Risk Management in Information Security
Risk Management in Information Security
Management Assurance
(ISM811S)
Chapter 5 – Risk Management Summary
29 March 2023
2
Reading Material
Formal 3
Outline
• Learning Outcomes
• Introduction
• Risk Management Framework
• Risk Management Process
• Risk Analysis
• Case Study
Formal 4
Learning outcomes
Formal 5
Key words
• Enterprise risk management (ERM): The evaluation and reaction to risk to the entire organisation;
ERM is not restricted to the risk facing information assets.
• Information security risk management (ISRM): The entire program of planning for and managing risk
to information assets in the organisation.
• Risk assessment: An approach to combining risk identification, risk analysis, and risk evaluation into a
single strategy.
• Risk Management framework (RMF): The overall structure of the strategic planning and design for the
entirety of the organisation's risk management efforts.
• Risk Management process: The identification, analysis, evaluation, and treatment of risk to
information assets, as specified in the risk management framework
• Risk management policy: “Policy designed to regulate organisational efforts related to the
identification, assessment, and treatment of risk to information assets” (Whitman & Mattord, 2019. pp
308).
• Residual risk: “The risk to information assets that remains even after current controls have been
applied
Formal 6
Key words
• Risk appetite: “The quantity and nature of risk that organisations are willing to accept as they evaluate
the trade-offs between perfect security and unlimited accessibility”
• Risk appetite statement: “A formal document developed by the organisation that specifies its overall
willingness to accept risk to its information assets, based on a synthesis of individual risk tolerances”
Risk management plan: “A document that contains specifications for the implementation and conduct
of risk management efforts”
• Risk tolerance/threshold: “The assessment of the amount of risk an organisation is willing to accept
for a particular information asset, typically synthesized into the organisation's overall risk appetite”
• Zero tolerance risk exposure: “An extreme level of risk tolerance whereby the organisation is unwilling
to allow any successful attacks or suffer any loss to an information asset”
Formal 7
Introduction
Formal 8
Threat vs Vulnerability vs Risk
• A threat is something that can, or someone that wants to cause harm to the
organisation and is identified through threat modeling
• A vulnerability is a weakness that can be exploited and is identified through security
testing and vulnerability assessments
• A risk is something bad that can happen and is characterised by having a certain
impact (loss or negative outcome) and probability of occurrence (likelihood)
• Interrelationship
• A threat exploits a vulnerability leading to a risk materialising (consequence)
• Management needs a way to measure risk to indicate to the board that systems are
operating within risk tolerance levels
• A suitable method to do this is through risk appetite model and CyberMIS as part of
the Risk management framework and Risk management process in later slides
Supplementary 9
When is something a risk
Formal 10
Risk management
Formal 11
Risk management questions
Formal 12
Information security risk management methodologies (ISRM)
Formal 13
NIST framework processes
Formal 14
Risk management framework and process
Formal 15
Risk management framework and process
Formal 16
Risk management framework steps
Executive governance
and support
Step 1 • Initially CISO and top
management must
develop and enable the
risk management
framework and its
resulting risk management
process.
Formal 17
Risk management framework steps
• Ensuring compliance with all legal and regulatory statutes and mandates;
• Guiding the development of, and formally approving, the risk management
policy.
• Recommending performance measures for the risk management effort and
ensuring that they are compatible with other performance measures in the
organisation;
• Assigning roles and responsibilities;
• Ensuring that the selected goals and objectives are appropriate and in
alignment with the organisation's strategic goals and objectives;
• Providing needed resources
Formal 18
Risk management framework steps
Framework design
• risk management process
Step 2 design.
• determine current levels of risk
and controls to reduce risk
level down to acceptable levels
specified by the risk appetite.
• define the organisation's risk
appetite and draft the risk
management plan.
Formal 19
Risk management framework steps
Framework
implementation
Step 3
• Implement the controls
and describe how the
controls are employed
within the system and
its environment of
operation
Formal 20
Risk management framework steps
Framework
Monitoring and
Step 4 Review
• evaluate the implemented
controls to determine if the
controls are implemented
correctly, operating as
intended, and producing
the desired outcome
Formal 21
Risk management framework steps
CyberMIS
• Create Cyber Management Information System (CyberMIS) in line with
the risk appetite model
• Use data from diverse data sources to build data models of all items that
drive risk for measurement
• Link data models on common fields to build a 3D model of the
environment and how it interacts
• Refresh the live environment on at least a daily basis
• Visualise the result for various reporting and operational purposes
Supplemental 22
Risk management framework steps
CyberMIS
Data warehouse
Applied to users
Extract via ETL
Publish view to
Or
SQL database
Emp ID Name/surname
In the datamart
6 1
Data models
Awareness User
5 2 Entity
Model
4 3 Risk score
Crown jewel
1 4 5 6
From data sources
2 3
Data tables
User data User data Risk data Crown jewel Awareness stats User data
(Name/surname) (Entity) (app risk score) indicator (Emp ID)
Source: HR system Source: HR system Source: IAM tool Source: eg Excel Source: Awareness Source: HR system
Method: Flat file Method: Flat file via Method: Data Method: Template software Method: Flat file via
via data import data import import import Method: Data import data import
Supplemental 23
Risk management framework steps
CyberMIS
Data warehouse
Applied to workstations
Extract via ETL
Publish view to
Or
SQL database
8
8 Network Network
Software status interaction
Asset ID
In the datamart
6 1
Data models
Source: Netflow
AV status Workstation Method: Data import
5 2 Emp ID
Model 7
4 3 Encr status IP address
Crown jewel
7 IP address
Source: SCCM or
Netflow
Method: Data import
1 4 5 6
From data sources
2 3
Data tables
Logon data Logon data Encryption Crown jewel Anti-virus status Software status
(Asset ID) (Emp ID) status indicator
Source: Active Source: Active Source: Encr software Source: eg Excel Source: AV software Source: SCCM
directory directory Method: Data import Method: Template Method: Data import Method: Data import
Method: Flat file Method: Flat file via import
via data import data import
Supplemental 24
Risk management framework steps
CyberMIS
Join data models on common fields
8 Network
Software status
Asset ID Emp ID Name/surname
6 1 6 1
AV status Workstation Awareness User
5 2 Emp ID 5 2 Entity
Model Model
□ Metric 1: % of unencrypted workstations for plant1 = number of Workstation Model: Encr status = “no” and
where User Model: Entity = Plant1 , divided by total count of Workstation Model where User Model: Entity
= “plant1”
□ Metric 2: % of Water Pump crown jewel users in plant1 not completing awareness training = number of
User Model:Crown jewel = “Water Pump” and User Model:Awareness = “No” and User Model:Entity =
“Plant1” divided by total count of User Model: Crown jewel = Water Pump and User Model: Entity =
“plant1”
□ Etc.
Supplemental 25
Risk management framework steps
CyberMIS
1. Accuracy and completeness of the live environment and data sources
□ Any data source item that does not join to the model becomes a reconciling item
□ Reconciling items need to be investigated and fixed eg. a missing agent for that data source
□ All fixed items will the next day join and the data sources will become more accurate and in sync
Data source 5
Data source 5
Data source 4
Data source 3
Data source 2
Data source 1
Data source 1
Data source 3
670
699
733 Valid recon items
710 710 710 710 710 Eg. new machines
730 in AD but still
712 being loaded with
other agents
Supplemental 26
Risk management framework steps
CyberMIS
2. Calculating cyber posture
Supplemental 27
Risk management framework steps
Continuous Improvement
• Is a maintenance process to
continuously review and improve risk
Formal 28
Risk management framework and process
Formal 29
Risk management process steps
Formal 32
Risk management process steps
Risk identification
• Creating an inventory of
information assets
• Classifying and organizing
Step 2 those assets meaningfully
• Assigning a value to each
information asset
• Identifying threats to the
cataloged assets
• Pinpointing vulnerable assets
by tying specific threats to
specific assets
Formal 33
Risk management process steps
Identification of technical assets
• Using scanners are common in many organisations, however it is
dangerous as it can bring systems down
• Most appropriate and safest method to obtain an accurate view of the
environment is by analysing network traffic
• Tap network traffic via span ports through popular tools eg. DarkTrace or
Qradar Network Insights
• Event collectors collect traffic via switch span ports
• Learn what is normal traffic and what not
• Artificial Intelligence and behavioural analysis
• Create accurate view of the environment and monitor for any changes
• Correlate with other sources as per CyberMIS golden data sources
Supplementary 34
Risk management process steps
Formal 35
Risk management process steps
Information Assets
Information System Risk Management Example Risk Management components
Components components
People Internal personnel Trusted employees
External personnel Other staff members
People we trust outside our organisation
Strangers
Formal 36
Risk management process steps
Information Assets Classification
Asset Internal Public Confidentiality Integrity Availability
People
Procedures
Networking
Formal 37
Risk management process steps
Formal 38
Risk management process steps
Weighted score table
Asset Criteria1 Criteria2 Criteria3 Criteria4 Weighted score
Asset1
Step 2.3.2
Asset2
Asset3
Prioritise
information assets Asset4
Asset6
Formal 39
Risk management process steps
Crown Jewels
• Assets/systems with the highest impact if compromised are crown jewels
• Crown jewels are a small number of critical systems, the rest are jewels
• Eg. an assessment could yield 30 candidates (jewels) of which 5 or 6 are critical
(crown jewels)
Scenario analysis
• Consider and review examples of cyber attacks that occurred in the world
• Analyse how those were executed
• Consider potential losses of similar attacks that could happen in the
organisation against similar crown jewels
• Consider assets end to end through what an attacker would need to accomplish
Supplementary 40
Risk management process steps
Scenario analysis (also part of external context)
Event Type Date Description Gross Loss
Loss of data 2011 Global Payments: A US payment processing company, reported that it had lost $92.5M due to information theft.
In March 2012, Global Payments reported a data breach that affected approximately .95M credit card customers.
$92.5m
Thieves accessed Global Payments' servers and stole card numbers and other information from Visa, MasterCard,
American Express, and Discover Financial Services customers.
Loss of data 2019 Capital One: This data breach ranks as one of the biggest in history. A hacker named Paige Thompson infiltrated the
servers of a third-party cloud computing company (AWS S3) contracted for use by Capital One. According to the
$150m
U.S. Department of Justice, Thompson exploited a misconfigured web application firewall to gain access to the
information.
Bangladesh central bank, reported that it lost $81M (6.2B BDT) due to a hacking incident. In early February 2016,
hackers breached Bangladesh Bank's computer systems and submitted 35 payment requests worth $951M
Loss of money 2016 (72.79B BDT) to the Federal Reserve Bank of New York (NY Federal Reserve). The hackers had the necessary codes $81m
to authorise Swift transfers from the central bank's account, and they submitted the requests on a weekend when
they would receive less scrutiny.
Loss of money 2012 Postbank: Hackers used the login credentials for two Postbank employees to gain remote access to the employees'
R42m
computers and moved funds from legitimate Postbank accounts into the bogus accounts which was then
withdrawn from ATMs
Loss of money 2016 Standard Bank: Attackers managed to withdraw money from international ATMs using 1600 cards
R300m
Loss of data 2014 Target: The attackers found their way into Target's corporate network by compromising a third-party vendor, Fazio
Mechanical, a refrigeration contractor. A phishing email caught a Fazio employee, allowing Citadel, a variant of the
Zeus banking trojan, to be installed on Fazio computers. With Citadel in place, the attackers obtained Fazio $202m
Mechanical's login credentials to Target’s network. Compromised Target servers and lastly Point of Sale devices to
steal card data. BlackPOS malware was used to scrape card details from the server memory.
Loss of systems 2017 Maersk: NotPetya malware infected the company’s network and operations ground to a halt. All end-user devices,
including 49,000 laptops and print capability, were destroyed, all 1,200 applications were inaccessible and
$300m+
approximately 1,000 were destroyed. Backups couldn’t be restored as they were immediately re-infected. Around
3,500 of 6,200 servers were destroyed and couldn’t be reinstalled.
Supplementary 41
Risk management process steps
• The impact on the business can be material and can be so severe that a well-
managed and successful organisation that is profitable and running smoothly can
be severely damaged or terminated by a single cyber incident, and needs a
comprehensive business response vs a technical response eg cyber crisis
management team (CCMT)
Hacker shuts down Rogue engineer manipulates Manufacturing plant shuts Reputational damage
manufacturing plant PLC down
Social media fallout
Hacker steals designs from Compromise of database Database extracted to the
database through SQL injection Internet
Loss of market share
Regulatory fines
Hacker extorts money by Staff member inserts a Ransomware encrypts the
shutting down operations malicious USB thumb drive Windows estate Liability for loss of life
Supplemental 42
Risk management process steps
Formal 43
Risk management process steps
Step 2.4.1
Identifying threats
Formal 44
Risk management process steps
Formal 45
Risk management process steps
Threat modelling
• Who/what is likely to attack the organisation, what methods will they use
and how will it be done
• Threat identification
• Threat actors eg nation state
• Threat vector eg USB media
• Threat event eg inject malicious software into organisational systems
Supplementary 46
Risk management process steps
• Analyse each stage to understand what could go wrong and how to defend
• Avoid right side of the BOOM
* Developed my Lockheed Martin Supplementary 47
Risk management process steps
Formal 49
Risk management process steps
Threat1
Threat2
Threat5
Threat6
Formal 50
Risk management process steps
Formal 51
Risk management process steps
Vulnerability assessment of a DMZ router
Threat Possible vulnerabilities
Compromises to intellectual property Router has little intrinsic value, but other assets protected by this device could be
attacked if it is compromised.
Espionage or trespass Router has little intrinsic value, but other assets protected by this device could be
attacked if it is compromised.
Forces of nature All information assets in the organisation are subject to forces of nature unless suitable
controls are provided.
Human error or failure Employees or contractors may cause an outage if configuration errors are made.
Information extortion Router has little intrinsic value, but other assets protected by this device could be
attacked if it is compromised.
Quality-of-service deviations from Unless suitable electrical power conditioning is provided, failure is probable over time.
Step 2.4.4
service providers
Sabotage or vandalism IP is vulnerable to denial-of-service attacks.
Device may be subject to defacement or cache poisoning.
assessment
controls are implemented.
Technical hardware failures or errors Hardware could fail and cause an outage.
Power system failures are always possible.
Technical software failures or errors Vendor-supplied routing software could fail and cause an outage.
Technological obsolescence If it is not reviewed and periodically updated, a device may fall too far behind its vendor
support model to be kept in service.
Theft Router has little intrinsic value, but other assets protected by this device could be
attacked if it is stolen.
Formal 52
Risk management process steps
Risk analysis
Step 3 •Assigning a score to
each vulnerability
•Determine likelihood
•Determine Impact
•Risk determination
Formal 53
Risk management process steps
Formal 54
Risk management process steps
Formal 55
Risk management process steps
Formal 56
Risk management process steps
Risk evaluation
• Evaluating the risk to the organization's
key assets and comparing identified
Step 4 uncontrolled risks against its risk
appetite
• Identifying individual risk tolerances
for each information asset
• Combining or synthesizing these
individual risk tolerances into a
coherent risk appetite statement
• Informs the risk treatment approach
Formal 57
Risk management process steps
Five step risk appetite process
Quantitative / Qualitative
Cascade through the security value chain
Supplementary 58
Risk management process steps
Five step risk appetite process
grid
Quantitative / Qualitative
(1) Staff, (2) Computer systems
Supplementary 59
Risk management process steps
Risk treatment
• Determining which
treatment/control strategy is
Step 5 best considering the value of the
information asset and which
control options are cost effective
• Acquiring or installing the
appropriate controls
• Overseeing processes to ensure
that the controls remain
effective
Formal 60
Risk management process steps
Formal 61
Risk management process steps
Step 5
Risk treatment
Formal 62
Risk management process steps
• Based on priorities, implement required controls and countermeasures
• Preventative controls – prevent something going wrong
• Detective controls – detect if something went wrong
• Corrective controls – fix something that went wrong
• Deterrent controls – discourage an attacker to do something wrong
• Consider resiliency controls ie. defending against unknown APT attacks
Prevention vs response
Apply more resources to prevention of high risk hazards and
more resources to response to low-risk hazards
• I don’t want high risk incidents to occur but I don’t mind to
rather respond to a low risk incident if it occurs
Supplemental 63
Risk management process steps
Process communication
• Process communication is when
risk assessment results are
Step 6 communicated to organisational
decision makers to support risk
responses.
• The communication can be
formal or informal and can
happen through executive
briefings, risk assessment
reports, dashboards
Formal 64
Risk management process steps
Formal 65
Thank you
66