IT Risk Management Assignment
Executive summary
IT risk management, often known as "information security risk management," comprises of
a company's policies, processes, and technologies for mitigating risks from hostile actors
and reducing information technology vulnerabilities that jeopardize data confidentiality,
integrity, and availability. Measuring information technology risk, which contributes
significantly to information security risk, continues to be a difficulty for many businesses.
Furthermore, present information technology risk measurements mostly refer to tactical
security risk indicators rather than strategic security risk indicators. An excess of data
obtained from information security technology solutions may actually make risk
assessments more difficult.
We are going to look at the role of the risk consultants, due diligence, internal and external
auditors, the risk management goal, FUD and analyzing and preventing information
technology risks and threats.
Background: Role of IT Risk Consultant
IT risk consultants use their understanding of information technology to help firms reduce
or eliminate risks to IT systems and data. They help customers in detecting, analyzing, and
controlling risks connected with important commercial information technology systems
such as computers and networks. They enable clients to strengthen internal controls and
corporate assurance frameworks while addressing risks and identifying risky opportunities.
IT risk consultants:
create risk policies and processes that adhere to corporate requirements.
examine company processes to determine risk levels.
assist in the risk analysis and management of business systems.
develop risk management strategies in collaboration with the manager.
work with the HR staff to recruit and train new personnel.
assist with internal audits and put audit recommendations into action.
assess possible hazards and devise risk-mitigation strategies.
create best practices for risk management and reduction initiatives.
provide knowledgeable answers to risk-related queries and concerns.
examine and make suggestions for improvements to risk modeling methodologies.
They help to secure the company's information technology system by safeguarding
computers, servers, and wireless networks. They utilize anti-virus and anti-spyware
protection, as well as firewalls, and they update software to the latest versions on a regular
basis. They also educate personnel on IT rules and procedures and keep the company's
credentials secure. Their primary responsibility is to access and assess any IT threats.
Definition and application of ‘due diligence’
Due diligence is the process or effort of gathering and analyzing information before to
deciding or completing a transaction so that a party is not legally accountable for any loss
or damage. As a result, due diligence in IT risk has been described as "a evaluation of the
governance, procedures, and controls utilized to safeguard information assets." It is
basically the process of monitoring, recognizing, and mitigating third-party vendor cyber
hazards.
Cyber security firms gather information on an organization's third-party vendor
cybersecurity posture and IT security activities throughout the due diligence process. The
customer is then aware of the dangers and vulnerabilities that might arise from
relationships with third-party providers and can take appropriate action.
Conducting cybersecurity due diligence is tremendously valuable to businesses all around
the world. It not only properly assesses risk before taking on liability in mergers and
acquisitions, but it also detects any concerns that may need a transaction modification.
Furthermore, it assists organizations in understanding the cyber security landscape and
identifying risks. It also enables the assessment and identification of a company's overall
cybersecurity posture. Due diligence is primarily used to reduce risk exposure. The
procedure ensures that both parties are aware of all the details of a transaction before
agreeing to it. A broker-dealer, for example, will provide the contents of a due diligence
report to a client so that the investor is fully aware and cannot hold the broker-dealer liable
for any losses.
Internal & External Auditors
Internal audit plays an important role in assisting organizations in their ongoing battle to
manage cyber threats, both by providing an independent assessment of existing and
required controls and by assisting the audit committee and board in understanding and
addressing the diverse risks of the digital world. Cyberattacks pose a significant and ever-
changing threat. Many audit committees and boards of directors have made it a
requirement for internal audit to understand and assess the organization's capabilities in
managing the associated risks. Our experience shows that conducting a cyber risk
assessment and distilling the findings into a concise summary for the audit committee and
board is an effective first step for internal audit, which will then drive a risk-based,
multiyear cybersecurity internal audit plan. Your organization can confidently assess where
it stands in terms of security risks and compliance with state and federal regulations by
utilizing an external IT audit. An audit identifies potential security issues so that they can be
addressed before they cause a damaging breach. Employee actions, natural disasters, and
malicious attacks such as ransomware, phishing, and viruses can all be considered IT
security threats. An external auditor can assist you in ensuring your organization has the
necessary security measures in place. Internal auditors look at their organization's
governance, risk, and control systems holistically (in other words, primarily non-financial
information), whereas external auditors are concerned with the accuracy of business
accounts and the organization's financial condition, or, in some industries, the
organization's compliance with laws and regulations.
There are several distinctions between internal and external audit functions, which are as
follows:
Internal auditors work for the corporation, whereas external auditors work for an
outside audit firm.
Internal auditors are engaged by the corporation, whereas external auditors are
elected by shareholders.
Internal auditors are not required to be CPAs, however external auditors must be
directed by a CPA.
Internal auditors report to management, but external auditors report to
shareholders.
Internal auditors can communicate their findings in any manner, however external
auditors must utilize certain templates for audit opinions and management letters.
The internal auditor's goal is to analyze normal activities and make suggestions for
improvement. The role of the external auditor is to study and verify the company's financial
statements.
IT risk management's goal
IT risk management, also known as "information security risk management," consists of a
company's policies, procedures, and technologies for mitigating threats from malicious
actors and reducing information technology vulnerabilities that jeopardize data
confidentiality, integrity, and availability. Organizations can better prepare for cyberattacks
and reduce the impact of a cyber incident if potential vulnerabilities in their enterprise IT
network are identified and analysed. An IT risk management program's procedures and
policies can help guide future decision-making about how to control risk while focusing on
company goals. The goal of IT risk assessment is to bring your IT department and
organizational decision-makers together in order to strengthen cybersecurity. With a clear
understanding of your IT vulnerabilities and the value of your data assets, you can improve
your security policy and practices to better defend against cyberattacks and protect your
critical assets. The goal of the risk assessment process is to evaluate hazards, then remove
or reduce the level of risk by implementing control measures as needed. You have thus
created a safer and healthier workplace. The goal of risk management is to maximize the
organization's output (in terms of services, products, and revenue) while minimizing the
possibility of unanticipated negative outcomes. You can think of this in terms of reducing
uncertainties about your company's products and services, or aligning and controlling
organizational components to maximize output. The goal should never be to have no
exposure, but to strike the right balance. It all comes down to making well-informed
decisions. The security program should serve as a governance and oversight function,
assisting in the identification of risks that have the greatest potential to harm the
organization with the greatest severity.
Role of an external consultant versus the full‐time IT employee.
An external consultant is someone recruited from outside the company to perform the
assessment; they may create the evaluation design or implement the design stated in the
Terms of Reference. The main difference between external and internal consultants is their
clients. External consultants operate with a wide range of companies and have a diversified
customer base. They seldom work with the same firm on a regular basis. Internal
consultants operate continually within one firm and do not seek employment from outside
companies, therefore their customer is always the same.
Risk identification is the act of noting any dangers that might impede an organization or
program from accomplishing its purpose. It is the first phase in the risk management
process, and it is designed to help firms recognize and plan for potential hazards. Finally, it
is the employer's obligation to guarantee that a risk assessment is performed in the
workplace. This does not imply that the employer must do the risk assessment themselves;
they can choose someone else inside the business to undertake the risk assessment and
ensure that all health and safety regulations are met. This individual must be qualified to
perform all health and safety duties, beginning with risk assessment.
External consultants can be utilized when highly specialized knowledge is required for a
large-scale project, or when a neutral, independent perspective on an issue is required,
which is preferable in some instances. Sometimes an organization just lacks the internal
competence to address a certain issue, or the board need outside experience to fully
analyze the risks of the choices available. Internal advisers, on the other hand, are familiar
with the company and are aware of what is going on within it, particularly because they
understand the culture of the professionals who work there. Furthermore, employing an
external consultant might be an expensive commitment, whereas an inside adviser may be
a better cost-effective option.
Fear, Uncertainty and Doubt
FUD tactics are used to terrify customers into purchasing a product or utilizing a service,
and they rely on the customer's lack of information to make their own decision. Fear,
Uncertainty, and Doubt are important emotions that, when activated (jointly or
independently) at the proper time and place, may guide visitors in the correct path,
benefiting both the value seeker (them) and the value supplier (us) (you). FUD can and is
used to urge readers/customers to question their assumptions/capabilities so that they
might learn more and perform better. The IT business was infamous for employing FUD
psychology to outdo one other by disseminating misleading information about their
competitor's goods.
This enhanced client retention, but only through psychological manipulation. FUD
strategies, on the other hand, are seen favorably in today's digital marketing world since
they yield results. Fear, Uncertainty, and Doubt are no longer utilized to exploit or deceive
customers, but rather to assist them in achieving their commercial or professional
objectives more quickly and effectively. It all starts with the word 'fear.' The fear of falling
behind or losing a significant advantage/edge if a particular action is not taken. It may help
your business, employment, skill set, and even your personal safety.
Fear, Uncertainty, and Doubt (FUD) are no longer used to raise funds or resources for
initiatives in the information security industry. The business is growing more complex,
management is learning to ask the correct questions, and we must be prepared to respond
appropriately. You may spend a substantial amount of time and work defending the
expense of your program and future efforts, especially in challenging economic
circumstances. Many companies have only engaged in information security after suffering
the consequences of a large data breach. Your objective is to avoid becoming one of those
companies, but it requires preparatory investigation to establish how to effectively utilize
your limited resources.
When presenting your argument to company leaders, you must talk in their language. Begin
by explaining how this weakness will affect their bottom line and how probable it is that it
will occur. You may take advantage of the fact that risk is a common language that
company managers will comprehend. It is vital to demonstrate that you have done your
study before presenting your case to top management. Justification will not be found in a
gut sensation.
Project managers and their teams will be kept on their toes by the promise of project
success and the dread of failure. Regardless of the strategy taken or where project efforts
are directed, the ultimate outcome contains all of the suspense—and keeps us focused on
it. Projects Require Executive Management Assistance to:
1. Clarify organizational/strategic objectives: Organizational/strategic objectives might
include increasing market share, maximizing profitability, establishing new trends,
leveraging technology for corporate success, or developing an innovative product. In
a nutshell, senior management assists in clearly defining and clarifying strategic
objectives and expectations so that the project is completed and delivered in
accordance with the strategic aim and fulfills the entire company purpose.
2. The second most important reason for senior management assistance is to assure
adequate project finance. The financing mechanisms are established and determined
by the nature of the programs/projects, the cost, and the total impact.
When addressing continuity planning, many individuals emphasize on the FUD (Fear,
Uncertainty, and Doubt). It is true that one of the most important advantages of a solid
continuity program is that it reduces the effect of unexpected accidents. Instead,
concentrate on the positive: you'll be selling tomorrow. A solid program will guarantee that
your business is ready for whatever the future holds. Fear, Uncertainty, and Doubt (FUD)
will not bring you extra resources on their own. While a recent data breach or major
ransomware incident can occasionally be utilized as a tasty appetizer before the cyber main
meal in a presentation, I learnt a long time ago that security professionals will fail if they are
always providing negative news.
IT department and intrusion detection
The Intrusion Detection System (IDS) is a detective device that detects harmful (including
policy-violating) activity. An Intrusion Prevention System (IPS) is essentially a preventative
device that is meant to not only detect but also to prevent hostile activity. IDS are
developed to give preparedness to prepare for and deal with cyber threats. This is
performed by gathering data from various systems and network sources, which is then
assessed for security flaws. In general, intrusion detection systems (IDS) are used to
monitor and analyze user and system activity, audit system configurations and
vulnerabilities, assess the integrity of any critical system and data files, perform statistical
analysis of activity patterns based on matching to known attacks, detect abnormal activity,
and audit operating systems.
To prevent intrusion, companies persuade employees to:
Restriction of Employee Access to Your Data & Information
Limiting access to your critical corporate data decreases the possibility of human mistake,
which is the leading source of information security threats. Employees should only have
access to the systems and information required to do their duties. If an employee quits
your organization or transfers to another location, take quick precautionary measures, such
as erasing passwords and accounts from all systems and collecting corporate ID badges and
entrance keys. When it comes to reducing the effect of a dissatisfied ex-employee, an
ounce of access prevention can equal a pound of protection.
They update their operating systems and software on a regular basis.
If they don't constantly patch and update all software on every device used by staff, any
new app might open the door to a cyber assault. When acquiring a new computer or
installing a new software system, always check for updates. It's important to remember
that software companies aren't compelled to issue security updates for unsupported
programs. For example, Microsoft will cease support for Windows 7 in January 2020, so if
they haven't already updated, now is the time. Don't put off installing operating system
updates. These upgrades frequently incorporate new or improved security measures.
Firewalls, both software and hardware, must be installed and activated.
Firewalls can protect against harmful hackers and prevent employees from visiting
undesirable websites. Install and maintain firewall software on all staff computers,
smartphones, and networked devices. Include workers who work remotely, even whether
they use a cloud service provider (CSP) or a virtual private network (VPN) (VPN). They may
also wish to install an intrusion detection/prevention system (IDPS) for further security.
In most cases, an intrusion detection system is implemented in-line to actively prevent or
stop invasions as they occur. A certain IP address, for example, can be automatically
banned, with an alert given to the administrator if an attempt is made. These are just a few
of the measures you may take to protect your company's network. Other security
alternatives for organizations exist, but the four procedures listed above are a solid place to
start when it comes to keeping your network safe.
IT Risk ‘Best practices’
Since the world has shifted to the digitalization of all processes, there is a great deal of
sensitive information that must be safeguarded. Sensitive data from customers and
consumers might be kept on the systems of any firm. It is critical to protect this data in
order to reduce any hazards to the firm. These principles are critical to ensuring that your
risk management deployment goes well.
The following are the top risk management best practices in IT:
Create Risk Management Awareness.
Institutions must raise awareness of the IT risks that they confront inside the organization.
In a recent research, approximately 60 percent of CEOs regarded cybersecurity as one of
the most serious risks within the firm. Organizations can become aware of the dangers they
face in a variety of ways. The first stage is to identify all of the hazards that might develop
into potential threats. After that, they will be able to begin developing an effective
framework to address the dangers. They must have effective data recovery procedures in
place in the event that the IT department loses the data. Team members must also take
rigorous precautions to avoid security breaches and keep track of who they grant access to.
Scalability must be managed.
Every business is supposed to develop over time, and as it does, the risks get more
complicated. This means that the risk management platform must be scalable in order to
keep up with the company's expansion. Scalability concerns may develop, and protocols
should be in place to assist enterprises in smoothly migrating to alternative apps. Because
of internal concerns inside the organization, this may not always be the case. These
concerns must also be addressed by a risk management platform.
If sensitive data is lost or exposed, the implications might range from humiliation or
reputational harm to substantial legal culpability in the worst-case scenario. That is why it is
critical to ensure that your personal data is always secure - not just while you are using it,
but also thereafter. Data security will not occur by itself. Someone must accept
responsibility for it, and they must have the power to establish rules and processes for
others to follow. Part of their responsibilities will include developing a security policy and
ensuring that everyone knows it.
IT Risk as a ‘Moving target’
Moving target — As we improve at safeguarding our systems, attackers devise more and
more inventive ways to circumvent our defenses. They create more complex assaults as we
block the easy entry points. It is a never-ending struggle.
The concept of risk is a moving target.
Because the environments you defend are always changing, you must account for changes
in risks and exposures in your risk management workflow. There are several occasions
where a re-evaluation is required (essentially restarting the assessment cycle), including the
following:
• A shift in the target resource's sensitivity.
• There has been a substantial shift in the danger landscape.
• A change in legal/regulatory requirements.
• An alteration in security policy.
• On a timetable dependent on the resource's risk sensitivity.
It is vital to remember that the sensitivity of a resource might alter over time if its intended
purpose changes, new forms of sensitive data are added, or the organization's goals shift. It
is the responsibility of the resource owner to alert the security team of any substantial
changes that may need an out-of-cycle assessment, and it is the responsibility of the
security team to remain up to date on changes in the threat environment in order to
educate the resource owners. Any significant modifications to the design, intended
application, client base, or execution should need a fresh evaluation. Consider it similar to
controlling the categorization of a document.
The same is true for your resources: if the sensitivity of the data being handled changes, the
controls around that resource must be re-evaluated. You may accept specific restrictions
for a server or application knowing that it would not process sensitive data; yet, later on,
someone may decide to broaden the scope of that system to include a sensitive function.
The intended use is critical when attempting to understand why controls failed in various
breach incidents; you will frequently discover that the controls were suitable for the
system's original use, but that the controls did not develop as the scope of the system
evolved.
IT risk management workflow
Dissimilarities between threat assessment, vulnerability assessment
and risk assessment.
What exactly are threats?
Threats have the ability to steal or damage data, disrupt business, or cause general harm.
What exactly is vulnerability?
A vulnerability is a flaw in your hardware, software, or operations. It's a vulnerability that
allows a bad actor to obtain access to your assets. Threats, in other words, take advantage
of weaknesses.
What exactly is risk?
The junction of assets, threats, and vulnerabilities is known as cyber risk. When a threat
exploits a vulnerability, it has the potential to cause an asset to be lost, damaged, or
destroyed.
The distinctions between threat, Vulnerability and risk assessment.
The distinctions between threat, vulnerability and risk are subtle, but vital to understand.
Consider a threat to be an outside force, or an attacker, who may do harm to your system.
It might take the shape of a virus, malware, or even a genuine hacker. You've been
threatened if someone breaches into your system or hacks into your accounts. Your
security system works to keep threats from causing harm.
A threat assessment examines your system to determine whether assaults are already
taking place or which attacks are being threatened. Threat assessments can gather
information about assaults before they occur, which can assist evaluate the scope and
severity of a threat and how it may affect an organization. It's a more reactive approach to
IT security, and it's a good option for businesses that need to know what's going on in their
system and what concerns need to be fixed right soon.
Risk appears to be quite similar to threat, but consider this: although a threat is the
attacker itself, a risk is the level to which an attack (or other unanticipated occurrence) may
cause harm. The probability of damage occurring as a result of flaws in your security
system, unanticipated occurrences, or human mistake is referred to as risk. Essentially, your
business is your home, and your information technology system is the locks and doors.
Someone attempting to enter uninvitedly is a threat, whereas leaving your doors and
windows unsecured is a risk.
A risk assessment, like a threat assessment, examines your system for security flaws. They
include threats to company continuity, catastrophe recovery, data recovery, staff skill set /
aptitude, and even equipment power and cooling. It is, nevertheless, a more proactive
approach to IT security. These risk assessments must consider risk from top to bottom, as it
might be anything that has the capacity to interrupt operations. While threat assessments
look at issues when they happen or are attempted, risk assessments look at a larger range
of possibilities to identify prospective problems and the extent of potential damage.
Vulnerabilities are defects in a computer system that reduce the device's or system's
overall security. Vulnerabilities can be flaws in the hardware itself or in the software that
runs on it. A threat actor, such as an attacker, can exploit vulnerabilities to breach privilege
boundaries (i.e. execute illegal activities) within a computer system. An attacker must have
at least one appropriate tool or method that can connect to a system flaw in order to
exploit a vulnerability. In this context, vulnerabilities are often referred to as the attack
surface.
Vulnerability assessments also deal with identifying and addressing risks to the firm. A
vulnerability assessment, as opposed to a risk assessment, focuses on detecting internal
flaws that might evolve into threats. A vulnerability assessment defines, detects,
categorizes, and prioritizes all of the vulnerabilities that exist in the company's numerous
applications, network infrastructures, and computer systems.
Risk Exposure Factors
Qualitative risk management and risk assessment are the two risk exposure elements. The
purpose of qualitative risk management is to put into place a paradigm that goes beyond
just classifying a scenario or issue as "risky." By explicitly describing the sensitivity of the
resource, the degree of the vulnerability, and the likelihood of the threat, a well-designed
qualitative model may assist in identifying the most probable effect to the business.
Identifying threats and vulnerabilities, as well as assessing each combination to obtain a
final risk exposure value, are all part of risk assessment.
In business, risk exposure is typically used to estimate the possibility of various types of
losses in order to determine whether losses are acceptable or undesirable. Losses can
include legal liability, property loss or damage, unanticipated employee turnover, and
changes in consumer demand, to name a few.
Risk Control Measures
Most modern firms face threats and dangers to their information technology (IT) systems
and data on a daily basis. You should put safeguards in place to secure your systems and
data against theft and hackers.
These are the following risk control measures one should take:
Use secure passwords.
Strong passwords are essential for internet security.
Use a combination of capital and lower-case characters, numbers, and symbols to
make your password tough to guess.
The password should be between eight and twelve characters long.
Prevent the use of personal information
Make sure it is often changed.
It should never be used for numerous accounts.
Two-factor authentication must be used.
Access Control
Ensure that individuals can only access data and services for which they have been granted
access. You can, for example,
regulate physical access to buildings and computer networks.
Unauthorized users should be denied access.
Application controls can be used to restrict access to data or services.
Limit the amount of data that may be copied from the system and stored to storage
devices.
Limit the sending and receiving of specific email attachments.
Make use of security software.
Security software, such as anti-spyware, anti-malware, and anti-virus tools, should be used
to identify and delete bad code if it enters your network. Learn how to identify spam,
malware, and virus threats.
Conclusion
The risk analysis method aids the organization's effective and efficient operation by
identifying those hazards that demand management's attention. They will need to prioritize
risk management activities based on their potential to benefit the organization. The
effectiveness of internal control refers to the extent to which the suggested control
measures would either eliminate or minimize the risk. Internal control cost effectiveness
refers to the cost of implementing the control in relation to the predicted risk reduction
advantages. The proposed regulations must be weighed in terms of the possible economic
impact if no action is taken vs the cost of the proposed actions, and this will necessarily
need more comprehensive information and assumptions than are now available.
For IT systems, risks must be adequately evaluated and managed. Some project managers
neglect to evaluate project risks, resulting in project failure. According to risk management,
we must thoroughly assess risks since firms do not want to squander time, staff, or incur
unanticipated expenditures. The use of risk assessment approaches in projects aids in the
prevention of potential damage to an organization's systems. Cost, reputation, and time are
all vital to the company, thus risk management must be used with caution.
In this assessment we learned the following:
Risk definition and risk management
Developing approaches for risk assessment.
Identification of potential threats.
Identification of Vulnerabilities
Analysis of Control.
Estimation of Likelihood.
How risk is managed