0% found this document useful (0 votes)
15 views13 pages

Risk Management Concepts Explained

Risk Management

Uploaded by

aderoyeke
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
15 views13 pages

Risk Management Concepts Explained

Risk Management

Uploaded by

aderoyeke
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

T OP IC 1

RISK
MANAGEMENT
CONCEPTS

ASSURANCEHILL CONSULTING 1
Risk Management is the consideration and implementation of any number of
resources, processes, or procedures used in determining (identifying), analyzing,
remediating/ response, and monitoring risk-related activities (or events)
Risk is the product of the likelihood of occurrence (p) of a threat event (both
non-adversarial and adversarial) successfully exploiting a vulnerability and the
associated impact (i) of such event successfully occurring

❑ Risk is the potential/possibility of an event occurring which means it has


not occurred
❑ Risk Equation → P (likelihood) x I (impact)
❑ Risk Factors → the aggregate of threat, threat events, vulnerability, and
impact
❑ Risk can be measured quantitatively (using metrics/values), qualitatively
(based on judgment), or semi-quantitative (hybrid) approach

WHAT IS RISK MANAGEMENT ?


ASSURANCEHILL CONSULTING 2
Risk management activities should follow a holistic (top-down) approach so that
risks are properly addressed organization-wide
That means, risk management should traverse all three tiers of the organization,
starting from the top

❑ Tier 1 – organizational officials such as the C-level executives are responsible for
creating, designing, and enforcing risk management policies → LEADERS
❑ Tier 2 – organization managers/ or business leads are responsible for interpreting
those organizational policies and drafting applicable procedures that strategically
aligns to the policies → ENFORCERS
❑ Tier 3 – information system owners and system specialists are responsible for
ensuring compliance with procedures and their daily operations are sufficient and
effective in driving down organizational risks → DOERS

HOLISTIC APPROACH
ASSURANCEHILL CONSULTING 3
The Holistic Approach to Risk Management requires:
❑ Risk management activities occur at both the enterprise- (organization) level and system-level;
but not one or the other

❑ As such, risk assessment activities must be performed at the enterprise level


(GSS/Network/Infrastructure) and system (application) level

❑ All types of risks must be considered such as technical risks, reputational risks, business/
operational risks, security risks...compliance risk in order to have a full perspective of the
organizational risk posture

Through a thorough risk management exercise, organizations would identify


❑ Critical and non-critical assets such as information and systems
❑ As a result, strategically identify and allocate resources to safeguards or protect these assets,
especially critical ones
❑ These safeguards/countermeasures are called CONTROLS

HOLISTIC APPROACH
ASSURANCEHILL CONSULTING 4
What is the relationship between Security and Risk?

Why is it important to identify critical vs. non-critical assets?

Why should the identification of critical assets be performed more than once,
perhaps on an ongoing basis?

Are critical assets the only resource that must be safeguarded?

QUESTIONS
ASSURANCEHILL CONSULTING 5
Risk Management Framework is a structured methodology/ model/ guide used
for managing risks to organization assets (information, system, humans), to
ensure continuous business operation in the organization
❑ In government, the current risk management framework used to manage security-risk is called
NIST-RMF
❑ The NIST-RMF is a framework that evolved in 2013 from the previous models DIACAP-RMF
and DISTCAP-RMF
❑ There are other risk management framework for non-government entities such as COBIT 5.0 –
Governance of Enterprise IT (GEIT)

Organizations should select which risk management framework implement. In


considering the ever-changing security-threat landscape and innovation in
technology; organizations should select a framework that is robust and
customizable to address various risks for various systems (such as legacy,
minor, ERP)

SELECTING A RISK MANAGEMENT


FRAMEWORK
ASSURANCEHILL CONSULTING 6
The process of managing risk within an organization (as adopted by NIST)
includes these phases:

❑ Risk Framing/Scoping – draw a boundary (or define the areas for risk management)
and select the risk management framework that is most suitable to address the
related risks
❑ Risk Identification – identify assets, threats, threat events, and vulnerabilities
❑ Risk Assessment – Quantitative, Qualitative, Semi-Quantitative analysis of threats
and vulnerabilities.
❑ Risk Response – acceptance, avoidance, sharing, mitigation, and exploitation.
Prioritization of risk is important here
❑ Risk Monitoring – developing risk monitoring strategies, implementing security
controls, monitoring risky behaviors

THE RISK MANAGEMENT PHASES


ASSURANCEHILL CONSULTING 7
You are the Cybersecurity Risk & Compliance Advisor for Adveris Data Records Processing Solutions
(ADRPS); a company that manages healthcare records in digital formats for its clients across the
country. ADRPS is currently located in Key West, Florida. There has been a justified business need to
increase the current processing capabilities; hence acquire a new larger facility and a host of data
processing systems including new employees.
Currently, most of your operations are considered highly critical because it deals with sensitive data
records that must be digitalized. The CIO has requested your input in the plan to migrate current
processing capabilities to a new facility that is larger and more technically equipped to handle the
growing business needs. The senior executive leadership has considered an incomplete commercial
property that is adjacent from the current site due to its geographic proximity. They believe that it
will be an easier lift and shift from a technical and financial standpoint.
The new larger facility is directly adjacent and considerably operable below the ground because it
has some of the physical infrastructure in place. However, significant work must be done which
could take another year to complete. Senior management thinks this will be a good acquisition and a
right decision in the migration plan. This facility has not been fully constructed above ground. Due
to the critical nature of your operations, you always require your critical operations be housed
underground. They would like to make the acquisition immediately and start migration of physical
infrastructure by Fall 2020, while other major construction is occurring. You were asked yesterday,
July 16, 2021, for you input. Is this the right step to make? Provide your recommendations.

CASE STUDY
ASSURANCEHILL CONSULTING 8
Threat Source/Threat Event
❑ Natural Disaster i.e. Tornado is a threat source
❑ Facility temporary shutdown/delay is the threat event

Vulnerability/Predisposing condition
❑ Portion of the new facility will be under construction during migration

Likelihood of Occurrence
❑ There is a 40-50% chance of hurricane occurring every year in Florida which has been assessed as Moderate
occurrence

Impact
❑ Physical property damage cause electrical outage, loss of human life, and disruption of business operation
which has been deemed High impact

Risk
❑ Qualitative i.e. Low, Mod, High
❑ Quantitative values i.e. 60, 78, 88
❑ Risk determination is Moderate-High or 80

CASE STUDY ANALYSIS


ASSURANCEHILL CONSULTING 9
Risk Impact
Determination High Moderate Low

Likelihood of Occurrence
High High Mod-High Mod

Moderate Mod-High Mod Mod-Low

Low Mod Mod-Low Low

SAMPLE RISK MATRIX


ASSURANCEHILL CONSULTING 10
These are some considerations when performing a risk assessment
❑ Timeframe
o Short-term: Loss of operation, Life, and physical assets
o Long-term: The business operation could face legal actions which can significantly impact
their operation financially. They may suffer significant business loss.

❑ Cumulative Impact
o Single Loss Expectancy - Loss associated from a single occurrence of risk event. Calculated
as a factor of Asset Value (AV) and Exposure Factor (EF).
➢ SLE = AV x EF
➢ AV is the valuation of assets that could be affected
➢ EF is the loss (in %) that could impact each asset
o ALE is annualized Loss Expectancy and ARO is Annualized Rate of Occurrence
➢ ALE = SLE x ARO

CONDUCTING A RISK ASSESSMENT


ASSURANCEHILL CONSULTING 11
Risk Response is the set of activities employed to treat or remediate identified
risks

❑ Risk Acceptance - within risk tolerance level; accept!


❑ Risk Avoidance – outside risk tolerance level; choose alternative option
❑ Risk Sharing/ Transference – share risk with other organizations; obtain insurance
or warranty
❑ Risk Reduction/ Mitigation – reduce risk!

RISK RESPONSE/REMEDIATION
ASSURANCEHILL CONSULTING 12
What is the difference between Risk, Issue, and Problem?
What is the difference between Assessment and Analysis?
What is the difference between Result and Report?
What is the difference between Remediation and Mitigation?
What is the difference between control and security control?
When do we accept risk versus avoiding risk?
How do we justify acceptance of risk?
How do we reduce the risk?

QUESTIONS
ASSURANCEHILL CONSULTING 13

You might also like