Risk Analysis
risk assessment
procedures
A risk assessment is a scientific method that includes identifying, studying,and
controlling risks. It is done by a specialized person To determine the methods to be taken to
eliminate or control risks.
A part of any assessment plan is to define the risks and then count the likelihood of the
happening risk ,main goal is to help organizations prepare for risks,
First of all, before starting the process of risk management, defining the assessment's
scope, essential resources and the involved stakeholders is very important. After that, you
continue to the next five procedures.
12
risk assessment
procedures
1- Identifying the risk:
• Identifying the risk is the first step in producing a risk assessment plan, in which we include
several potential risks like human error, physical, or cybersecurity risks. Deciding what is
going to be harmed and how. Then come up with an estimate of likelyhood of that risk
happening.
• Some IT risks: -Malware -Phishing -Device vulnerabilities -Web Application vulnerabilities
( These include SQL injection attacks, cross-site scripting attacks, and session hijacking.)
2- Decide who might be harmed and how:
To determine the best strategy of managing the risk, one must be conclusive about whom and
what could be affected by each risk. Not every person must be included by name, but rather
specific categories of individuals must be put into consideration
12
risk assessment
procedures
3- Evaluating the risk:
One must then choose how to respond to the threats after spotting them. Follow the law and
take all reasonable precautions to keep others safe. Consider what you are already doing, the
controls you have in place and the way it is organized first. Then, compare this to the
recommended practice to determine if there is anything else you can do to improve.
4- Record your findings and implement them:
Implementing the findings of your risk assessment will let you to decide how you are going to
put these actions in place.
12
risk assessment
procedures
5- Review your risk assessment and update if necessary:
As time passes, conducting risk assessment and profit events will most likely change. For this
particular reason, it’s necessary to regularly evaluate and update what you are doing. Be sure
to maintain your risk assessment and keep it up to date.
12
Security Risk
Evaluation
Risk Assessment: ‘spotting’ the most significant
vulnerabilities in the sea of potential vulnerabilities
vulnerabilit
y that
carries
most risk
Risk Analysis: Is a security risk worth a security
control?! 2
Qualitative vs. Quantitative
Analysis
Qualitative Risk – scenario based approach -
Analysi
uses labels & relative values
s (high/low) rather than
numbers; blends in
experience & personal
judgment
Quantitative Risk – predicts level of
Analysi
monetary loss for each threat, and
s monetary benefit of
controlling the treat
each element is
quantified and entered
into equations, e.g.:
asset value
damage
threat frequency 3
impact
Qualitative vs.
Quantitative Analysis
Qualitative Analysis Quantitative Analysis
• Requires simple (or no) calculations. • Easier to automate and
pros evaluate.
• Considers hands-on opinions of • Very useful in performance
individuals who know the process tracking - provide credible
best. cost/benefit analysis.
• Assessment and results are • Complex calculations – may not
cons subjective. be understood by all.
• Does not enable dollar cost/benefit • Very detailed information about
discussion. environment need to be
• Difficult to track gathered. 4
performance.
Qualitative vs.
Quantitative Analysis
Quantitative risk measurement is the standard way of measuring risk in many
fields, such as finance and insurance, but it is not commonly used to
measure risk in information systems.
Two of the reasons claimed for this are:
• the difficulties in identifying and assigning a value to assets.
• the lack of statistical information that would make it possible to determine
frequency.
Thus, most of the risk assessment tools that are used today for
information systems are measurements of qualitative risk.”
5
Qualitative
Analysis
Challenges of – define likelihood and
Qualitati
impact values in a manner that
ve would allow the same scale
Analysis to be used across multiple
risk assessments
Example: Sample ‘likelihood of threat’ definitions
6
Qualitative
Analysis (cont.)
Example: Sample ‘impact’ definitions
Example: Sample ‘risk determination’ matrix
7
Qualitative Analysis
(cont.)
10
Table 14.2
Risk Likelihood
Table 14.3
Risk
Consequence
(Impact)
(Table can be found on pages
503-504 in textbook)
Table 14.4
Risk Level Determination and Meaning
Table 14.6
Silver Star Mines Risk Register
Quantitative Analysis
(cont.)
Example: Determining ARO, SLE, ALE
12