0% found this document useful (0 votes)
18 views17 pages

Comprehensive Risk Assessment Guide

The document outlines the procedures for conducting a risk assessment, which includes identifying risks, evaluating potential harm, and implementing findings. It emphasizes the importance of defining the assessment's scope and regularly updating the risk assessment. Additionally, it contrasts qualitative and quantitative analysis methods for measuring risk, highlighting their respective advantages and challenges.

Uploaded by

Not.DXcr GaMeR
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
18 views17 pages

Comprehensive Risk Assessment Guide

The document outlines the procedures for conducting a risk assessment, which includes identifying risks, evaluating potential harm, and implementing findings. It emphasizes the importance of defining the assessment's scope and regularly updating the risk assessment. Additionally, it contrasts qualitative and quantitative analysis methods for measuring risk, highlighting their respective advantages and challenges.

Uploaded by

Not.DXcr GaMeR
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

Risk Analysis

risk assessment
procedures
A risk assessment is a scientific method that includes identifying, studying,and
controlling risks. It is done by a specialized person To determine the methods to be taken to
eliminate or control risks.

A part of any assessment plan is to define the risks and then count the likelihood of the
happening risk ,main goal is to help organizations prepare for risks,

First of all, before starting the process of risk management, defining the assessment's
scope, essential resources and the involved stakeholders is very important. After that, you
continue to the next five procedures.

12
risk assessment
procedures
1- Identifying the risk:
• Identifying the risk is the first step in producing a risk assessment plan, in which we include
several potential risks like human error, physical, or cybersecurity risks. Deciding what is
going to be harmed and how. Then come up with an estimate of likelyhood of that risk
happening.
• Some IT risks: -Malware -Phishing -Device vulnerabilities -Web Application vulnerabilities
( These include SQL injection attacks, cross-site scripting attacks, and session hijacking.)

2- Decide who might be harmed and how:


To determine the best strategy of managing the risk, one must be conclusive about whom and
what could be affected by each risk. Not every person must be included by name, but rather
specific categories of individuals must be put into consideration

12
risk assessment
procedures
3- Evaluating the risk:
One must then choose how to respond to the threats after spotting them. Follow the law and
take all reasonable precautions to keep others safe. Consider what you are already doing, the
controls you have in place and the way it is organized first. Then, compare this to the
recommended practice to determine if there is anything else you can do to improve.

4- Record your findings and implement them:


Implementing the findings of your risk assessment will let you to decide how you are going to
put these actions in place.

12
risk assessment
procedures
5- Review your risk assessment and update if necessary:
As time passes, conducting risk assessment and profit events will most likely change. For this
particular reason, it’s necessary to regularly evaluate and update what you are doing. Be sure
to maintain your risk assessment and keep it up to date.

12
Security Risk
Evaluation
Risk Assessment: ‘spotting’ the most significant
vulnerabilities in the sea of potential vulnerabilities

vulnerabilit
y that
carries
most risk

Risk Analysis: Is a security risk worth a security


control?! 2
Qualitative vs. Quantitative
Analysis
 Qualitative Risk – scenario based approach -
Analysi
uses labels & relative values
s (high/low) rather than
numbers; blends in
experience & personal
judgment
 Quantitative Risk – predicts level of
Analysi
monetary loss for each threat, and
s monetary benefit of
controlling the treat
 each element is
quantified and entered
into equations, e.g.:
 asset value
 damage
 threat frequency 3
impact
Qualitative vs.
Quantitative Analysis

Qualitative Analysis Quantitative Analysis

• Requires simple (or no) calculations. • Easier to automate and


pros evaluate.
• Considers hands-on opinions of • Very useful in performance
individuals who know the process tracking - provide credible
best. cost/benefit analysis.

• Assessment and results are • Complex calculations – may not


cons subjective. be understood by all.
• Does not enable dollar cost/benefit • Very detailed information about
discussion. environment need to be
• Difficult to track gathered. 4

performance.
Qualitative vs.
Quantitative Analysis
Quantitative risk measurement is the standard way of measuring risk in many
fields, such as finance and insurance, but it is not commonly used to
measure risk in information systems.

Two of the reasons claimed for this are:

• the difficulties in identifying and assigning a value to assets.

• the lack of statistical information that would make it possible to determine


frequency.

Thus, most of the risk assessment tools that are used today for
information systems are measurements of qualitative risk.”

5
Qualitative
Analysis
 Challenges of – define likelihood and
Qualitati
impact values in a manner that
ve would allow the same scale
Analysis to be used across multiple
risk assessments

Example: Sample ‘likelihood of threat’ definitions

6
Qualitative
Analysis (cont.)
Example: Sample ‘impact’ definitions

Example: Sample ‘risk determination’ matrix

7
Qualitative Analysis
(cont.)

10
Table 14.2
Risk Likelihood
Table 14.3

Risk

Consequence

(Impact)

(Table can be found on pages

503-504 in textbook)
Table 14.4

Risk Level Determination and Meaning


Table 14.6
Silver Star Mines Risk Register
Quantitative Analysis
(cont.)
Example: Determining ARO, SLE, ALE

12

You might also like