I.
Core Risk Management Concepts
Risk Definition: Risk is the likelihood that an uncertain event will
affect an organization's assets or resources.
Risk Equation: Risk = Threat × Vulnerability.
o Threat: An opportunity to exploit a vulnerability.
o Vulnerability: A weakness that, if exploited, results in an
Impact (cost).
Business Driver: Identifying, assessing, and addressing risks is
essential for an organization's longevity and should align with strategic
goals.
Two Classes of Risk:
o Inherent Risk: The risk as it exists currently without any
security controls in place.
o Residual Risk: The amount of risk that remains after
implementing controls; it is nearly impossible to eliminate all
risk.
Risk Methodology: A formal process for identifying, assessing,
prioritizing, and addressing risks, including specific techniques and
approach.
Risk Register: The central document that results from the risk
identification process, listing all identified risks.
II. Contingency Planning: BIA, BCP, and DRP
The primary focus is to ensure that events do not interrupt normal business
functions.
1. Business Impact Analysis (BIA)
A formal analysis that classifies functions as critical (required to run the
business, e.g., sales order entry) or noncritical (important but not deal-
breaking, e.g., zip-code-sorted customer reporting).
Recovery Point Objective (RPO): The maximum amount of data
loss (not time) that is acceptable.
Recovery Time Objective (RTO): The maximum allowable time to
recover a function.
2. Business Continuity Plan (BCP)
A written response plan for events resulting in interruptions to critical
activities.
Order of Priorities:
1. Safety and well-being of people (ALWAYS FIRST).
2. Continuity of critical business functions.
3. Continuity of IT infrastructure components.
4. Minimizing direct and indirect costs.
Interruption vs. Disaster: A BCP manages interruptions (minor,
short-term events), while a DRP manages disasters (extended events
causing substantial damage).
3. Disaster Recovery Plan (DRP)
Directs actions to recover resources after a disaster.
Recovery Sites:
o Hot Site: Fully equipped with hardware, software, and data;
most expensive but fastest recovery.
o Warm Site: Basic computer hardware and utilities; requires
more time to load data.
o Cold Site: Basic utilities only; no infrastructure components
initially.
o Mobile Site: A trailer with utilities that can function as a warm
or cold site.
DRP Testing Methods:
o Checklist Test: Simplest; participants check off steps.
o Structured Walk-through (Tabletop): Role-playing to
simulate a disaster in a conference room.
o Simulation Test: Realistic role-playing without affecting live
operations.
o Parallel Test: Full processing at an alternate site while the
primary site stays live.
o Full-Interruption Test: The only complete test; interrupts the
primary data center and transfers to an alternate site.
III. Security Gaps and Analysis
Security Gap: The difference between controls currently in place (per
policy) and the controls needed to address vulnerabilities.
Gap Analysis: A comparison and assessment of existing versus
required controls.
Causes of Gaps: Lack of training, intentional disregard of policy,
unintended consequences of changes, or new external requirements
(laws/standards).
IV. Ethics and Policy Enforceability
Ethics vs. Law: Laws carry the authority of a governing body; ethics
are socially acceptable behaviors based on cultural mores.
Enforceable Policy Criteria: To be legally enforceable, a policy must
meet five criteria:
1. Dissemination: Readily available.
2. Review: In an intelligible form (non-English if necessary).
3. Comprehension: Demonstrated understanding (e.g., quizzes).
4. Compliance: Agreement through act or affirmation.
5. Uniform Enforcement: Applied fairly to everyone regardless of
status.
Deterring Unethical Behavior: Requires fear of penalty, high
probability of being caught, and high probability of the penalty being
administered.
V. Major Compliance Laws and Standards
FERPA (1974): Protects the privacy of student education records.
GLBA (1999): Addresses information security in the financial industry.
HIPAA (2006): Governs the security and privacy of medical records
and health information.
SOX (2002): Regulates corporate governance and financial disclosure.
FISMA (2002/2014): Requires federal agencies to develop and
maintain information security programs.
PCI DSS: Not a law, but a set of security standards for organizations
handling credit cards; non-compliance results in financial
consequences.
GDPR (2016): European Union regulation on personal data and
privacy.
VI. Data Confidentiality and Control
C-I-A Triangle: Confidentiality, Integrity, and Availability.
Confidentiality: Once breached, it cannot be undone.
Accounting: Recording events in log files to trace user actions.
Authentication Controls (Who are you?): Passwords, PINs, Smart
cards, Biometrics, and Kerberos.
Authorization Controls (What can you do?): Access control lists
(ACLs), IDS/IPS, and network traffic filters.
VII. Mobility and BYOD Security
Bring Your Own Device (BYOD): Employees using personal devices
for business use.
BYOD Policy Concerns: Data ownership, privacy, patch
management, and acceptable use.
Endpoint Security Controls:
o Remote Wiping: Deleting data if a device is lost or stolen.
o Full Device Encryption: Protecting data on the device.
o Storage Segmentation: Separating personal and business
data.
o Mobile Device Management (MDM): Software agents to
monitor and control mobile devices.
KTC:
Acceptable use policy (AUP): Guidelines that describe acceptable
and unacceptable employee behaviors in the workplace, functioning as
organizational laws complete with penalties and sanctions.
Accounting: In the context of monitoring system activity, this refers
to recording events in log files to trace user actions and determine
a sequence of events.
Business driver: Elements within an organization—including people,
information, and conditions—that support business objectives.
Security activities are considered business drivers because they
protect intellectual property and ensure compliance.
Gap analysis: A comparison and assessment of the security
controls currently in place versus the controls needed to address all
identified threats.
Inherent risk: The level of risk as it currently exists before any
security controls or risk-mitigating solutions have been implemented.
Mobility: A capability that allows remote workers and employees to
stay connected to the organization's IT infrastructure in almost real
time.
Privacy policy: A document that defines what an organization
does with the data it collects about individuals, why it collects that
data, and the options available to those who do not want their data
shared.
Project Management Body of Knowledge (PMBOK): A guide
containing industry best practices for project management,
maintained by the Project Management Institute (PMI).
Project Management Institute (PMI): The professional organization
that maintains the PMBOK and establishes the framework for risk
management and project management.
Recovery point objective (RPO): The target state of recovered data
required to continue normal processing; it represents the maximum
amount of data loss (not time) that is acceptable.
Recovery time objective (RTO): The maximum allowable time an
organization has to recover a specific business function following an
interruption.
Risk methodology: The formal process an organization adopts for
identifying, assessing, prioritizing, and addressing risks.
Risk register: The central document resulting from the risk
identification process that contains a list of all identified risks, their
impacts, probabilities, and mitigation steps.
Security gap: The difference between the security controls currently
outlined in a security policy and the controls actually needed to
address vulnerabilities.
Security policy: An organizational document that defines risk-
mitigating solutions and outlines the security controls that should be
in place.
Threat analysis: The process of identifying and documenting
threats to critical resources, including the types of disasters possible
and the potential damage they could cause.