0% found this document useful (0 votes)
4 views6 pages

Ch4notes

The document outlines core risk management concepts, including definitions of risk, types of risk, and methodologies for assessing and addressing risks. It also discusses contingency planning, including Business Impact Analysis, Business Continuity Plans, and Disaster Recovery Plans, as well as security gaps, ethics, compliance laws, data confidentiality, and BYOD security. Key terms and concepts related to risk management and security policies are defined to provide a comprehensive understanding of the subject.

Uploaded by

jeremylwasson
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views6 pages

Ch4notes

The document outlines core risk management concepts, including definitions of risk, types of risk, and methodologies for assessing and addressing risks. It also discusses contingency planning, including Business Impact Analysis, Business Continuity Plans, and Disaster Recovery Plans, as well as security gaps, ethics, compliance laws, data confidentiality, and BYOD security. Key terms and concepts related to risk management and security policies are defined to provide a comprehensive understanding of the subject.

Uploaded by

jeremylwasson
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

I.

Core Risk Management Concepts

 Risk Definition: Risk is the likelihood that an uncertain event will


affect an organization's assets or resources.

 Risk Equation: Risk = Threat × Vulnerability.

o Threat: An opportunity to exploit a vulnerability.

o Vulnerability: A weakness that, if exploited, results in an


Impact (cost).

 Business Driver: Identifying, assessing, and addressing risks is


essential for an organization's longevity and should align with strategic
goals.

 Two Classes of Risk:

o Inherent Risk: The risk as it exists currently without any


security controls in place.

o Residual Risk: The amount of risk that remains after


implementing controls; it is nearly impossible to eliminate all
risk.

 Risk Methodology: A formal process for identifying, assessing,


prioritizing, and addressing risks, including specific techniques and
approach.

 Risk Register: The central document that results from the risk
identification process, listing all identified risks.

II. Contingency Planning: BIA, BCP, and DRP

The primary focus is to ensure that events do not interrupt normal business
functions.

1. Business Impact Analysis (BIA)

A formal analysis that classifies functions as critical (required to run the


business, e.g., sales order entry) or noncritical (important but not deal-
breaking, e.g., zip-code-sorted customer reporting).

 Recovery Point Objective (RPO): The maximum amount of data


loss (not time) that is acceptable.

 Recovery Time Objective (RTO): The maximum allowable time to


recover a function.
2. Business Continuity Plan (BCP)

A written response plan for events resulting in interruptions to critical


activities.

 Order of Priorities:

1. Safety and well-being of people (ALWAYS FIRST).

2. Continuity of critical business functions.

3. Continuity of IT infrastructure components.

4. Minimizing direct and indirect costs.

 Interruption vs. Disaster: A BCP manages interruptions (minor,


short-term events), while a DRP manages disasters (extended events
causing substantial damage).

3. Disaster Recovery Plan (DRP)

Directs actions to recover resources after a disaster.

 Recovery Sites:

o Hot Site: Fully equipped with hardware, software, and data;


most expensive but fastest recovery.

o Warm Site: Basic computer hardware and utilities; requires


more time to load data.

o Cold Site: Basic utilities only; no infrastructure components


initially.

o Mobile Site: A trailer with utilities that can function as a warm


or cold site.

 DRP Testing Methods:

o Checklist Test: Simplest; participants check off steps.

o Structured Walk-through (Tabletop): Role-playing to


simulate a disaster in a conference room.

o Simulation Test: Realistic role-playing without affecting live


operations.

o Parallel Test: Full processing at an alternate site while the


primary site stays live.
o Full-Interruption Test: The only complete test; interrupts the
primary data center and transfers to an alternate site.

III. Security Gaps and Analysis

 Security Gap: The difference between controls currently in place (per


policy) and the controls needed to address vulnerabilities.

 Gap Analysis: A comparison and assessment of existing versus


required controls.

 Causes of Gaps: Lack of training, intentional disregard of policy,


unintended consequences of changes, or new external requirements
(laws/standards).

IV. Ethics and Policy Enforceability

 Ethics vs. Law: Laws carry the authority of a governing body; ethics
are socially acceptable behaviors based on cultural mores.

 Enforceable Policy Criteria: To be legally enforceable, a policy must


meet five criteria:

1. Dissemination: Readily available.

2. Review: In an intelligible form (non-English if necessary).

3. Comprehension: Demonstrated understanding (e.g., quizzes).

4. Compliance: Agreement through act or affirmation.

5. Uniform Enforcement: Applied fairly to everyone regardless of


status.

 Deterring Unethical Behavior: Requires fear of penalty, high


probability of being caught, and high probability of the penalty being
administered.

V. Major Compliance Laws and Standards

 FERPA (1974): Protects the privacy of student education records.

 GLBA (1999): Addresses information security in the financial industry.

 HIPAA (2006): Governs the security and privacy of medical records


and health information.

 SOX (2002): Regulates corporate governance and financial disclosure.


 FISMA (2002/2014): Requires federal agencies to develop and
maintain information security programs.

 PCI DSS: Not a law, but a set of security standards for organizations
handling credit cards; non-compliance results in financial
consequences.

 GDPR (2016): European Union regulation on personal data and


privacy.

VI. Data Confidentiality and Control

 C-I-A Triangle: Confidentiality, Integrity, and Availability.

 Confidentiality: Once breached, it cannot be undone.

 Accounting: Recording events in log files to trace user actions.

 Authentication Controls (Who are you?): Passwords, PINs, Smart


cards, Biometrics, and Kerberos.

 Authorization Controls (What can you do?): Access control lists


(ACLs), IDS/IPS, and network traffic filters.

VII. Mobility and BYOD Security

 Bring Your Own Device (BYOD): Employees using personal devices


for business use.

 BYOD Policy Concerns: Data ownership, privacy, patch


management, and acceptable use.

 Endpoint Security Controls:

o Remote Wiping: Deleting data if a device is lost or stolen.

o Full Device Encryption: Protecting data on the device.

o Storage Segmentation: Separating personal and business


data.

o Mobile Device Management (MDM): Software agents to


monitor and control mobile devices.
KTC:

 Acceptable use policy (AUP): Guidelines that describe acceptable


and unacceptable employee behaviors in the workplace, functioning as
organizational laws complete with penalties and sanctions.

 Accounting: In the context of monitoring system activity, this refers


to recording events in log files to trace user actions and determine
a sequence of events.

 Business driver: Elements within an organization—including people,


information, and conditions—that support business objectives.
Security activities are considered business drivers because they
protect intellectual property and ensure compliance.

 Gap analysis: A comparison and assessment of the security


controls currently in place versus the controls needed to address all
identified threats.

 Inherent risk: The level of risk as it currently exists before any


security controls or risk-mitigating solutions have been implemented.

 Mobility: A capability that allows remote workers and employees to


stay connected to the organization's IT infrastructure in almost real
time.

 Privacy policy: A document that defines what an organization


does with the data it collects about individuals, why it collects that
data, and the options available to those who do not want their data
shared.

 Project Management Body of Knowledge (PMBOK): A guide


containing industry best practices for project management,
maintained by the Project Management Institute (PMI).

 Project Management Institute (PMI): The professional organization


that maintains the PMBOK and establishes the framework for risk
management and project management.

 Recovery point objective (RPO): The target state of recovered data


required to continue normal processing; it represents the maximum
amount of data loss (not time) that is acceptable.
 Recovery time objective (RTO): The maximum allowable time an
organization has to recover a specific business function following an
interruption.

 Risk methodology: The formal process an organization adopts for


identifying, assessing, prioritizing, and addressing risks.

 Risk register: The central document resulting from the risk


identification process that contains a list of all identified risks, their
impacts, probabilities, and mitigation steps.

 Security gap: The difference between the security controls currently


outlined in a security policy and the controls actually needed to
address vulnerabilities.

 Security policy: An organizational document that defines risk-


mitigating solutions and outlines the security controls that should be
in place.

 Threat analysis: The process of identifying and documenting


threats to critical resources, including the types of disasters possible
and the potential damage they could cause.

You might also like