Showing posts with label Risk Assessment. Show all posts
Showing posts with label Risk Assessment. Show all posts

Monday, January 9, 2017

CyberSecurity: Risk Management



  1. The identification and assessment of levels of risk in an organization describes: Risk Analysis
  2. Two of the activities involved in risk management include identifying risks and assessing risks. Creating an inventory of information assets is part of the risk assessment process?
  3. The likelihood of the occurrence of a vulnerability multiplied by the value of the information asset minus the percentage of risk mitigated by current controls plus the uncertainty of current knowledge of the vulnerability are each examples of Risk assessment estimate factors.
  4. Mitigation describes an organization’s efforts to reduce damage caused by a realized incident or disaster through planning and preparation.
  5. Risk appetite can be described as the quantity and nature of risk that organizations are willing to accept as they evaluate the trade-offs between perfect security and unlimited accessibility? 

Online computer science courses to jumpstart your future.Become a Web Developer in 2016 with Coursera

CyberSecurity: Risk Management - The Risk Assessment Process

In order to begin the risk assessment phase, the organization uses the list of information assets it has identified and prioritizes assets and the threats facing them to compare information assets to threats. The resulting list of vulnerabilities are those that remain risks to the organization. This list should be created for each information asset to document its vulnerability to each possible or likely attack. The best way found to do this documentation is the threat vulnerability asset, or TVA, Table.



As shown, it would list assets along the x-axis from most to least valuable and lists threats along the y-axis from most to least dangerous. At the intersection of the asset and threat pair, list the vulnerabilities that the threat might use to cause a loss to the asset. Now, we move onto assess the risk that exists in each of the TVA tables. Risk is commonly calculated as the likelihood that a threat to an asset will result in an adverse impact which is then multiplied by the consequences or impact of that attack.



That value is then increased by an estimate of how reliable our values of both likelihood and impact are, known as a confidence interval. Many approaches to assessing likelihood exist. One example of some likelihood ratings on a scale of 0 to 5 is shown here. Likewise, there are many ways to assess impact. Here is an example of some impact ratings on a scale of zero to five.

Start your future with a Data Analysis Certificate.   Online learning to jumpstart your future.  Python Specialization from University of Michigan

Before the organization can proceed with the final phase of risk management, activities, which is risk control, it needs to understand how much risk is acceptable to management. Some organizations have a very low tolerance for risk. Such as banking and other financial services firms. Other types of organization may tolerate more risk. The amount of risk that remains after all current levels are implemented is known as residual risk. Any organization may reach a point in the risk management process and find that the documented residual risk is low enough to accept being within the bounds of its risk appetite. They would end the current risk management cycle and document everything for the next cycle.



Once the organization has assessed the current level of risk facing its information assets and defined its risk appetite, it can move to the final phase of risk management. And that's called Risk Control. In the Risk Control phase, organizations employ one or more of the five strategies of risk control.
  1. Defense, which is applying safeguards that eliminate or reduce the remaining uncontrolled risk. 
  2. Transference, which is shifting risk to other areas or outside entities. 
  3. Mitigation, which is reducing the impact to information assets should an attacker successful exploit a vulnerability. 
  4. Acceptance. That's understanding the consequences of choosing to leave a risk uncontrolled and then formally accepting the risk that remains without an attempt at control. 
  5. And the final is termination. And that's removing or discontinuing the information asset from the organization's operating environment all together. 



Risk management is an essential process for every organization. There are many formalized models for risk management in the marketplace, and many organizations are using consulting resources to assist them in finding the optimum means to reduce operational risk.

CyberSecurity: Risk Management - The Risk Identification Process

At its heart, information security is all about managing risk.

What is risk? 
Risk is the probability of a loss. It's the chance of something adverse happening to our interests.

Risk Management?
Risk management is understanding how bad the loss from an adverse event can be, and how we can get the risk down to a level we can absorb. A loss is an event that can negatively affect our information assets, such as  
  • unauthorized/unwanted access,  
  • destruction
  • modification,  
  • theft or  
  • denial of access

Risk management involves a preparation and planning phase followed by a risk identification phase, a risk assessment phase, a risk appetite determination phase, and then a risk control phase.

  • Risk identification is where we seek to determine if risk exists from known vulnerabilities as well as threats that we can identify that may attempt to exploit those vulnerabilities or find new ways to cause us loss. 
  • Risk assessment is the determination of the extent to which our assets are at risk. 
  • In determining our risk appetite, we determine and document how much risk we can tolerate? 
  • Risk control is where we plan additional appropriate controls to reduce excessive risk to that defined acceptable level. 
Risk management also means that we continue to monitor our risk environment until we need to begin the process again.

Start your future with a Business Analytics Certificate.Coursera DS Design 10Coursera Business Vertical Orange Design 10

Risk identification is the first phase of the process, the first step in risk identification involves identifying, classifying, and prioritizing our assets. Information assets are found across the organization not just in data basis or on service. Information exists in filling cabinets, on personal computers and numerous other locations. Once identified, assets must be evaluated and place in the classes or categories to determine who cannot access to it. Many approaches to classifying data exist. One common approach is signs asset as one of public, official use only, or confidential. After classification, assets must be assess for a value it has to the organization. Using this information, we'll be able to determine each assets needed level of protection.

When assessing the value of an information asset, there are a number of questions we could use.
Like: Which information asset...
  • is the most critical to the success of the organization?
  • generates the most revenue?
  • generates the highest profitability?
  • is the most expensive to replace?
  • is the most expensive to protect?
  • loss or compromise would be the most embarrassing or cause the greatest liability? 
Placing an exact dollar value on most assets is very difficult. However, we can place relative values to help us prioritize them. One method uses a weighted factor table to assess and compare the worth of our assets.



This is done by first listing the criteria we care about and then assessing each asset using those criteria. This allows the creation of a weighted score. Which helps us to compare the value of dissimilar assets within our organization. The second step in risk identification is to identify and prioritize the threats to our information assets. We can identify threats by looking for studies and surveys published in trade and academic journals. This study published by the communications of the ACM, identified 12 categories of threats to information security.



Other such lists have been published as well. Just as we assessed our assets, we must assess the threats facing them. The questions shown here could be used as criteria in a weighted table to prioritize threats.

Business Analytics from the Wharton SchoolData science is one of today‰Ûªs fastest-growing fields. Become a Data Scientist in 2016 with Coursera.

Threat Assessment questions: Which Threat:
  • Present danger to this organization's information assets in its current environment?
  • represent the gravest danger to the organization's information assets?
  • have the highest probability of success?
  • could result in the greatest loss if successful?
  • is the organization least prepared to handle?
  • cost the most to protect against?
  • cost the most to recover from?
Summary:
There are four ways of managing risk
  1. avoiding the risk – avoidance would mean stopping the activity that is causing the risk. For example, deleting all banking information and unsubscribing from internet banking would avoid the risks associated with the information assets related to banking.
  2. modifying the risk (likelihood and/or impact) – this involves choosing and implementing a security mechanism that reduces the likelihood of a successful attack, or the impact that would result from such an attack. For example, installing an up to date antivirus application can prevent the attacker from using malware to gain access to the computer holding the internet banking information.
  3. transferring the risk to others – typically involves taking out insurance to cover any losses in the event the threat materialises.
  4. accepting the risk – would mean choosing not to implement any of these countermeasures, choosing instead to monitor the information asset for any attacks.