparative judgments made to ensure that the most
valuable information assets are given the highest priority

Assessing Values for Information Assets – Questions


1. Which asset is the most critical to the success of the organization?
2. Which asset generates the most revenue?
3. Which asset generates the highest profitability?
4. Which asset is the most expensive to replace?
5. Which asset is the most expensive to protect?
6. Which asset’s loss or compromise would be the most embarrassing or
cause the greatest liability?

22
Sample asset classification worksheet

23
Listing Assets in Order of Importance
achieved by using a weighted factor analysis worksheet

24

Example weighted factor analysis worksheet


Threats Identification
Threats are potential causes of unwanted incidents that may result in harm to a
system or organization.

Categories of Threats
▪ Natural: Earthquakes, floods, fires
▪ Technical: System failures, software bugs, power outages
▪ Human (Malicious): Hackers, insiders, cybercriminals
▪ Human (Accidental): Employee errors, misconfigurations

Identification Techniques
▪ Historical Data Analysis: Reviewing past incidents and breach reports.
▪ Threat Intelligence Feeds: Subscribing to databases or feeds (e.g., MITRE
ATT&CK).
▪ Brainstorming and Expert Workshops: Engaging stakeholders to identify threats.
▪ Scenario Analysis: Creating hypothetical but realistic threat scenarios.
Threat Modeling
Threat modeling is the structured process of identifying, enumerating, and
prioritizing potential threats to a system, and documenting the measures needed
to mitigate or manage those threats.
Importance
▪ Enables proactive security design
▪ Helps in resource allocation
▪ Supports compliance and risk management
▪ Improves overall system resilience
▪ Understand the system from an attacker’s perspective
▪ Identify potential attack vectors
▪ Prioritize threats based on risk
Threat Modeling Approaches
▪ Asset-Centric - Focuses on protecting valuable assets (data, resources, systems).
▪ Attacker-Centric - Considers possible attack vectors and adversaries.
▪ System-Centric - Evaluates threats based on system architecture and workflows.
Key Frameworks and Methodologies for Threat Modelling
STRIDE is Microsoft designed framework for threat modeling and stands for
and addresses the following threats.
# Threat Description
1 Spoofing Impersonating users or systems
2 Tampering Altering data or code
3 Repudiation Denying actions
4 Information Disclosure Unauthorized data access
5 Denial of Service Making systems unavailable
6 Elevation of Privilege Gaining unauthorized access
Key Frameworks and Methodologies for Threat Modelling
DREAD for risk rating

# Threat Description
1 Damage potential How severe is the damage?
2 Reproducibility How easily can the attack be repeated?
3 Exploitability How easy is it to exploit the threat?
4 Affected users How many users are impacted?
5 Discoverability How easy is it to find the vulnerability?

PASTA (Process for Attack Simulation and Threat Analysis) - A risk-centric


methodology focusing on business impact.
Attack Trees: Diagrams that represent how an asset can be attacked
step-by-step.
Threat Modeling Process
Define
security
objectives

Define and
Create and
apply
architectural
mitigation
overview
strategies

Rate the threat


using a risk Decompose
scoring system the system
(e.g. DREAD)

Identify threats
using a known
Framework (e.g.
STRIDE)
Threat Identification
▪ Typically: wide variety of threats; each threat presents a
unique challenge to information security

Questions:
▪ Which threats present a danger to your company’s
information assets?
• reduce scope and cost of risk management

▪ Which threats present the gravest danger to your


company’s information assets?
• Rough assessment of severity of threat
30
Threat Identification (cont’d.)

31
Threats Prioritisation
Severity of threat: catastrophic, major, moderate, minor,
insignificant

32
Threats Prioritisation (cont’d)

Probability of threat: negligible to extreme

33
Vulnerability Identification
Vulnerabilities are weaknesses or flaws in a system (asset) that could be exploited by
a threat.

Sources of Vulnerabilities
▪ Software bugs or outdated software
▪ Poor access control
▪ Weak passwords
▪ Misconfigured firewalls or routers
▪ Lack of employee training

Identification Techniques
▪ Vulnerability Scanning Tools: Tools like Nessus, OpenVAS, Qualys.
▪ Security Audits and Penetration Testing: Manual and automated testing.
▪ Code Reviews: Reviewing source code for security issues.
▪ Configuration Reviews: Checking system and network settings.
▪ Security Checklists and Standards: NIST, CIS Benchmarks.
Vulnerability Assessment
Vulnerability
flaw or weakness in an asset that can be exploited to breach
security
▪ Begin to review every information asset and its
vulnerability
▪ leads to the creation of a list of vulnerabilities that
remain potential risks to the organization
▪ At the end of the risk identification process, a list of
assets and their vulnerabilities has been developed
▪ This list serves as the starting point for the next step in
the risk management process - risk assessment
Some assets have known vulnerabilities that are recorded in the common vulnerabilities and
exposure
35
(CVE) database and nations’ vulnerability databases (e.g, the USA has a national
vulnerability databse (NVD)
Vulnerability Assessment (cont’d)
Examples:

1. Asset: email servers,


• vulnerability: antivirus software not updated,
• threat: virus attack

2. Asset: router,
• vulnerability: incorrect router configuration,
• threat: network susceptible to reduction or loss of
36 connectivity
Vulnerability Assessment (contd.)

37

Vulnerability assessment of a DMZ router


Likelihood and Consequences (contd.)
• Consequences and likelihoods are combined

• The resulting rankings can then be inserted into the


TVA tables for use in risk assessment
38

TVA: Threat-Vulnerability-Asset
The TVA Worksheet
▪ At the end of the risk identification process, a list
of assets and their vulnerabilities has been
developed
▪ Another list prioritizes threats facing the
organization based on the weighted table discussed
earlier
▪ These lists can be combined into a single
worksheet

39
Introduction to Qualitative Risk Assessment

Qualitative Risk Assessment is a method of evaluating risks


based on descriptive categories (e.g., high, medium, low)
rather than numerical values. It relies on subjective
judgment, expert opinion, and risk scenarios to prioritize
and communicate risks in a clear and actionable way.

This method is often used when:


▪ There is insufficient data for quantitative analysis
▪ Quick decision-making is required
▪ Risks are complex or context-dependent
40
Risk Matrices – cont’d
Steps in Using a Risk Matrix
▪ Identify risks (threats + vulnerabilities).
▪ Assign a likelihood rating (e.g., Rare, Possible, Likely).
▪ Assign an impact rating (e.g., Minor, Moderate, Severe).
▪ Cross-reference in the matrix to assign a risk level (Low, Medium, High, Critical).
▪ Use the result to determine risk response priorities.

Advantages
▪ Easy to understand and communicate
▪ Quick to implement
▪ Useful for high-level decision making

Limitations
▪ Subjective classifications
▪ May oversimplify complex risks
▪ Not
41
suitable for detailed cost-benefit analysis
Risk Ranking
Risk ranking - involves arranging identified risks in order of priority based on their
assessed severity (impact and likelihood combined).
Ranking Techniques
Ordinal Scales: Assign scores (e.g., 1 to 5) for impact and likelihood and multiply for
a risk score.
Example:
▪ Likelihood = 4 (Likely)
▪ Impact = 3 (Moderate)
▪ Risk Score = 4 × 3 = 12
Custom Risk Scoring Models: Incorporate other factors like detectability, business
impact, or duration.
Application
▪ Used in risk registers or risk logs
▪ Helps
42 in identifying top risks that need urgent attention
▪ Supports decision-making in resource allocation and risk mitigation planning
Risk Matrices
Risk Matrices - A risk matrix (or risk heat map) is a graphical
representation used to assess and prioritize risks based on their
likelihood and impact.
Likelihood Impact
Insignificant - Minor - Moderate - Major Catastrophic
1 2 3 -4 -5
Rare - 1 (1,1) (1,2) (1,3) (1,4) (1,5)
Unlikely - 2 (2,1) (2,2) (2,3) (2,4) (2,5)
Possible - 3 (3,1) (3,2) (3,3) (3,4) (3,5)
Likely - 4 (4,1) (4,2) (4,3) (4,4) (4,5)
Almost (5,1) (5,2) (5,3) (5,4) (5,5)
certain - 5
Risk Score = Likelihood x Impact
Expert-Based Assessments
Expert-based assessment leverages the knowledge and experience of subject matter experts
(SMEs) to evaluate risks, particularly when data is limited or ambiguous.
Common Methods
▪ Interviews: Direct discussions with stakeholders or technical experts
▪ Workshops: Collaborative sessions using brainstorming or SWOT analysis
▪ Delphi Technique: A structured method where multiple rounds of expert opinion are gathered
anonymously and refined
▪ Surveys/Questionnaires: Distributed tools for collecting risk perceptions from many
participants
Benefits
▪ Taps into domain knowledge not found in documents
▪ Enhances risk identification and validation
▪ Supports context-aware risk prioritization
Challenges
▪ Bias and subjectivity
▪ Requires experienced and credible experts
44
▪ Consensus can be difficult in diverse teams
Introduction to Quantitative Risk Assessment

Quantitative Risk Assessment (QRA) involves using numerical


methods to estimate the potential financial impact of risks. Unlike
qualitative assessments that use descriptive labels (e.g., high,
medium, low), quantitative methods rely on mathematical models to
express risk in monetary terms.

Purpose
▪ Justify security investments using cost-benefit analysis
▪ Estimate potential financial losses due to risks
▪ Enable data-driven decision-making
45
Concepts and Formula

Single Loss Expectancy (SLE) - SLE is the expected monetary loss every time a risk
event (e.g., cyberattack, equipment failure) occurs once.
Formula:
SLE=Asset Value (AV)×Exposure Factor (EF)
SLE = AV x EF
▪ Asset Value (AV): The monetary value of the asset at risk.
▪ Exposure Factor (EF): The percentage of asset loss due to a specific threat
(range: 0 to 1).
Example:
If a server worth $50,000 is estimated to lose 40% of its value in a data breach:
SLE=$50,000×0.4=$20,000
46
Concepts and Formula
Exposure Factor (EF) - EF represents the proportion of an asset's value that is lost due
to a particular incident. It is based on expert judgment and historical data.

Scale
Ranges from 0.0 (no loss) to 1.0 (total loss) – (0.00 – 1.00

Example ratings
▪ EF = 0.1 → Minor damage (10%)
▪ EF = 0.5 → Moderate damage (50%)
▪ EF = 1.0 → Total loss (100%)

Factors Affecting EF
▪ Type and severity of threat
▪ Asset resilience
▪ Mitigation controls in place
47
Concepts and Formula
Annualized Rate of Occurrence (ARO) - ARO is the estimated frequency with which a risk
event is expected to occur in one year.
Examples
▪ ARO = 1 → Occurs once a year
▪ ARO = 0.1 → Occurs once every 10 years
▪ ARO = 3 → Occurs three times a year
Annualized Loss Expectancy (ALE) - ALE is the expected yearly financial loss due to a
risk.
Formula
ALE=SLE×ARO
Example:
Continuing from the previous example:
▪ SLE = $20,000
▪ ARO = 0.5 (once every two years)
ALE = SLE x ARO = 20,000 x 0.5 = 10,000
This means
48 the organization should expect an average loss of $10,000 per year from that
risk.
Use Cases, Advantages and Limitation
Use Cases
▪ Determining insurance coverage needs
▪ Justifying cybersecurity budgets
▪ Evaluating cost-effectiveness of risk controls

Decision Making
If a control costs less than the ALE it mitigates, it may be considered cost-effective.
Example:
If ALE = $50,000 and a new control reduces ARO by half and costs $10,000 annually, then:
• New ALE = $25,000
• Risk reduction benefit = $25,000
• Since benefit ($25k) > cost ($10k), the control is cost-effective.

Advantages
▪ Provides objective, data-driven results
▪ Enables ROI analysis for security investments
▪ Easy to integrate with budgeting and financial planning

Limitations
▪ Requires accurate and often unavailable data
49
▪ Estimations (e.g., ARO, EF) may be subjective
▪ Not suitable for all types of risk (e.g., reputational damage)
Risk Analysis Tools and Techniques
Risk analysis is a vital part of information security risk management. It helps
organizations identify, evaluate, and prioritize risks to assets. This lecture focuses on
widely adopted frameworks and tools for performing risk analysis in a structured and
repeatable manner.
OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation) is a risk-based
strategic assessment and planning technique for information security developed by CERT at
Carnegie Mellon University.

Key Characteristics
▪ Self-directed: Performed by an internal cross-functional team
▪ Focuses on organizational risks—not just IT risks
▪ Emphasizes operational impact and organizational context

OCTAVE Variants
▪ OCTAVE Classic – Suitable for large organizations
▪ OCTAVE-S
50 – Tailored for small organizations
▪ OCTAVE Allegro – Focuses on information assets and streamlines the process
OCTAVE – CONT’D
OCTAVE Allegro Process Steps
▪ Identify and prioritize information assets
▪ Identify threats to those assets
▪ Identify vulnerabilities and exposures
▪ Evaluate risks based on impact
▪ Develop mitigation strategies

Benefits
▪ Structured and comprehensive
▪ Customizable to organization size and needs
▪ Promotes collaboration between business and IT

51
FAIR
FAIR (Factor Analysis of Information Risk) is a quantitative risk analysis framework that
helps organizations understand and measure information risk in financial terms.

Key Elements
▪ Focuses on calculating probable loss magnitude and loss event frequency
▪ Uses taxonomy of risk components (e.g., threat actor capability, control strength,
asset value)
▪ Compatible with standards like NIST and ISO/IEC 27005

FAIR Process Overview


▪ Identify scenario (threat, asset, and effect)
▪ Evaluate Loss Event Frequency (LEF):
▪ Threat Event Frequency × Vulnerability
▪ Evaluate Probable Loss Magnitude (PLM):
▪ Primary loss (e.g., system downtime)
52
▪ Secondary loss (e.g., legal fees, reputation damage)
▪ Calculate Risk = LEF × PLM
FAIR – cont’d
Advantages of FAIR
▪ Converts risk into financial terms (e.g., expected annual loss)
▪ Enables cost-benefit analysis of controls
▪ Enhances communication with executives and stakeholders

Limitations
▪ Requires training and calibration
▪ Time-consuming without automated tools

53
Hands-on Risk Assessment Tools

Tool Purpose Key Features


Implements FAIR Cloud-based, financial risk
RiskLens
methodology modeling
Support for OCTAVE Templates and guides for
OCTAVE Toolkits
processes risk workshops
Microsoft Threat Modeling Threat modeling (not just DFD-based, automated
Tool risk) threat identification
Web-based platform,
Simple Risk General risk management
integrates with standards
OpenFAIR Tools (Excel- Manual calculations and
FAIR analysis
based) modeling

54
Risk Evaluation and Prioritization

▪ Once risks have been identified and analyzed, they must be evaluated and
prioritized to determine which requires action and what level of response is
appropriate. This ensures that organizational resources are focused where they
are needed most — on risks that matter.
▪ Risk evaluation involves comparing assessed risk levels against predefined risk
criteria, such as risk appetite and tolerance, and determining the urgency and
importance of response actions.

Determination of Risk Levels


A risk level is a numerical or categorical representation of a risk’s likelihood and
impact. It helps quantify the severity of a risk and facilitates comparison between
multiple risks.
55
Risk Evaluation and Prioritization
Risk Matrix
A risk matrix is a commonly used tool for visualizing and categorizing risks.
Low Impact Medium Impact High Impact
Low Likelihood Low Low Medium
Medium Likelihood Low Medium High
High Likelihood Medium High Critical

Risk Rating Formula

For quantitative assessment:


Risk Score = Likelihood × Impact

Example
Likelihood: 4 (on a scale of 1–5)
Impact: 5 (on a scale of 1–5)

Risk Score = 4 × 5 = 20
This score helps in categorizing the risk as Low, Medium, High, or Critical.
56
Setting Risk Appetite and Tolerance
Risk appetite is the amount or level of risk an organization is willing to accept in pursuit of its
objectives. It is a strategic decision defined by senior management.

Example: A fintech company may have a low-risk appetite for data breaches but a higher tolerance
for market-related financial risks.

Risk Tolerance
Risk tolerance defines the acceptable deviation from the risk appetite. It provides operational
boundaries for decision-making.

Example:
Risk Appetite: No more than 1% customer data loss.
Tolerance: Acceptable if the breach affects fewer than 100 customers.

Importance in Risk Evaluation


Helps determine whether a risk is acceptable or needs mitigation.
Aligns risk decisions with organizational objectives and regulatory requirements.

57
Prioritizing Mitigation Efforts
Why Prioritize?
▪ Limited resources (time, budget, personnel).
▪ Some risks pose more immediate or severe threats.
▪ High-impact, high-likelihood risks require urgent attention.

Prioritization Criteria
▪ Risk Score (Likelihood × Impact)
▪ Legal or regulatory obligations
▪ Time sensitivity (e.g., threats with near-term consequences)
▪ Asset criticality (e.g., risks affecting mission-critical systems)
▪ Control effectiveness (are current controls sufficient or failing?)
Risk Treatment Priority Matrix
Risk Level Priority Action Required Example Mitigation Prioritization
Immediate Risk ID Description Score Priority Action
Critical Very High Ransomware Strengthen backups,
mitigation R1 20 High
Prompt treatment attack patching
High High Insider data Update access
planning R2 15 Medium
leak controls
Monitor and treat
Outdated
Medium Medium within reasonable R3 8 Low Scheduled update
58 antivirus
time
Low Low Accept or monitor
Risk Treatment and Mitigation Strategies

Risk Avoidance

Risk treatment refers to the


process of selecting and
implementing measures to Risk
Exploitation
Risk Mitigation

modify risk. It involves


deciding how to respond to
identified risks, whether by
reducing, avoiding,
transferring, or accepting
them. The goal is to bring the Risk Sharing Risk Transfer
risk within acceptable levels
that align with an
organization's risk appetite. Risk Acceptance
Risk Avoidance
▪ This strategy involves taking actions to avoid activities that
introduce risks altogether. If the risk is deemed too high or
unmanageable, the organization may choose not to engage in
the activity or process that creates the risk.

▪ For instance, an organization decides not to develop a new web


application that would require collecting sensitive customer
information due to the high risk of data breaches.
• Application of policy
• Application of training and education
• Countering threats
60
• Implementation of technical security controls and safeguards
Risk Transfer
▪ This strategy involves transferring the risk to a third party,
often through insurance or outsourcing. The organization
pays a premium to an insurer or service provider who
assumes the risk on their behalf.

▪ Purchasing cybersecurity insurance to cover potential


financial losses from data breaches or partnering with a
managed security service provider (MSSP) to handle certain
security functions.
▪ Revising deployment models
▪ Outsourcing to other organizations
61▪ Purchasing insurance
▪ Implementing service contracts with providers
Risk Mitigation
▪ Also known as risk reduction, this strategy involves implementing
controls and measures to reduce the likelihood or impact of the risk.
The goal is to bring the risk to an acceptable level.

▪ Implementing firewalls, intrusion detection systems, encryption,


regular software updates, and employee training to reduce the risk of
cyber-attacks.

▪Types of mitigation plans


• Disaster recovery plan (DRP)
• Incident response plan (IRP)
• Business continuity plan (BCP)
62
Mitigation (cont’d.)

63
Summaries of mitigation plans
Acceptance
▪ Do nothing to protect an information asset
• To accept the loss when it occurs

▪ Assumes that it may be a prudent business decision


to examine the alternatives and conclude that the
cost of protecting an asset does not justify the
security expenditure

64
Acceptance (contd.)
▪ The organization must:
• Determine the level of risk to the information asset
• Assess the probability of attack and the likelihood of a
successful exploitation of a vulnerability
• Approximate the ARO of the exploit
• Estimate the potential loss from attacks
• Perform a thorough cost benefit analysis
• Evaluate controls using each appropriate type of feasibility
• Decide that the particular asset did not justify the cost of
protection

65
Risk Sharing
Risk sharing involves transferring part or all of the cyber risk to a third
party. This doesn't eliminate the risk but reduces the burden on the
organization. Common methods include:

▪ Cyber insurance – where an insurer covers financial losses due to


cyber incidents.
▪ Outsourcing or cloud services – where third-party providers assume
some responsibility for managing cybersecurity (e.g., managed
security service providers).
▪ Contracts and SLAs – which define how partners or vendors are
accountable for cybersecurity controls and incidents.

Example: A company purchases cyber insurance to cover potential losses


from data breaches or ransomware attacks.
Risk Exploitation
Risk exploitation is less common in cybersecurity but refers to taking
advantage of a positive risk (an opportunity) that arises from a
cyber-related scenario. It means actively pursuing a situation that
could bring benefits despite associated cyber risks.

Example: A company adopts cutting-edge cloud technologies to gain


competitive advantage, knowing it increases certain cyber risks, but
implements strong controls to manage those risks while leveraging
the business opportunity.
Security Controls and Countermeasures
Security controls and countermeasures are essential mechanisms used to protect
information systems against threats and vulnerabilities. They form the backbone of
an organization’s defense strategy in ensuring confidentiality, integrity, and
availability (CIA) of information assets. Security controls are typically classified into
three categories based on their nature and implementation: Technical,
Administrative and Physical.

Technical Controls (Logical Controls)


Controls that are implemented through hardware or software to protect systems and data to prevent
unauthorized access, detect malicious activity, and protect data in processing, storage or transit.

Examples
▪ Firewalls
▪ Intrusion Detection/Prevention Systems (IDS/IPS)
▪ Encryption
▪ Multi-Factor Authentication (MFA)
▪ Antivirus software
▪ Access
68 control lists (ACLs), etc
Security Controls and Countermeasures – Administrative Controls

Administrative Controls (Managerial Controls)


Policies, procedures, and practices that define organizational
security posture and personnel behaviour. The purpose is to guide
employee behaviour, ensure compliance, and manage risk
through governance.

Examples
▪ Security policies and procedures
▪ User training and awareness programs
▪ Risk assessments and audits
▪ Background checks
▪ Incident response plans
▪ Separation of duties
69
Security Controls and Countermeasures – Physical Controls

Physical Controls
Controls designed to prevent physical access to facilities, systems,
or information. The purpose is to prevent unauthorized physical
access, theft, or damage to physical infrastructure and assets.

Examples:
▪ Locked doors and cabinets
▪ Security guards
▪ Surveillance cameras (CCTV)
▪ Biometric access control
▪ Environmental controls (fire suppression, HVAC)
70
Security Controls and Countermeasures – Control Effectiveness
Control Effectiveness
Control effectiveness refers to how well a security control mitigates the
associated risks or reduces the likelihood and/or impact of a threat
exploiting a vulnerability.
Factors Influencing Control Effectiveness:
Appropriateness: Is the control suited to the risk and the environment?
Correct Implementation: Was the control configured and deployed
correctly?
Coverage: Does it cover all applicable assets and threat vectors?
Timeliness: Is it applied in a timely manner (e.g., patching
vulnerabilities)?
Monitoring and Maintenance: Are the controls regularly updated and
monitored?
71
Security Controls and Countermeasures – Measuring Control Effectiveness

Measuring Control Effectiveness


Testing how well the controls that have been put in place are
working to mitigate risk on the assets.
Control effectiveness can be assessed using:
▪ Security audits
▪ Penetration testing
▪ Vulnerability scans
▪ Key Performance Indicators (KPIs)
▪ Risk assessments using frameworks like NIST, ISO/IEC 27001, or
FAIR
72
Security Controls and Countermeasures – Measuring Control Effectiveness
Summary
Type of Control Focus Area Examples Key Benefit
Automation,
Systems and data Firewalls,
Technical scalable
protection Encryption, IDS
enforcement
Governance and
Policies and Training, Policies,
Administrative human risk
processes Risk Assessment
reduction
Asset protection
Facility and Locks, Guards,
Physical from physical
equipment CCTV
73
threats
Risk Monitoring and Review

Risk monitoring and review is a critical phase in the risk management lifecycle. It
ensures that identified risks are being managed effectively, that controls remain
appropriate, and that new or evolving threats are promptly addressed. This is a
continuous process that supports decision-making, compliance, and organizational
resilience.
Continuous Risk Assessment
Continuous risk assessment refers to the ongoing process of identifying, analyzing,
and evaluating risks in real-time or near real-time, rather than at fixed intervals.

Importance
▪ Keeps up with rapidly changing threat landscapes.
▪ Detects emerging risks early.
▪ Maintains the relevance of risk treatment plans.
▪ Enables
74 proactive, rather than reactive, risk management.
Risk Monitoring and Review – Continuous Risk Assessment
Methods of Continuous Risk Assessment
▪ Real-time monitoring of systems and networks.
▪ Automated tools for threat intelligence and vulnerability scanning.
▪ Continuous compliance assessments (e.g., through GRC tools).
▪ Feedback loops from incident response activities.

75
Risk Monitoring and Review – Risk Metrics
Risk Metrics
Risk metrics are quantitative or qualitative indicators used to assess the status and effectiveness of risk
management efforts.

Common Risk Metrics

Metric Description

Number of incidents Frequency of security or risk events.

Mean time to detect (MTTD) Average time to identify a risk or incident.

Mean time to respond (MTTR) Average time taken to mitigate a risk.

Risk exposure level Assessed severity based on impact × likelihood.

Control effectiveness score Evaluation of how well a control mitigates risk.

Risk treatment
76 progress % of risks mitigated or under treatment.
Risk Monitoring and Review – Dashboards of Risk Management
Dashboards for Risk Management

A risk dashboard is a visual interface displaying real-time data and risk indicators
to support monitoring and decision-making.

Key Features
Traffic-light indicators for risk status (Red-Amber-Green)
Drill-down capability to see risk details
Trending charts and heatmaps
Alerts for threshold breaches
Integration with tools (SIEM, GRC, ticketing systems)

Benefits
Facilitates executive-level oversight.
Improves
77
communication between security teams and management.
Enables timely action on risk indicators.
Risk Monitoring and Review – Improvement Strategies
Improvement Strategies

Lessons Learned
After incidents or near misses, analyze causes and update risk treatment plans accordingly.

Control Optimization
Regularly test and update security controls to maintain or improve their effectiveness (e.g., red
teaming, control tuning).

Training and Awareness


Conduct regular staff training to improve the human aspect of risk management.

Risk Appetite Adjustment


Periodically revisit and adjust the organization's risk appetite and thresholds as business objectives
evolve.

Use of Standards and Frameworks


Adopt and benchmark against industry standards such as:
NIST 78Cybersecurity Framework (CSF)
ISO/IEC 27005 (Risk Management)
FAIR Model
Legal, Ethical, and Regulatory Considerations
cyber risk management is not only a technical process but also one deeply rooted in legal, ethical, and
regulatory obligations. Organizations must ensure compliance with laws and standards that govern data
protection, privacy, and information security. Failure to comply can lead to significant legal liabilities,
financial penalties, and reputational damage.

General Data Protection Regulation (GDPR) – European Union


Enacted: May 25, 2018
Scope: Applies to all organizations processing the personal data of EU citizens, regardless of location.

Key Provisions
▪ Lawful, fair, and transparent data processing.
▪ Rights of data subjects (access, rectification, erasure).
▪ Mandatory breach notification within 72 hours.
▪ Appointment of a Data Protection Officer (DPO) for certain organizations.
▪ Data Protection Impact Assessment (DPIA).
Implications for Risk Management
▪ Requires organizations to assess and mitigate privacy risks proactively.
▪ Non-compliance risks include fines of up to €20 million or 4% of annual global turnover.
▪ Encourages
79
privacy by design and by default principles.
Legal, Ethical, and Regulatory Considerations - HIPAA
Health Insurance Portability and Accountability Act (HIPAA) – United States
Enacted: 1996
Scope: Applies to healthcare providers, health plans, and their business associates in
the U.S.

Key Provisions
▪ Protects the confidentiality, integrity, and availability of Protected Health
Information (PHI).
▪ The HIPAA Security Rule mandates administrative, physical, and technical
safeguards.
▪ Breach notification requirements under the HITECH Act.

Implications for Risk Management


▪ Requires formal risk assessments and security management processes.
▪ Violations may lead to civil and criminal penalties.
▪ Enforcement
80
by the Department of Health and Human Services (HHS).
Legal, Ethical, and Regulatory Considerations - NDPR
Nigeria Data Protection Regulation (NDPR) – Nigeria

Enacted: January 2019 by the National Information Technology Development Agency


(NITDA).
Scope: Applies to all organizations processing the personal data of Nigerian citizens.

Key Provisions
▪ Consent-based data processing.
▪ Rights to access, rectification, and erasure of personal data.
▪ Requirement for a Data Protection Officer (DPO).
▪ Mandatory data audits and filing of compliance reports.

Implications for Risk Management


▪ Organizations must develop and implement data protection policies.
▪ Regular risk assessments to identify and mitigate data privacy risks.
▪ Non-compliance
81
may result in fines of up to 2% of annual gross revenue.
Legal, Ethical, and Regulatory Considerations - Other Relevant Frameworks
a. ISO/IEC 27001
▪ International standard for Information Security Management Systems (ISMS).
▪ Encourages risk-based approach to securing information assets.
▪ Supports regulatory compliance efforts globally.

b. NIST Cybersecurity Framework (CSF) – U.S.


▪ Provides guidelines for identifying, protecting, detecting, responding to, and
recovering from cyber incidents.
▪ Helps align cybersecurity strategies with risk management and compliance
requirements.

c. PCI DSS (Payment Card Industry Data Security Standard)


▪ Applies to organizations that handle credit card transactions.
▪ Focuses on protecting cardholder data and reducing fraud risks.

82
Ethical Considerations in Cyber Risk Management
Definition
Ethical considerations involve understanding what is right or wrong beyond legal
compliance. It addresses responsibilities to stakeholders, transparency, fairness, and
respect for privacy.

Common Ethical Issues


▪ Invasive surveillance of employees or users.
▪ Exploiting personal data without informed consent.
▪ Failure to disclose data breaches promptly.
▪ Unethical use of AI in monitoring or decision-making.

Ethical Principles
▪ Confidentiality – Respect and protect user data.
▪ Integrity – Avoid manipulating or misrepresenting data.
▪ Accountability – Be responsible for decisions and actions.
▪ Transparency
83
– Inform stakeholders about data practices and risks.
Integrating Legal, Ethical, and Regulatory Considerations in Risk Management
Key Strategies
▪ Compliance mapping – Align organizational practices with applicable laws and
standards.
▪ Training and awareness – Educate employees on legal obligations and ethical
expectations.
▪ Risk assessment – Incorporate legal and ethical risks into enterprise risk
assessments.
▪ Policy development – Ensure policies reflect regulatory requirements and ethical
standards.
▪ Incident response planning – Include regulatory reporting and communication
protocols.

Role of Governance
▪ Strong governance ensures that cyber risk management is aligned with:
▪ Legal compliance.
▪ Ethical
84 accountability.
▪ Strategic organizational goals.
Developing a Risk Management Plan
A Risk Management Plan (RMP) is a document that outlines the strategy and
processes an organization will use to identify, assess, mitigate, and monitor risks. It
provides a structured approach to ensure risks are managed systematically and
aligned with organizational objectives. The following are the components of a risk
management plan.

Risk Management
Risk Management Scope Risk Governance and Roles
Objectives ▪ Lists key stakeholders and their
▪ Defines the purpose and ▪ Specifies the boundaries of
the risk management effort responsibilities:
goals of the risk ✓ Risk Owner
management process. (e.g., project, department,
✓ Risk Manager
▪ Aligns with organizational or enterprise-wide). ✓ Executive Sponsor
strategy or project ▪ Identifies assets, processes, ▪ Describes oversight mechanisms
objectives. or systems covered. (e.g., Risk Committee, Risk
▪ Example: "Minimize Board).
disruptions to service
delivery caused by cyber
85
threats."
Developing a Risk Management Plan – cont’d
Risk Identification Process Risk Analysis and Evaluation Risk Treatment and Response
▪ Describes methods used to ▪ Specifies how risks will be Plan
identify risks: assessed: ▪ Outlines strategies to
✓ Brainstorming ✓ Qualitative (likelihood × address risks:
✓ Checklists impact matrix) ✓ Avoid
✓ Interviews ✓ Quantitative (e.g., ✓ Mitigate
✓ Threat modeling Annualized Loss ✓ Transfer (e.g.,
✓ Vulnerability Expectancy) insurance)
assessments ▪ Defines the risk rating scale ✓ Accept
and criteria for prioritizing ✓ Exploit (for
Risk Register risks. opportunities)
Central record of all identified ▪ Includes specific control
risks and their details Monitoring and Review measures or
✓ Description ▪ Describes how and when risks countermeasures.
✓ Likelihood and impact will be monitored.
✓ Owner ▪ Includes indicators for tracking
✓ Mitigation actions risk levels (e.g., KPIs).
✓ Status ▪ Specifies review intervals and
86 update procedures.
Developing a Risk Management Plan – cont’d
Communication and Reporting Budget and Resources
Plan Risk Register ▪ Allocates resources required to
▪ Identifies who needs risk Central record of all identified implement risk management
information, what type, and risks and their details activities.
how often. ✓ Description ▪ Includes staff, tools, and
▪ Specifies communication ✓ Likelihood and impact funding for controls or
channels (e.g., reports, ✓ Owner mitigation actions.
dashboards, meetings). ✓ Mitigation actions
▪ Addresses escalation paths. ✓ Status

Tools and Methodologies


Risk Appetite and Tolerance
▪ Lists any frameworks, tools, or Approval and Revision History
▪ Defines the acceptable level of
standards used: Sign-off by relevant authorities.
risk based on business priorities.
✓ NIST, ISO/IEC 27005, FAIR, Version control and record of
▪ Helps determine when a risk
OCTAVE, etc. updates to the plan.
requires treatment or can be
✓ Risk management software
87 or templates.
accepted.
Risk Register
A Risk Register (also called a Risk Log) is a centralized document that records all
identified risks, their characteristics, and how they are being managed.
Components of a Risk Register
Field Description
Risk ID Unique identifier for tracking each risk
Description Clear statement of the risk
Probability of the risk occurring (e.g., Low, Medium,
Likelihood
High)
Consequences if the risk occurs (e.g., financial,
Impact
reputational)
Risk Score Combination of likelihood × impact (e.g., 3 × 4 = 12)
Owner Person or department responsible for managing the risk
Controls / Mitigation Existing or planned measures to reduce the risk
Status Risk status (e.g., Open, Mitigated, Monitoring)
Next Review Date Date of next evaluation
Sample Entry in a Risk Register
Risk
ID Likelihood Impact Score Owner Mitigation Status
88 Description
Data breach due Staff training,
R1 High High 15 IT Dept Monitoring
to phishing email filters
Developing a Risk Communication Plans
A communication plan ensures that risk-related information is clearly, timely, and
appropriately shared among stakeholders, including management, technical teams,
and external parties.
Key Elements of a Communication Plan
Element Details
Who needs to be informed (e.g., CIO, project teams,
Stakeholders
regulators)?
Type of information (e.g., risk status, new threats,
What to Communicate
incidents)
Frequency How often updates will be shared (e.g., weekly, monthly)
How communication will occur (e.g., meetings, email,
Channels
dashboards)
Responsibility Who is responsible for reporting or escalation
Conditions that require urgent or higher-level
Escalation Triggers
communication
Benefits of Risk Communication
▪ Informed decision-making.
▪ Better collaboration between departments.
89
▪ Timely response to emerging risks.
▪ Alignment with legal and regulatory expectations.
Presenting Risk Assessments
This entails to communicate the results of risk analysis to stakeholders in a way that supports
strategic decisions, resource allocation, and regulatory compliance.

Common Formats of Presentation


▪ Risk Heat Maps
✓ Visual matrix showing risks plotted by likelihood and impact.
✓ Helps prioritize risk responses.
▪ Dashboards
✓ Summarized real-time risk indicators and metrics.
✓ Often used in executive reporting.
▪ Risk Summary Reports
✓ Written reports detailing high, medium, and low risks, current treatments, and
recommendations.
▪ Risk Briefings / Presentations
✓ Slide decks for board or stakeholder meetings.
✓ Highlight top risks, changes in risk profile, and strategic implications.
Best Practices for Presenting Risks
▪ Use clear, non-technical language for non-technical audiences.
▪ Focus
90 on high-priority risks and their business impact.
▪ Show trends over time to highlight emerging risks or improvements.
▪ Tie risks to business objectives or regulatory compliance.

You might also like