Topics:
- Types of risks
- Risk Management process
Inherent risk is the baseline level of risk exposure in an IT system, process, or asset before any
security controls or mitigations are applied. It reflects the natural vulnerability due to factors like
asset sensitivity, threat landscape, and operational complexity.
Residual risk is the level of risk that remains after all security controls, treatments, and mitigations
have been applied to the original inherent risk. It represents the unavoidable exposure your
organization accepts.
Risk acceptance criteria are documented thresholds (for impact, likelihood, or overall risk rating)
that define when a risk may be accepted rather than reduced, transferred, or avoided. They are
aligned with the organization’s risk appetite (how much risk it is willing to take) and risk tolerance
(how much variation from objectives it can withstand).
Risk appetite is the broad, strategic amount and type of risk an organization is willing to pursue to
achieve objectives, often set by the board (e.g., high for growth-focused firms, low for conservative
ones). Risk tolerance defines the specific, measurable variation or deviation from objectives that the
organization can withstand within that appetite, like operational limits or thresholds. Risk
acceptance is the tactical decision to formally approve and live with a specific risk that falls within
tolerance after assessment, typically for residual risks post-mitigation.
The logic requires reducing risks until additional mitigation measures provide diminishing
returns that are grossly disproportionate to their benefits. Risks fall into three zones on a typical risk
matrix: unacceptable (must reduce regardless of cost), broadly acceptable (no action needed), and
tolerable only if ALARP—meaning further controls are justified only if reasonably practicable
ALARP stands for "As Low As Reasonably Practicable," while ALARA means "As Low As
Reasonably Achievable." These are risk management principles used to balance safety or compliance
benefits against the costs, time, and effort of further risk reduction.
Information Security Risk Management (ISRM) Process
1. Identify Assets - Determine the scope and identify where risks may exist within the organization.
You can’t protect what you don’t know, so the first step is to create an inventory of all physical and
logical assets within the scope of the risk assessment.
When identifying assets, it’s important to include:
Crown jewels – critical business assets that are prime targets for attackers.
Pivot assets – systems attackers may exploit to expand their reach, such as Active Directory
servers or Picture Archiving and Communication Systems (PACS).
Creating a network architecture diagram from the asset inventory helps visualize interconnectivity,
communication paths, and entry points into the network, making threat identification easier.
2. Identify Risks - Identify vulnerabilities, threats, and their potential impact.
Threat actors use tactics, techniques, and procedures (TTPs) that can compromise the CIA triad
(Confidentiality, Integrity, Availability). To identify potential threats:
Use resources like the MITRE ATT&CK Knowledge Base and the Cyber Threat Alliance.
Review security vendor reports and government advisories (e.g., CISA) for industry-specific
or emerging threats.
3. Assess the Risk - Evaluate the likelihood of each risk scenario and its potential impact. This can be
achieved using Quantitative and Qualitative Risk Assessment.
Risk Level = Likelihood or Probability of Attack × Impact
Likelihood = Vulnerability × Threat
Impact = Effect on CIA triad
Likelihood: The probability that a threat can exploit a vulnerability. This should be based on
discoverability, exploitability, and reproducibility, not just historical data (since cyber
threats evolve rapidly).
Impact: The magnitude of harm if a vulnerability is exploited. Assess confidentiality,
integrity, and availability separately, and use the highest rating as the final score.
3.1. Quantitative RA – assigns a monetary value to the asset. It then uses the anticipated exposure
to calculate a dollar cost.
In QRA, Risk Level is expanded into SLE, ARO, and ALE. Therefore, Risk Level (ALE) = Likelihood
(ARO) x Impact (SLE).
Step 1. Determine the single loss expectancy (SLE): This step involves determining the single amount
of loss you could incur on an asset if a threat becomes realized or the amount of loss you expect to
incur if the asset is exposed to the threat one time. SLE is calculated as follows: SLE = Asset Value ×
Exposure Factor. The Exposure Factor (EF) is the subjective, potential portion of the loss to a specific
asset if a specific threat were to occur.
Step 2. Evaluate the annual rate of occurrence (ARO): The purpose of evaluating the ARO is to
determine how often an unwanted event is likely to occur on an annualized basis.
Step 3. Calculate the annual loss expectancy (ALE): This final step of the quantitative assessment
seeks to combine the potential loss and rate per year to determine the magnitude of the risk. This is
expressed as annual loss expectancy (ALE), which is calculated as follows: ALE = SLE × ARO.
E.g. If you have data worth $500 that has an exposure factor of 50 percent due to lack of
countermeasures such as antivirus, what would the SLE be? Use the following formula to calculate
the answer: AV × EF = SLE, or $500 × .50 = $250
As part of a follow-up test question, could you calculate the annualized loss expectance (ALE) if you
knew that this type of event typically happened four times a year? Yes, as this would mean the ARO
is 4. Therefore: ALE = SLE × ARO or $250 × 4 = $1,000. This means that, on average, the loss is $1,000
per year.
3.2. Qualitative RA - Evaluates risks based on subjective judgment, experience, or descriptive scales
rather than hard numbers.
Risk Level = Likelihood or Probability of Attack (event) × Impact
Likelihood is rated descriptively (unlikely, possible, likely).
Impact is rated descriptively (minor, moderate, severe).
Scoring Example:
Likelihood: 1 (Rare) → 3 (Highly Likely)
Impact: 1 (Minor) → 3 (Severe)
This enables creation of a risk matrix
Impact ↓ / Likelihood → 1: Rare 2: Likely 3: Highly Likely
3: Severe High High Critical
2: Moderate Low High High
1: Minor Low Medium High
Likelihood scale (1–3):
1 = Rare
2 = Likely
3 = Highly Likely
Impact scale (1–3):
1 = Minor
2 = Moderate
3 = Severe
Risk levels:
Low = Acceptable, monitor only
Medium = Requires mitigation planning
High = Needs prompt action
Critical = Immediate action required
3.3. Semi-Quantitative approach - A single incident causing more than a defined financial loss (e.g.,
2% of annual EBITDA) or more than X hours of critical service outage is considered unacceptable and
must be reduced; below those bands, acceptance may be considered subject to ALARP and
management sign-off
4. Prioritize Risks - Rank identified risks based on severity using. This classification helps determine
which risks require immediate attention.
5. Risk Treatment - Decide how to handle each risk:
This can be determined through quantitative or qualitative assessment. Assess each risk post-
analysis: compare against predefined criteria (e.g., high/medium/low thresholds). Prioritize based on
potential business impact—financial loss, regulatory fines, or operational disruption—then select the
optimal treatment balancing cost versus residual risk.
Avoid / Terminate: If the cost outweighs the benefit i.e. when risk exposure is unacceptable
and easily preventable, discontinue the activity to eliminate exposure. This can be
determined through quantitative or qualitative assessment.
Transfer: Opt for transfer in high-impact scenarios where third parties can assume liability,
such as cyber insurance for ransomware attacks or outsourcing cloud security to AWS/Azure
managed services with SLAs (e.g., outsourcing DDoS mitigation, purchasing cyber insurance).
o First-party coverage: Costs incurred directly (e.g., customer notifications after a
breach).
o Third-party coverage: Settlements, penalties, and fines.
o Not covered: Intangible losses like intellectual property theft or brand damage.
Mitigate: Ideal when treatment costs are justified.
Implement security controls to reduce likelihood and/or impact. Assign responsibility to the
appropriate team, set deadlines, and track progress.
Tolerate / Accept: If the risk falls within the organization’s risk acceptance criteria,
acknowledge and accept it.
6. Communication - Regardless of treatment, decisions must be communicated across the
organization.
Stakeholders should understand the costs of treating vs. not treating a risk.
Roles and responsibilities must be clearly defined to ensure accountability.
7. Rinse and Repeat - Risk management is a continuous process.
Controls must be monitored and updated as systems evolve (e.g., new ports opened, code
changes, infrastructure updates).
Regular reassessment ensures controls remain effective over time.