0% found this document useful (0 votes)
13 views12 pages

NIST Risk Assessment Methodology Overview

Uploaded by

dylanmao1231
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
13 views12 pages

NIST Risk Assessment Methodology Overview

Uploaded by

dylanmao1231
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Guide to Conducting Risk Assessments

Overview of NIST Special Publication 800-30, Revision 1

NIST Risk Management Framework (RMF) Team


sec-cert@[Link]
Risk Management Framework Overview

The RMF provides a structured, yet flexible process


for managing cybersecurity and privacy risk to
information & systems that includes system
categorization, control selection, implementation,
assessment, authorization, and continuous
monitoring.

2
Risk Management Framework Steps
Essential activities to prepare the organization
to manage security and privacy risks
Categorize the system and information
processed, stored, and transmitted based on an
impact analysis
Select the set of NIST SP 800-53 controls to
protect the system based on risk assessment(s)
Implement the controls and document how
controls are deployed
Assess to determine if the controls are in place,
operating as intended, and producing the
desired results
Senior official makes a risk-based decision
to authorize the system (to operate)
Continuously monitor control implementation
and risks to the system 3
Risk Management and Risk Assessment
• Risk assessment is a key component of a holistic risk
management process (as defined in NIST SP 800-39, Managing
ASSESS
Information Security Risk: Organization, Mission, and System
View)

• Risk management processes include:


FRAME • Framing Risk
• Assessing Risk
• Responding to Risk
MONITOR RESPOND
• Monitoring Risk

4
Framing Assessment
Establishing the context for how Identify threat sources & events,
ASSESS
organizations manage information vulnerabilities, determine risk (impact &
security risk likelihood) & uncertainty

FRAME
RISK
MONITOR RESPOND

Response Monitoring
Develop risk response strategy (accept, Verify implementation, determine
reject, mitigate, share/transfer risk) & effectiveness of risk mitigation
courses of action measures, identify changes

5
Key Terms in Risk Assessment

Risk
Risk Assessment Threat

Vulnerability Impact Likelihood

6
Organization-Wide Risk Assessment
Broad-based risk perspective

Strategic
Focus
Level 1: Support organization-wide
strategies/policies/procedures Level 1
Organiza�on

Level 2: Support determination of


Level 2 Tac�cal
mission/business process protection, inform
Mission / Business Process Focus
decisions on use of systems

Level 3
Level 3: Focused on individual systems, System (Environment of Opera�on)
can be conducted during each step of
More detailed and granular risk perspective
the RMF

Three Levels of Organiza�on-Wide


Risk Management 7
NIST SP 800-30, Revision 1: Organization

Chapter 1 - Introduction
Risk Assessment Goal
Chapter 2 – Process overview and terminology

Chapter 3 – Risk assessment process activities • Determination of risk


Supporting appendices, including: • What is the degree of
• Threat sources and threat events potential harm?
• Vulnerabilities and predisposing conditions • How likely would such
• Likelihood of threat occurrence
• Impact harm occur?
• Risk and uncertainty
• Prioritization of risks

8
Risk Management Framework Steps
Essential activities to prepare the organization
to manage security and privacy risks
Categorize the system and information
processed, stored, and transmitted based on an
impact analysis
Select the set of NIST SP 800-53 controls to
protect the system based on risk assessment(s)
Implement the controls and document how
controls are deployed
Assess to determine if the controls are in place,
operating as intended, and producing the
desired results
Senior official makes a risk-based decision
to authorize the system (to operate)
Continuously monitor control implementation
and risks to the system 9
Risk Assessment (RA) Process

Prepare Conduct Maintain

Identify Identify scope Identify threat Identify threat Ongoing


purpose of RA of RA sources events Monitoring

Identify Identify Update RA


Identify Determine
assumptions sources of using results
vulnerabilities likelihood
& constraints information of monitoring

Determine
Define or Determine
adverse
refine the risk risk
impacts
model

10
Assessment Approaches

Quantitative Qualitative
• Based on numbers where proportionality of • Based on non-numerical levels such as low,
values is maintained in and out of the context of moderate, and high
the assessment; higher degree of repeatability
• Results typically easier to convey to decision
• Qualitative-like subjective interpretations may makers
still be involved
• Extra work required to ensure repeatability and
• Benefits may be outweighed by costs in time, reproducibility
effort, and tools

Semi-Quantitative
• Based on scales or representative numbers
whose values/proportions are not maintained in
other contexts, e.g., 0-15, 16-35, 35-70, 71-85,
86-100)
• Expert judgment needed to assign values
appropriately/reduce subjectivity

11
STAY IN TOUCH
CONTACT US
[Link]/RMF sec-cert@[Link]

@NISTcyber

12

You might also like