0% found this document useful (0 votes)
23 views38 pages

Security Risk Presentation-V1

The document discusses integrating IT risk into enterprise risk management. It provides background on enterprise risk management and lists common risks such as credit, liquidity, and operational risk. It notes that IT risks are difficult to quantify and outlines challenges in assessing the likelihood and impact of cyber threats. The document explores both quantitative and qualitative approaches to analyzing IT risk.

Uploaded by

Greg
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
23 views38 pages

Security Risk Presentation-V1

The document discusses integrating IT risk into enterprise risk management. It provides background on enterprise risk management and lists common risks such as credit, liquidity, and operational risk. It notes that IT risks are difficult to quantify and outlines challenges in assessing the likelihood and impact of cyber threats. The document explores both quantitative and qualitative approaches to analyzing IT risk.

Uploaded by

Greg
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Integrating IT Risk into

Enterprise Risk Management

MAY 14, 2019


About Greg Smith
• Bio Statements go here

© 2019 Alagen. Confidential. All rights reserved.


Agenda
• Enterprise Risk Management
Integrating • The Challenge
IT Risk into • How to Integrate IT Risk
Enterprise
Risk • Summary

Management • Q+A

© 2018 Alagen. Confidential. All rights reserved.


Enterprise Risk Management (ERM)
“a process, effected by an entity's board of directors,
management and other personnel, applied in strategy
setting and across the enterprise, designed to identify
potential events that may affect the entity, and
manage risks to be within its risk appetite, to provide
reasonable assurance regarding the achievement
of entity objectives.”
– Committee of Sponsoring Organizations of Treadway Commission (COSO)

© 2019 Alagen. Confidential. All rights reserved.


Enterprise Risk Management
(Banking)

Credit Interest Rate Liquidity Market Regulatory Strategic Operational Reputation


Risk Risk Risk Risk Compliance Risk Risk Risk

© 2019 Alagen. Confidential. All rights reserved.


Credit Risk Interest Rate Risk
Risk that contract terms Financial risk arising from
go unmet and loans, movements in interest rates.
commitments, or investments Includes repricing, yield curve,
fail to perform as agreed. and options risks.

Liquidity Risk Market Risk


Arises from a bank’s inability Arises from changes in
to meet obligations when due the value of portfolios
without incurring of financial instruments.
unacceptable losses.

© 2019 Alagen. Confidential. All rights reserved.


Regulatory
Compliance Strategic Risk
Risk arising from violations or Arises from adverse or
nonconformance with laws, improper implementation of
rules, regulations, prescribed business decisions, lack of
practices, or ethical standards. responsiveness.

Operational Risk Reputation Risk


Arises from inadequate or The loss of customer trust
failed internal processes or has serious financial
IT systems, the misconduct or consequences.
errors of people, and adverse
external events.
Includes IT Risk

© 2019 Alagen. Confidential. All rights reserved.


Top Risks for 2019
1.
1. Existing operations
Existing operations meeting
meeting performance
performance expectations, competing
expectations,
competing“born-digital”
against against “born-digital”
[Link].
2. Succession challenges and ability to attract and retain top talent.
2. Succession challenges and ability to attract and retain top talent.
3. Regulatory changes and regulatory scrutiny.
3.
4. Regulatory
Cyber threats. changes and regulatory scrutiny.
4.
5. Cyber
Resistancethreats.
to change operations.
5.
6. Resistance
Rapid speed ofto changeinnovations
disruptive operations. and new technologies.
7. Rapid
6. Privacy/identity
speed of management
disruptiveand information and
innovations security.
new technologies.
8. Inability to use analytics and big data.
7. Privacy/identity management and information security.
9. Organization’s culture may not sufficiently encourage timely
8. Inability
identificationto and
useescalation
analytics andissues.
of risk big data.
9.
10. Organization’s
Sustaining customer culture
loyalty may not sufficiently encourage timely
and retention
identification and escalation of risk issues.
Source: Executive Perspectives on Top Risks 2019, Protiviti and North Carolina State
[Link] customer
University Poole College loyalty
of Management’s and retention
ERM Initiative

Source: Executive Perspectives on Top Risks 2019, Protiviti and North Carolina State University Poole College of
Management’s ERM Initiative

© 2019 Alagen. Confidential. All rights reserved.


Really Secure Money Went To
Bank Marketing Bank
1% likelihood of breach 30% likelihood of breach
in next 5 years in next 5 years

© 2019 Alagen. Confidential. All rights reserved.


The Challenge

IT risks are notoriously hard to quantify

Breaches: Not if, but when

Cost of financial services breach


is $206 per capita
10,000 records = $2.06 million
50,000 records = $10.3 million
100,000 records = $20.6 million

© 2019 Alagen. Confidential. All rights reserved.


Financial Statistical
Institutions Techniques
Asset Quality
Profit Margin
Return on Investment (ROI)
Return on Equity (ROE)
Operational Efficiency
Asset Turnover
Debt to Asset Ratio
Debt to Capital Ratio
IT Risk

© 2019 Alagen. Confidential. All rights reserved.


Quantitative Qualitative
Analysis Analysis
Tells part of the story

Devil is in the details


of assumptions

© 2019 Alagen. Confidential. All rights reserved.


Risk Factors
Inherent Risk – level of risk present before any action is taken to manage or mitigate the risk
Quantity of Risk – the level or volume of risk that the bank faces and is characterized as low,
moderate, or high

Quality of Risk Management – how well risks are identified, measured, controlled, and
monitored and is characterized as strong, satisfactory, or weak

Impact – the resulting effect of an event


Likelihood – how often something is expected to occur
Residual Risk or Aggregate Risk – incorporates an overall evaluation about the quantity of
risk and the quality of risk management expressed as high, moderate, or low

Risk Appetite – the type and amount of risk a bank is willing to tolerate in the pursuit of their
objectives

Direction of Risk – is an assessment of the probable movement in aggregate risk over the
next 12 months and is characterized as decreasing, stable, or increasing

Velocity of Risk – the speed of occurrence of a particular risk impacting the organization.
Some risks have an immediate impact, such as a tornado, and others are more gradual in the
onset of effect

Key Risk Indicators – measurable events that an organization believes to be valuable to track
as an early warning to possibly negative events. Examples are loan delinquency rates, computer
patching compliance levels, system downtime, etc.

© 2019 Alagen. Confidential. All rights reserved.


ERM Report

© 2019 Alagen. Confidential. All rights reserved.


ERM Process
1. Risk Assessment Methodology
2. Creation of a Risk Team
3. Identification of Threats and Types of Losses
4. Identification of Controls Used to Mitigate Risks
5. Evaluation of Controls
6. Method of Quantifying Risk
7. Rating Quality of Risk Management
8. Likelihood and Impact
9. Communication and Reporting of Risk
10. Ongoing Risk Monitoring

© 2019 Alagen. Confidential. All rights reserved.


Risk Assessment Methodology

NIST

ANSI Identify or establish


ERM framework and
use it for IT risk.

COSO
ERM
ISO
31000

© 2019 Alagen. Confidential. All rights reserved.


Creation of a Risk Team

• Long-standing
• Different backgrounds
• Meet periodically
• Goal: Assess Risk using
ERM methodology

© 2019 Alagen. Confidential. All rights reserved.


Identification of Threats
And Types of Losses

Privileged
• Categorize your data
• Identify threats:
Restricted
Confidential • Bad guys value:
IP, SSN, Cardholder Data
Company Confidential
• Resources: Verizon
Data Breach Report
• Threat modeling
Public

© 2019 Alagen. Confidential. All rights reserved.


Identification of Controls
Used to Mitigate Risk
• Technical + Non-technical
• Preventative Controls: web filtering, blocking
known outbound ports, up-to-date antivirus
• Administrative Controls: acceptable use of policy
and training program
• Detective Controls: alerting when malicious links
are clicked

© 2019 Alagen. Confidential. All rights reserved.


Evaluation of Controls

Goal: accurately rate the effectiveness of controls


as compared to an industry standard

Rating Description

1 Control effectiveness significantly exceeds all industry standards

2 Control effectiveness meets and, in some cases, exceeds industry standards

3 Control effectiveness meets industry standards

4 Control effectiveness does not meet all industry standards

5 Control effectiveness has significant deficiencies compared to industry standards

© 2019 Alagen. Confidential. All rights reserved.


Evaluation of Controls: Approaches
1 Consensus rating
• Requires true understanding of industry standard
• Requires intimate knowledge of org’s control effectiveness
• At best, it can be acceptable
• At worst, it’s just an educated guess

2 Use the rating system used by examiners:


Uniform Rating System for IT (URSIT)
• Easy to understand composite rating (1–5 scale)
• 4 components: audit, management, development + acquisition,
support + deliver
• Compliance-driven approach of correcting findings
• Not proactive

© 2019 Alagen. Confidential. All rights reserved.


3 Compare org’s inherent risk levels to FFIEC cyber
assessment tool cybersecurity maturity levels
• Quantify actual controls in place
• Variance from maturity level that corresponds to inherent risk
allows for increase / decrease of control effectiveness rating
• Fine-tuning by CAT “domains” allows
tailoring of goals
• FSSCC spreadsheet tool provides
useful graphs and analysis

© 2019 Alagen. Confidential. All rights reserved.


4 Use scenario analysis to prioritize and rate controls
based on relevant (financial services) breach data
• Gives importance to controls in the “kill chain” that stop attacks
• Ties control objectives to prevalent attack ”domains”
• Strategic planning can be tied to improvements that matter
• Attack sophistication, breach costs, and control quality can be
modeled statistically to project likelihood and impact

Domain Description

Any incident involving malware that did not fit into a more specific pattern. The majority of the
incidents that comprise this pattern are opportunistic in nature and have a financial motivation
Crimeware (CRI)
behind them. This pattern frequently affects consumers and is where “typical” malware
infections will land.

Payment Card All incidents in which a skimming device was physically implanted (tampering) on an asset that
Skimmers (PCS) reads magnetic stripe data from a payment card (e.g. ATMs, gas pumps, POS terminals, etc.).

© 2019 Alagen. Confidential. All rights reserved.


Method of Quantifying Risk
Ensure risks are ranked appropriately to guide decision making
• Requires detailed understanding of allowable limits and
standards used
• Need descriptions for high, medium, and low risk situations

High Risk Medium Risk Low Risk

Less than 65% of all critical and At least 65% of all critical and high All critical and high vulnerabilities
high vulnerabilities for servers, vulnerabilities for servers, network for servers, network devices, and
network devices, and workstations devices, and workstations are workstations are patched within 30
are patched within 30 days of the patched within 30 days of the days of the patch release
patch release. patch release.

Example of Risk ratings for a patch management program

© 2019 Alagen. Confidential. All rights reserved.


Other approaches:
• IT Risk in the context of Operational Risk
• Incorporates four components, including the FFIEC CAT
Inherent Risk Profile

High Risk High Risk

Risks from transaction-processing failures, The number, nature, and complexity of


technology changes, outsourcing, planned third-party relationships continue to
conversions, merger integration, or new expand.
products and services are high. Volume of
cyberattacks is high and increasing based High reliance on a few third parties that
on industry statistics. service multiple banking institutions.

The speed and sophistication of


Example of Risk ratings for overall program
cybersecurity threats are increasing.

FFIEC Cyber Assessment Tool (CAT)


Inherent Risk Profile is “Significant” or
“Most” as determined in the last year.

Example of Inherent Quantity of Cybersecurity


Risk ratings incorporating FFIEC CAT

© 2019 Alagen. Confidential. All rights reserved.


Rating Quality of Risk Management
Define weak, satisfactory, and strong risk management practices

Weak Risk Management Satisfactory Risk Mgmt. Strong Risk Management

No standards are defined for Appropriate standards are in place Standards are in place for patching
patching; no regular reporting of for patching; regular quarterly that are higher than industry
compliance with defined standards; reporting of compliance with standards; regular quarterly
vulnerability scanning is performed defined standards occurs to reporting of compliance with
less than quarterly; vulnerability appropriate level; vulnerability defined standards occurs to
results are inconsistent scanning is performed at least appropriate management;
quarterly; vulnerability results are vulnerability scanning is performed
generally consistent with some at least weekly; vulnerability results
occasional subpar patching levels are consistent and managed
effectively.

Example of Quality of Risk Management ratings for a patch management program

© 2019 Alagen. Confidential. All rights reserved.


Weak Risk Management Satisfactory Risk Mgmt. Strong Risk Management

Average declarative statement Average declarative statement Average control effectiveness across
(control) effectiveness across all (control) effectiveness across all all five FFIEC Cyber Assessment Tool
five FFIEC Cyber Assessment Tool five FFIEC Cyber Assessment Tool (CAT) domains is greater than “2.5”.
domains is less than“2”. domains is “2”.
Inherent Risk Profile suggested
Inherent Risk Profile suggested Inherent Risk Profile suggested maturity level is exceeded in at least
maturity level is not met for all maturity level is met in all domains three of five domains for most controls.
controls. for all controls for all controls.
Bank phishing click response rates are
Bank phishing click response rates Bank phishing click response rates formally monitored by an anti-phishing
are not formally monitored by a are formally monitored by an anti- program and click rates are below 10%.
anti-phishing program. phishing program and click rates
are below 20%.

Example of Quality of Risk Management ratings for overall program (3 components)

© 2019 Alagen. Confidential. All rights reserved.


Alternative “Top Down” approach:
• Rate how controls resist attack scenarios by comparing to a
standard, like FFIEC Cyber Assessment Tool’s declarative
statements

Sample rating system

Process or control is informal, at an initial phase of implementation, or


ad-hoc, and may not fully meet declarative statement intent. The process
may not be documented or repeatable and may be dependent on
individual heroics.

Process or control meets the specific requirements of the control


statements. Process or control is repeatable and appropriately managed;
and defined with documented policy, procedures, and standards.

Process or control meets and often exceeds the specific requirements of


the control statements; is repeatable and appropriately managed; and
defined with documented policy, procedures, and standards. Quality of
the implementation is high resulting in lower risk.

© 2019 Alagen. Confidential. All rights reserved.


• Create an aggregate rating (sum of ratings ÷ # of controls)
• Calculate residual risk value = remaining risk after inherent risk
has been reduced by your risk controls
• Good reflection of quality of overall cyber security program
• This quantitative rating can be used as a quality of risk
management value

Weak Risk Management Satisfactory Risk Mgmt. Strong Risk Management

Average control effectiveness Average control effectiveness Average control effectiveness across
across all five FFIEC Cyber across all five FFIEC Cyber all five FFIEC Cyber Assessment Tool
Assessment Tool domains is less Assessment Tool domains is “2”. domains is greater than “2.5”. Inherent
than “2”. Inherent Risk Profile Inherent Risk Profile suggested Risk Profile suggested maturity level is
suggested maturity level is not met maturity level is met in all domains. exceeded in at least three domains.
in some domains.

Example of Quality of Risk Management ratings for overall program

© 2019 Alagen. Confidential. All rights reserved.


Likelihood and Impact
Represents the probability an event might result in deliberate or
accidental impact to the organization.
• Lowest likelihood of an occurrence would be a 1.

Rating Likelihood
1 Extremely unlikely — once every 50 years

2 Unlikely — once every 10 years

3 Likely — once every 5 years

4 Probable — annually

5 Expected — monthly

Example of Likelihood Ratings for an event or category of events

© 2019 Alagen. Confidential. All rights reserved.


Impact ratings rate the relative significance of an event (like a
distributed denial of service (dDOS) attack or breach)
• Sample below shows two areas appropriate for most orgs.
• Other areas might include reputational, strategic,
regulatory/legal, and security

Rating Financial Impact Operational Impact


1 < $20k Minor operational problem with no customer impact

2 ~ $200k Temporary loss of services for less than 4 hours; limited customer impact

3 ~ $500k Temporary loss of a service for more than 4 hours; limited customer impact

4 ~ $1mil Temporary loss of a service for more than 12 hours; significant customer impact

5 ~ $5mil Temporary loss of a service for more than 36 hours; significant customer impact

Example of Impact Ratings for an operational event

© 2019 Alagen. Confidential. All rights reserved.


Communication and Reporting of Risk
Following assessment of components, a report is created
• Executive summary
• Rates the risks
• Provides context of the nature of the risk
• Documents contributing factors
• Clearly states recommendations to address any gaps
• Other relevant details

Once approved by risk team, request a verbal briefing


• Risk committee, board, CEO, or CFO
• Focus on important points, any action or funding needed
• If part of an ERM, you may only get a minute or two

Re-communicate report whenever significant incidents occur

© 2019 Alagen. Confidential. All rights reserved.


Ongoing Risk Monitoring
• IT Risk monitoring and reporting needs to occur regularly
• Keeps management and/or board informed about the true
state of IT Risk
• Ensures CISOs / IT Managers alert when processes are in
need of resources, expertise, and innovative thinking

© 2019 Alagen. Confidential. All rights reserved.


Where to Start
1. Talk with the most senior person in your organization
about the ERM framework

2. Understand the key concepts and definitions used and let


your Chief Risk Officer you’d like to contribute to the
quality of periodic evaluations

3. Do a Cyber Security Assessment

© 2019 Alagen. Confidential. All rights reserved.


Summary
Effective incorporation of IT Risks as a part of ERM:
• Provides critical intelligence about a key risk category
• Ensures company-wide awareness of security risks
• Enables appropriate prioritization and funding within
context of all organizational risks
• Improves security posture by enabling organizational
understanding and ongoing assessment of security needs

Following the outlined steps will ensure that IT security is


considered among other enterprise risks, bolstering your
institution’s enterprise risk management efforts.

© 2019 Alagen. Confidential. All rights reserved.


Questions?

Gregory Smith, CISSP


Senior Risk Advisor
[Link]@[Link]

© 2019 Alagen. Confidential. All rights reserved.


INTEGRATING IT RISK
INTO ENTERPRISE
RISK MANAGEMENT
Greg Smith, Alagen

You might also like