0% found this document useful (0 votes)
19 views45 pages

TVA Worksheet for Risk Assessment

Risk management involves identifying, assessing, and controlling risks to an organization's information assets. Key components include risk identification, assessment, and control strategies, which help organizations determine their risk appetite and manage residual risks. Effective risk management requires thorough planning, asset categorization, threat assessment, and ongoing monitoring of implemented controls.

Uploaded by

Shaloops hoops
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
19 views45 pages

TVA Worksheet for Risk Assessment

Risk management involves identifying, assessing, and controlling risks to an organization's information assets. Key components include risk identification, assessment, and control strategies, which help organizations determine their risk appetite and manage residual risks. Effective risk management requires thorough planning, asset categorization, threat assessment, and ongoing monitoring of implemented controls.

Uploaded by

Shaloops hoops
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Risk Management

Risk Management

Risk Management

• The process of identifying risk, assessing its relative magnitude,


and taking steps to reduce it to an acceptable level.

risk appetite
• The amount of risk an organization is willing to accept.

residual risk
• The amount of risk that remains to an information asset even
after the organization has applied its desired level of controls.
Risk Management
Three Major Undertaking of Risk Management:
1. Risk Identification
• The enumeration and documentation of risks to an organization’s
information assets.

2. Risk Assessment

• A determination of the extent to which an organization’s


information assets are exposed to risk.
3. Risk Control
• The application of controls that reduce the risks to an
organization’s information assets to an acceptable level.
Components of Risk Management
Components of Risk Identification
1. Planning and Organizing the Process

• Begin by organizing a team, which typically consists of


representatives from all affected groups.

• The process must then be planned, with periodic deliverables,


reviews, and presentations to management.

2. Identifying, Inventorying, and Categorizing Assets

• This iterative process begins with the identification and


inventory of assets, including all elements of an organization’s
system, such as people, procedures, data and information,
software, hardware, and networking elements.
Components of Risk Identification
People, Procedures, and Data Asset Identification

• Identifying assets for human resources, documentation, and


data.

When deciding which information assets to track, consider the


following asset attributes:

People: Position name, number, or ID (avoid using people’s names


and stick to identifying positions, roles, or functions); supervisor;
security clearance level; special skills.
Components of Risk Identification

Procedures: Description; intended purpose; relationship to


software, hardware, and networking elements; storage location for
reference; storage location for update.

Data: Classification; owner, creator, and manager; size of data


structure; data structure used (sequential or relational); online or
offline; location; backup procedures employed.
Components of Risk Identification
Hardware, Software, and Network Asset Identification
• The attributes to be tracked in hardware, software and network
assets depends on the needs of the organization and its risk
management efforts.
1. Name
2. IP Address
3. Media Access Control (MAC)
4. Element Type
5. Serial number
6. Manufacturer name
7. Manufacturer’ model number or part number
8. Software version
9. Physical Location
10 Logical Location
11. Controlling Entity
Components of Risk Identification

Asset Inventory

• Creating an inventory of information assets is a critical function


of understanding what the organization is protecting.

• The inventory process is critical in determining where


information is located; most commonly it is in storage.

• Not all information is stored in databases. A great deal of an


organization’s information is stored in hard copy—in filing
cabinets, desks, and in employee hands and briefcases.
Components of Risk Identification
Categorizing the Components of an Information System
Components of Risk Identification
3. Classifying, Valuing, and Prioritizing Information Assets

Data Classification and Management

• Corporate and government organizations use a variety of


classification schemes. Many corporations use a data
classification scheme to help secure the confidentiality and
integrity of information.

Data Classification Scheme


• A formal access control methodology used to assign a level of
confidentiality to an information asset and thus restrict the
number of people who can access it.
Components of Risk Identification
The information classifications are as follows:

1. Confidential

• Used for the most sensitive corporate information that must be


tightly controlled, even within the company.

• Access to information with this classification is strictly on a


need-to-know basis or as required by the terms of a contract.

• Information with this classification may also be referred to as


“sensitive” or “proprietary.”
Components of Risk Identification
The information classifications are as follows:

2. Internal

• Used for all internal information that does not meet the criteria
for the confidential category.

• Internal information is to be viewed only by corporate


employees, authorized contractors, and other third parties.
Components of Risk Identification
The information classifications are as follows:

3. External

• All information that has been approved by management for


public release.

Security Clearance

• A component of a data classification scheme that assigns a


status level to employees to designate the maximum level of
classified data they may access.
Components of Risk Identification
Management of Classified Data

clean desk policy

• An organizational policy that specifies employees must inspect


their work areas and ensure that all classified information,
documents, and materials are secured at the end of every
workday.

dumpster diving

• An information attack that involves searching through a target


organization’s trash and recycling bins for sensitive information.
Components of Risk Identification
Information Asset Valuation

Asset valuation
• The process of assigning financial value or worth to each
information asset.

Value of Information Asset Criteria:

• Which information asset is most critical to the organization’s


success?

• Which information asset generates the most revenue?

• Which of these assets plays the biggest role in generating


revenue or delivering services?
Components of Risk Identification
• Which information asset would be the most expensive to
replace?

• Which information asset would be the most expensive to


protect?

• Which information asset would most expose the company to


liability or embarrassment if revealed?
Components of Risk Identification
Sample Inventory worksheet
Components of Risk Identification
4. Identifying and Prioritizing Threats

threat assessment

• An evaluation of the threats to information assets, including a


determination of their potential to endanger the organization.

Basic Questions for threat Assessment

• Which threats present a danger to an organization’s assets in the given


environment?

• Which threats represent the most danger to the organization’s information?

• How much would it cost to recover from a successful attack?

• Which of the threats would require the greatest expenditure to prevent?


Components of Risk Identification
5. Specifying Asset Vulnerabilities

• review each information asset for each relevant threat and create
a list of vulnerabilities.

Vulnerabilities

• are specific avenues that threat agents can exploit to attack an


information asset.

• a flaw or weakness in an information asset, security procedure,


design, or control that could be exploited accidentally or on
purpose to breach security.
Components of Risk Identification

5. Specifying Asset Vulnerabilities

threats-vulnerabilities-assets(TVA)worksheet

• A document that shows a comparative ranking of prioritized assets


against prioritized threats with an indication of any vulnerabilities
in the asset/threat pairings.
Sample
Vulnerability
Assessment of DMZ
Router
Risk Assessment

Risk Assessment

• A process used to identify the organization’s information assets


and its threats and vulnerabilities, evaluate the relative risk for
each vulnerability.

• Risk assessment assigns a risk rating or score to each information


asset.
Risk Assessment

1. Planning and Organizing Risk Assessment

• The goal at this point is to create a method for evaluating the


relative risk of each listed vulnerability.
Risk Assessment

2. Determining the Loss Frequency

Factors of Risk

attack success probability The number of successful attacks that are


expected to occur within a specified time period.

likelihood The probability that a specific vulnerability within an


organization will be the target of an attack.

loss frequency The calculation of the likelihood of an attack coupled


with the attack frequency to determine the expected number of
losses within a specified time range.
Risk Assessment

3. Evaluating Loss Magnitude

loss magnitude

• Also known as event loss magnitude, the combination of an asset’s


value and the percentage of it that might be lost in an attack.

4. Calculating Risk

If an organization can determine loss frequency and loss magnitude


for an asset, it can then calculate the risk to the asset.
Risk Assessment
Risk Assessment
Risk Assessment
Risk Assessment

5. Assessing Risk Acceptability

• For each threat and its associated vulnerabilities that have residual
risk, you must create a ranking of their relative risk levels

• These rankings provide a simplistic approach to documenting


residual risk—the left-over risk after the organization has done
everything feasible to protect its assets.

• Next, the organization must compare the residual risk to its risk
appetite—the amount of risk the organization is willing to tolerate.
Risk Assessment

Documenting the Results of Risk Assessment

• The goal so far has been to identify the information assets that
have specific vulnerabilities, list them, and then rank them
according to which need protection most.

• In preparing the list, you collected and preserved a wealth of


information about the assets, the threats they face, and the
vulnerabilities they expose. You should also have collected some
information about the controls that are already in place.
Risk Assessment
Sample Ranked Vulnerability Risk Worksheet
Risk Assessment
Sample Risk Identification and Assessment Deliverable
Risk Control

• When an organization’s management determines that risks from


information security threats are creating a competitive
disadvantage, it empowers the information technology and
information security communities of interest to control the risks.

• Risk control involves three basic steps: selection of control


strategies, justification of these strategies to upper management,
and the implementation, monitoring, and ongoing assessment of
the adopted controls.
Risk Control
1. Selecting Control Strategies

• Once the project team for information security development has


created the ranked vulnerability risk worksheet, the team must
choose a strategy for controlling each risk that results from these
vulnerabilities.
Risk Control
1. defense control strategy

• The risk control strategy that attempts to eliminate or reduce any


remaining uncontrolled risk through the application of additional
controls and safeguards.

The defense strategy includes three common methods:

• Application of policy

• Education and training

• Application of technology
Risk Control
2. transfer control strategy

• The risk control strategy that attempts to shift residual risk to


other assets, other processes, or other organizations.

3. mitigation control strategy

• The risk control strategy that attempts to reduce the impact of a


successful attack through planning and preparation.

• Mitigation begins with the early detection of an attack in progress


and a quick, efficient, and effective response.
Risk Control
4. acceptance control strategy

• The risk control strategy that indicates an organization is willing


to accept the current level of residual risk.

5. termination control strategy

• The risk control strategy that eliminates all risk associated with
an information asset by removing it from service.

• Mitigation begins with the early detection of an attack in progress


and a quick, efficient, and effective response.
Risk Control
2. Justifying Controls

• Justification control in risk management refers to the process of


providing a rationale or explanation for why certain risks are
being accepted, mitigated, or transferred.

annualized cost of a safeguard (ACS) In a cost-benefit analysis, the total cost


of a control or safeguard, including all purchase, maintenance,
subscription, personnel, and support fees, divided by the total number of
expected years of use.

annualized loss expectancy (ALE) In a cost-benefit analysis, the product of


the annualized rate of occurrence and single loss expectancy.

annualized rate of occurrence (ARO) In a cost-benefit analysis, the expected


frequency of an attack, expressed on a per-year basis.
Risk Control
2. Justifying Controls

cost-benefit analysis (CBA) Also known as an economic feasibility


study, the formal assessment and presentation of the economic
expenditures needed for a particular security control, contrasted
with its projected value to the organization.

exposure factor (EF) In a cost-benefit analysis, the expected


percentage of loss that would occur from a particular attack.

single loss expectancy (SLE) In a cost-benefit analysis, the calculated


value associated with the most likely loss from an attack. The SLE is
the product of the asset’s value and the exposure factor.
Risk Control
2. Justifying Controls

cost-benefit analysis (CBA) Also known as an economic feasibility


study, the formal assessment and presentation of the economic
expenditures needed for a particular security control, contrasted
with its projected value to the organization.

exposure factor (EF) In a cost-benefit analysis, the expected


percentage of loss that would occur from a particular attack.

single loss expectancy (SLE) In a cost-benefit analysis, the calculated


value associated with the most likely loss from an attack. The SLE is
the product of the asset’s value and the exposure factor.
Risk Control
3. Implementation, Monitoring, and Assessment of Risk Controls

• The strategy and its accompanying controls must be implemented


and then monitored on an ongoing basis to determine their
effectiveness and to accurately calculate the estimated residual
risk.

Qualitative Risk Management Practices:

qualitative assessment An asset valuation approach that uses


categorical or non-numeric values rather than absolute numerical
measures.

quantitative assessment An asset valuation approach that attempts


to assign absolute numerical measures.
Risk Control
Benchmarking and Best Practices

benchmarking The process of comparing other organizations’


activities against the practices used in one’s own organization to
produce results it would like to duplicate.

best business practices Security efforts that seek to provide a


superior level of performance in the protection of information. Also
known as best practices or recommended practices.

metrics-based measures Performance measures or metrics based on


observed numerical data.

performance gap The difference between an organization’s observed


and desired performance.

process-based measures Performance measures or metrics based on


intangible activities.

You might also like