Risk Management
Risk Management
Risk Management
• The process of identifying risk, assessing its relative magnitude,
and taking steps to reduce it to an acceptable level.
risk appetite
• The amount of risk an organization is willing to accept.
residual risk
• The amount of risk that remains to an information asset even
after the organization has applied its desired level of controls.
Risk Management
Three Major Undertaking of Risk Management:
1. Risk Identification
• The enumeration and documentation of risks to an organization’s
information assets.
2. Risk Assessment
• A determination of the extent to which an organization’s
information assets are exposed to risk.
3. Risk Control
• The application of controls that reduce the risks to an
organization’s information assets to an acceptable level.
Components of Risk Management
Components of Risk Identification
1. Planning and Organizing the Process
• Begin by organizing a team, which typically consists of
representatives from all affected groups.
• The process must then be planned, with periodic deliverables,
reviews, and presentations to management.
2. Identifying, Inventorying, and Categorizing Assets
• This iterative process begins with the identification and
inventory of assets, including all elements of an organization’s
system, such as people, procedures, data and information,
software, hardware, and networking elements.
Components of Risk Identification
People, Procedures, and Data Asset Identification
• Identifying assets for human resources, documentation, and
data.
When deciding which information assets to track, consider the
following asset attributes:
People: Position name, number, or ID (avoid using people’s names
and stick to identifying positions, roles, or functions); supervisor;
security clearance level; special skills.
Components of Risk Identification
Procedures: Description; intended purpose; relationship to
software, hardware, and networking elements; storage location for
reference; storage location for update.
Data: Classification; owner, creator, and manager; size of data
structure; data structure used (sequential or relational); online or
offline; location; backup procedures employed.
Components of Risk Identification
Hardware, Software, and Network Asset Identification
• The attributes to be tracked in hardware, software and network
assets depends on the needs of the organization and its risk
management efforts.
1. Name
2. IP Address
3. Media Access Control (MAC)
4. Element Type
5. Serial number
6. Manufacturer name
7. Manufacturer’ model number or part number
8. Software version
9. Physical Location
10 Logical Location
11. Controlling Entity
Components of Risk Identification
Asset Inventory
• Creating an inventory of information assets is a critical function
of understanding what the organization is protecting.
• The inventory process is critical in determining where
information is located; most commonly it is in storage.
• Not all information is stored in databases. A great deal of an
organization’s information is stored in hard copy—in filing
cabinets, desks, and in employee hands and briefcases.
Components of Risk Identification
Categorizing the Components of an Information System
Components of Risk Identification
3. Classifying, Valuing, and Prioritizing Information Assets
Data Classification and Management
• Corporate and government organizations use a variety of
classification schemes. Many corporations use a data
classification scheme to help secure the confidentiality and
integrity of information.
Data Classification Scheme
• A formal access control methodology used to assign a level of
confidentiality to an information asset and thus restrict the
number of people who can access it.
Components of Risk Identification
The information classifications are as follows:
1. Confidential
• Used for the most sensitive corporate information that must be
tightly controlled, even within the company.
• Access to information with this classification is strictly on a
need-to-know basis or as required by the terms of a contract.
• Information with this classification may also be referred to as
“sensitive” or “proprietary.”
Components of Risk Identification
The information classifications are as follows:
2. Internal
• Used for all internal information that does not meet the criteria
for the confidential category.
• Internal information is to be viewed only by corporate
employees, authorized contractors, and other third parties.
Components of Risk Identification
The information classifications are as follows:
3. External
• All information that has been approved by management for
public release.
Security Clearance
• A component of a data classification scheme that assigns a
status level to employees to designate the maximum level of
classified data they may access.
Components of Risk Identification
Management of Classified Data
clean desk policy
• An organizational policy that specifies employees must inspect
their work areas and ensure that all classified information,
documents, and materials are secured at the end of every
workday.
dumpster diving
• An information attack that involves searching through a target
organization’s trash and recycling bins for sensitive information.
Components of Risk Identification
Information Asset Valuation
Asset valuation
• The process of assigning financial value or worth to each
information asset.
Value of Information Asset Criteria:
• Which information asset is most critical to the organization’s
success?
• Which information asset generates the most revenue?
• Which of these assets plays the biggest role in generating
revenue or delivering services?
Components of Risk Identification
• Which information asset would be the most expensive to
replace?
• Which information asset would be the most expensive to
protect?
• Which information asset would most expose the company to
liability or embarrassment if revealed?
Components of Risk Identification
Sample Inventory worksheet
Components of Risk Identification
4. Identifying and Prioritizing Threats
threat assessment
• An evaluation of the threats to information assets, including a
determination of their potential to endanger the organization.
Basic Questions for threat Assessment
• Which threats present a danger to an organization’s assets in the given
environment?
• Which threats represent the most danger to the organization’s information?
• How much would it cost to recover from a successful attack?
• Which of the threats would require the greatest expenditure to prevent?
Components of Risk Identification
5. Specifying Asset Vulnerabilities
• review each information asset for each relevant threat and create
a list of vulnerabilities.
Vulnerabilities
• are specific avenues that threat agents can exploit to attack an
information asset.
• a flaw or weakness in an information asset, security procedure,
design, or control that could be exploited accidentally or on
purpose to breach security.
Components of Risk Identification
5. Specifying Asset Vulnerabilities
threats-vulnerabilities-assets(TVA)worksheet
• A document that shows a comparative ranking of prioritized assets
against prioritized threats with an indication of any vulnerabilities
in the asset/threat pairings.
Sample
Vulnerability
Assessment of DMZ
Router
Risk Assessment
Risk Assessment
• A process used to identify the organization’s information assets
and its threats and vulnerabilities, evaluate the relative risk for
each vulnerability.
• Risk assessment assigns a risk rating or score to each information
asset.
Risk Assessment
1. Planning and Organizing Risk Assessment
• The goal at this point is to create a method for evaluating the
relative risk of each listed vulnerability.
Risk Assessment
2. Determining the Loss Frequency
Factors of Risk
attack success probability The number of successful attacks that are
expected to occur within a specified time period.
likelihood The probability that a specific vulnerability within an
organization will be the target of an attack.
loss frequency The calculation of the likelihood of an attack coupled
with the attack frequency to determine the expected number of
losses within a specified time range.
Risk Assessment
3. Evaluating Loss Magnitude
loss magnitude
• Also known as event loss magnitude, the combination of an asset’s
value and the percentage of it that might be lost in an attack.
4. Calculating Risk
If an organization can determine loss frequency and loss magnitude
for an asset, it can then calculate the risk to the asset.
Risk Assessment
Risk Assessment
Risk Assessment
Risk Assessment
5. Assessing Risk Acceptability
• For each threat and its associated vulnerabilities that have residual
risk, you must create a ranking of their relative risk levels
• These rankings provide a simplistic approach to documenting
residual risk—the left-over risk after the organization has done
everything feasible to protect its assets.
• Next, the organization must compare the residual risk to its risk
appetite—the amount of risk the organization is willing to tolerate.
Risk Assessment
Documenting the Results of Risk Assessment
• The goal so far has been to identify the information assets that
have specific vulnerabilities, list them, and then rank them
according to which need protection most.
• In preparing the list, you collected and preserved a wealth of
information about the assets, the threats they face, and the
vulnerabilities they expose. You should also have collected some
information about the controls that are already in place.
Risk Assessment
Sample Ranked Vulnerability Risk Worksheet
Risk Assessment
Sample Risk Identification and Assessment Deliverable
Risk Control
• When an organization’s management determines that risks from
information security threats are creating a competitive
disadvantage, it empowers the information technology and
information security communities of interest to control the risks.
• Risk control involves three basic steps: selection of control
strategies, justification of these strategies to upper management,
and the implementation, monitoring, and ongoing assessment of
the adopted controls.
Risk Control
1. Selecting Control Strategies
• Once the project team for information security development has
created the ranked vulnerability risk worksheet, the team must
choose a strategy for controlling each risk that results from these
vulnerabilities.
Risk Control
1. defense control strategy
• The risk control strategy that attempts to eliminate or reduce any
remaining uncontrolled risk through the application of additional
controls and safeguards.
The defense strategy includes three common methods:
• Application of policy
• Education and training
• Application of technology
Risk Control
2. transfer control strategy
• The risk control strategy that attempts to shift residual risk to
other assets, other processes, or other organizations.
3. mitigation control strategy
• The risk control strategy that attempts to reduce the impact of a
successful attack through planning and preparation.
• Mitigation begins with the early detection of an attack in progress
and a quick, efficient, and effective response.
Risk Control
4. acceptance control strategy
• The risk control strategy that indicates an organization is willing
to accept the current level of residual risk.
5. termination control strategy
• The risk control strategy that eliminates all risk associated with
an information asset by removing it from service.
• Mitigation begins with the early detection of an attack in progress
and a quick, efficient, and effective response.
Risk Control
2. Justifying Controls
• Justification control in risk management refers to the process of
providing a rationale or explanation for why certain risks are
being accepted, mitigated, or transferred.
annualized cost of a safeguard (ACS) In a cost-benefit analysis, the total cost
of a control or safeguard, including all purchase, maintenance,
subscription, personnel, and support fees, divided by the total number of
expected years of use.
annualized loss expectancy (ALE) In a cost-benefit analysis, the product of
the annualized rate of occurrence and single loss expectancy.
annualized rate of occurrence (ARO) In a cost-benefit analysis, the expected
frequency of an attack, expressed on a per-year basis.
Risk Control
2. Justifying Controls
cost-benefit analysis (CBA) Also known as an economic feasibility
study, the formal assessment and presentation of the economic
expenditures needed for a particular security control, contrasted
with its projected value to the organization.
exposure factor (EF) In a cost-benefit analysis, the expected
percentage of loss that would occur from a particular attack.
single loss expectancy (SLE) In a cost-benefit analysis, the calculated
value associated with the most likely loss from an attack. The SLE is
the product of the asset’s value and the exposure factor.
Risk Control
2. Justifying Controls
cost-benefit analysis (CBA) Also known as an economic feasibility
study, the formal assessment and presentation of the economic
expenditures needed for a particular security control, contrasted
with its projected value to the organization.
exposure factor (EF) In a cost-benefit analysis, the expected
percentage of loss that would occur from a particular attack.
single loss expectancy (SLE) In a cost-benefit analysis, the calculated
value associated with the most likely loss from an attack. The SLE is
the product of the asset’s value and the exposure factor.
Risk Control
3. Implementation, Monitoring, and Assessment of Risk Controls
• The strategy and its accompanying controls must be implemented
and then monitored on an ongoing basis to determine their
effectiveness and to accurately calculate the estimated residual
risk.
Qualitative Risk Management Practices:
qualitative assessment An asset valuation approach that uses
categorical or non-numeric values rather than absolute numerical
measures.
quantitative assessment An asset valuation approach that attempts
to assign absolute numerical measures.
Risk Control
Benchmarking and Best Practices
benchmarking The process of comparing other organizations’
activities against the practices used in one’s own organization to
produce results it would like to duplicate.
best business practices Security efforts that seek to provide a
superior level of performance in the protection of information. Also
known as best practices or recommended practices.
metrics-based measures Performance measures or metrics based on
observed numerical data.
performance gap The difference between an organization’s observed
and desired performance.
process-based measures Performance measures or metrics based on
intangible activities.