Discussion and Replies
43
Chapter 4
Risk Management: The Facilitated Risk Analysis and Assessment Process
Thomas R. Peltier
Contents Introduction ........................................................................................................60 Update ................................................................................................................60 FRAAP Overview ................................................................................................61 FRAAP History ...................................................................................................62 Introduce the FRAAP ..........................................................................................63
Key Concepts .................................................................................................65 The Pre-FRAAP Meeting .....................................................................................67
Pre-FRAAP Meeting Checklist .......................................................................72 Pre-FRAAP Meeting Summary ...................................................................... 77
The FRAAP Session .............................................................................................78 Overview ........................................................................................................78 FRAAP Session Introduction ..........................................................................78
FRAAP Session Talking Points ...................................................................79 FRAAP Threat Identification ..........................................................................81 Identify Threats Using a Checklist ..................................................................85 Identifying Existing Controls ..........................................................................85 Establish Risk Levels .......................................................................................88 Residual Risk ................................................................................................. 90
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
44 ◾ Information Security Fundamentals
Introduction After being in the information security profession for more than 35 years and in information technology for nearly 50 years, I have found that most organizations have the ability to identify threats that can affect the business objectives or mission of the organization. What they cannot do in a systematic manner is to take that threat and determine the level of risk it poses to the organization.
Years ago, I worked with a delightful gentleman named Irving Ball. Irv was six feet seven inches tall and I was five feet two. One morning, Irv came in with a fresh abrasion on his forehead. I inquired as to what happened and Irv asked “Didn’t you see that scaffolding in the parking lot?” I said that I thought that I had. At lunch, as we headed to my car, we passed the scaffolding and we noted that the threat to both of us was there. However, the probability of me hitting the portion of the scaffold where Irv did was much lower than for him. So, for both of us, the scaffold was a threat. The risk to me was lower because the probability and impact were lower.
Just because there is a threat does not mean that the organization is at risk. This is what risk assessment is all about. Identifying the threats that are out there and then determining if those threats pose a real risk to the organization.
With the changing business culture, successful security professionals have had to modify the process of responding to new threats in the high profile, ultra- connected business environment. With outside regulatory agencies and external auditors gaining more oversight strength over the past 5 years, organizations are met with an increased motivation to implement an effective, inexpensive risk assessment process.
Even with the change of focus, today’s organizations must still protect the integrity, confidentiality, and availability of information resources they rely on. Although there is an increased interest in security by senior management, the fact remains that the business of the enterprise is business. An effective security pro- gram must assist the business units by providing high-quality reliable service in helping them protect the enterprise’s assets.
Update The Facilitated Risk Analysis and Assessment Process (FRAAP) has gone through many changes since it was first used in 1995. This chapter discusses the formal facilitated version of the process. Included in Appendix A is a sample procedure
Using a Threat Identification Checklist..............................................................101 FRAAP Session Summary .............................................................................101
Post-FRAAP Process ..........................................................................................102 Complete the Action Plan .............................................................................105
Conclusion ........................................................................................................107
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
Risk Management ◾ 45
that discusses the latest version. The sample procedure is an example of how a risk assessment process could be deployed at your location. For more on FRAAP, see Information Security Risk Analysis, Third Edition.
FRAAP Overview The FRAAP was developed as an efficient and disciplined process for ensuring that threats to business operations are identified, examined, and documented. The process involves analyzing one system, application, platform, business process, or segment of business operation at a time. By convening a team of internal subject matter experts, the FRAAP will rely on the organization’s own people to complete the risk assessment process. These experts must include the business managers and system users who are familiar with the mission needs of the asset under review, and the infrastructure staff who have a detailed understanding of potential system vulnerabilities and related controls. The FRAAP sessions follow a standard agenda and are facilitated by a mem- ber of the project office or information security staff. The facilitators are responsible for ensuring that the team members communicate effectively and adhere to the proj- ect scope statement. A sample FRAAP procedure has been included Appendix A.
The team’s conclusions as to what threats exist, what their risk levels are, and what controls are needed are documented for the business owner’s use in developing the FRAAP, and is divided into three phases:
◾ The pre-FRAAP ◾ The FRAAP session ◾ The post-FRAAP
During the FRAAP session, the team will brainstorm to identify potential threats that could affect the task mission of the asset under review. The team will then establish a risk level for each threat based on the probability that the threat might occur and the relative effect were it to occur. We will go into more detail on this process later in the book.
The team does not usually attempt to obtain or develop specific numbers for threat likelihood or annual loss estimates unless the data for determining such fac- tors is readily available. Instead, the team will rely on their general knowledge of threats and probabilities obtained from national incident response centers, profes- sional associations and literature, and their own experience.
When assembling the team, it is experience that allows them to believe that additional efforts to develop precisely quantified risks are not cost-effective because
◾ Such estimates take an inordinate amount of time and effort to identify and verify or develop
◾ The risk documentation becomes too voluminous to be of practical use ◾ Specific loss estimates are generally not needed to determine if a control is needed
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
46 ◾ Information Security Fundamentals
After identifying the threats and establishing the relative risk level for each threat, the team identifies controls that could be implemented to reduce the risk, focusing on the most cost-effective controls. The team will use a common set con- trols designed to address various types of threats. We will discuss the controls selec- tion process later in this chapter.
Once the FRAAP session is complete, the security professional can assist the business owner in determining which controls are cost-effective and meet their business needs. Once each threat has been assigned a control measure or has been accepted as a risk of doing business, then the senior business manager and technical expert participating sign the completed document. The document and all associated reports are owned by the business unit sponsor and are retained for a period to be determined by the records management procedures (usually 7 years).
Each risk assessment process is divided into three distinct sessions:
◾ The pre-FRAAP meeting, which normally takes about an hour and has the business owner, project lead, scribe and facilitator, and has seven deliverables.
◾ The FRAAP session takes approximately 4 hours and includes 15 to 30 people, although sessions with as many as 50 and as few as 4 people have occurred.
◾ Post-FRAAP is where the results are analyzed and the Management Summary Report is completed. This process can take up to five workdays to complete.
During the rest of this chapter, we will examine why the FRAAP was developed and what each one of the three phases entail and what the deliverables are from each phase.
FRAAP History Before the development of the FRAAP, risk assessment was often perceived as a major task that required the enterprise to hire an outside consultant and could take weeks, if not months, to complete. Often, the risk assessment process was shrouded in mystery and often seemed that elements of voodoo were being used. The final report sometimes looked like the name of your organization was simply edited into a standard report template.
By hiring outside consultants, the expertise of the in-house staff was often over- looked and the results produced were not acceptable to the business unit manager. Additionally, the results of the old process in which business managers were not part of the risk assessment process found that they did not understand the recom- mended controls, did not want the recommended controls, and often worked to undermine the control implementation process.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
Risk Management ◾ 47
What was needed was a risk assessment process that
◾ Is driven by the business owners ◾ Takes days instead of weeks or months ◾ Is cost-effective ◾ Uses in-house experts
The FRAAP meets all of these requirements and adds another; it can be con- ducted by someone with limited knowledge of a particular system or business pro- cess, but with good facilitation skills.
The FRAAP is a formal methodology developed through understanding the previously developed qualitative risk assessment processes and modifying them to meet the current requirements. It is driven by the business side of the enterprise and ensures that the controls selected enable the business owners to meet their mis- sion objectives. With the FRAAP, controls are never implemented to meet audit or security requirements. The only controls selected focus on the businesses’ needs.
The FRAAP was created with an understanding that internal resources had limited time to spend on such tasks. By holding the information-gathering session to 4 hours, then the subject matter experts (SME) are more likely to participate in the process. Using time as a critical factor, the FRAAP addresses as many risk assessment issues as possible. If there is more time, then there are more tasks that can be performed.
By involving the business units, the FRAAP uses them to identify threats. Once the resource owner is involved in identifying threats and then determine the risk level, they generally see the business reason behind why implementing cost-effective controls to help limit exposure is necessary. The FRAAP allows the business units to take control of their resources. It allows them to determine what safeguards are needed and who will be responsible for implementing those safeguards.
The results of the FRAAP are a comprehensive set of documents that will iden- tify threats, prioritize those threats into risk levels, and identify possible controls that will help mitigate those high-level risks.
The FRAAP provides the enterprise with a cost-effective action plan that meets the business needs to protect enterprise resources while ensuring that business objectives and mission charters are met. Most importantly, with the involvement of the business managers, the FRAAP provides a supportive client or owner that believes in the action plan.
Introduce the FRAAP As with any new process, it is always best to conduct user awareness sessions to acquaint employees before the process is rolled out. It will be necessary to explain
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
48 ◾ Information Security Fundamentals
what the FRAAP is, how it works, and how it will help the business people meet their specific objectives.
To be successful, the awareness program should take into account the needs and current levels of training and understanding of the employees and management. There are five keys to establishing an effective awareness program. These include
◾ Assess current level of risk assessment understanding ◾ Determine what the managers and employees want to learn ◾ Examine the level of receptiveness to the security program ◾ Map out how to gain acceptance ◾ Identify possible allies
To assess the current level of risk assessment understanding, it will be necessary to ask questions of the audience. Although some employees may have been part of a risk assessment in the past, most employees have little first-hand knowledge of risk assessment. Ask questions such as why they believe there is a need for risk assessment. Listen to what the employees are saying and scale the training sessions to meet their specific needs. In the awareness field, one size or plan does not fit for everyone.
Work with the managers and supervisors to understand what their needs are and how the risk assessment process can help them. It will become necessary for you to understand the language of the business units and to interpret their needs. Once you have an understanding, then you will be able to modify the presentation to meet these special needs. No single awareness program will work for every busi- ness unit. There must be alterations and a willingness to accept suggestions from non–security personnel.
Identify the level of receptiveness to the risk assessment process. Find out what is accepted and what is meeting with resistance. Examine the areas of noncompli- ance and try to find ways to alter the program if at all possible. Do not change fundamental risk assessment precepts just to gain unanimous acceptance—this is an unattainable goal. Make the process meet the greater good of the enterprise and then work with pockets of resistance to lessen the impact.
The best way to gain acceptance is to make employees and managers partners in this process. Never decree a new control or policy to the employee population without involving them in the decision-making process. This will require you to do your homework and to understand the business process in each department. It will be important to know the peak periods of activity in the department and what the manager’s concerns are. When meeting with the managers, be sure to listen to their concerns and be prepared to ask for their suggestions on how to improve the program. Remember, the key here is to partner with your audience.
Finally, look for possible allies. Find out which managers support the objec- tives of the risk assessment process and those that have the respect of their peers. This means that it will be necessary to expand the area of support beyond risk
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
Risk Management ◾ 49
management and the audit staff. Seek out business managers that have a vested interest in seeing this program succeed. Use their support to springboard the pro- gram to acceptance.
A key point in this entire process is to never refer to the risk assessment process or the awareness campaign as “my program.” The enterprise has identified the need for risk assessment and you and your group are acting as the catalysts to moving the process forward. When discussing the process with employees and managers, it will be beneficial to refer to it as their risk assessment process or our process. Make them feel that they are key stakeholders in this process.
Involve the user community and accept their comments whenever possible. Make the risk assessment process “their” process. Use what they identify as impor- tant in the awareness program. By having them involved, then the risk assessment process truly becomes theirs and they are more willing to accept and internalize the results.
Key Concepts The FRAAP is a formal methodology for risk assessment that is driven by the owner. The asset owner schedules each FRAAP session and the team members are invited by the owner. The concept of what constitutes an owner is normally established in the organization’s information security policy. The policy generally addresses the concepts of information asset owner, custodian, and user. A typical company policy may resemble the following:
◾ Information created while employed by the company is a company asset and is the property of the company. All employees are responsible for protecting company information from unauthorized access, modification, destruction, or disclosure, whether accidental or intentional. To facilitate the protection of company information, employee responsibilities have been established at three levels: owner, custodian, and user.
− Owner: Is the highest level of company management of the organiza- tional unit where the information resource is created, or management of the organizational unit that is the primary user of the information resource. Owners have the responsibility to • Establish the classification level of all corporate information within
their organizational unit • Identify reasonable and prudent safeguards to ensure the confidenti-
ality, integrity, and availability of the information resource • Monitor safeguards to ensure that they are properly implemented • Authorize access to those who have a business need for the informa-
tion and • Delete access for those who no longer have a business need for the
information
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
50 ◾ Information Security Fundamentals
− Custodian: Employees designated by the owner to be responsible for maintaining the safeguards established by the owner.
− User: Employees authorized by the owner to access information and use the safeguards established by the owner.
Senior management must ensure that the enterprise has the capabilities needed to accomplish its mission or business objectives. As we will see, senior management of a department, business unit, group, or other such entity is considered to be the functional owner of the enterprise’s assets and, in their fiduciary duty, act in the best interest of the enterprise to implement reasonable and prudent safeguards and controls. Risk management is the tool that will assist them in this task (Figure 4.1).
As you can see, the risk assessment process assists management in meeting its obligations to protect the assets of the organization. By being an active partner in the risk assessment process, management, when acting in the owner’s capacity, gets the opportunity to see what threats are lurking around the business process. Therefore, FRAAP allows the owner to identify where control weaknesses are and to develop an action plan to remedy the risks in a cost-effective manner.
The results of the FRAAP are a comprehensive risk assessment document that has the threats, risk levels, and controls documented. It also includes an action plan created by the owner with action items, responsible entities identified, and a time frame for completion established. The FRAAP assists management in meeting its obligation to perform due diligence.
A trained facilitator conducts the FRAAP session. This individual will lead the team through the identification of threats, the establishment of a risk level by determining probability and impact, and then the selection of possible safeguards or controls. Because of qualitative risk assessment’s subjective nature, it will be the responsibility of the facilitator to lead the team into different areas of concern to ensure that as many threats as possible are identified (Figure 4.2).
Instead of concentrating on establishing audit or security requirements, the facilitator ensures that the risk assessment process examines threats that might affect the business process or the mission of the enterprise. This ensures that only
Typical Role Risk Management Responsibility
Management Owner Under the Standard of Due Care, senior management is charged with the ultimate responsibility for meeting business objectives or mission requirements. Senior management must ensure that necessary resources are effectively applied to develop the capabilities to meet the mission requirements. They must incorporate the results of the risk assessment process into the decision-making process.
Figure 4.1 Management owner definition.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
Risk Management ◾ 51
those controls and countermeasures that are truly needed and cost-effective are selected and implemented.
Helping the trained facilitator is an individual acting as a recording secretary who will transcribe the meeting and help create the risk assessment documentation. As a scribe, this individual will accurately record the identification of threats and all other relevant information. Unlike an editor, the scribe does not alter the written word once the team has agreed that the meaning of the statement has been properly captured (Figure 4.3).
The Pre-FRAAP Meeting The pre-FRAAP meeting is the key to the success of the project. The meeting is normally scheduled for an hour and a half and is usually conducted at the business owner’s office. The meeting should have the business owner (or representative), the project development lead, facilitator, and the scribe. There will be seven deliverables to come out of this session.
1. Prescreening results. The prescreening process is conducted earlier in the System Development Life Cycle (SDLC). Because the risk assessment is a historical record of the decision-making process, a copy of the prescreening results should be entered into the official record and stored in the risk assess- ment action plan. The prescreening process is discussed in Chapter 3.
2. Scope statement. The project lead and business owner will have to create a statement of opportunity for the risk assessment. They are to develop (in
Typical Role Risk Management Responsibility
FRAAP Facilitator A facilitator is someone who skillfully helps a group of people understand their common objectives and assists them in planning to achieve them without taking a particular position in the discussion. The facilitator will try to assist the group in achieving a consensus on any disagreements that preexist or emerge in the FRAAP so that an action plan can be created.
Figure 4.2 FRAAP facilitator definition.
Typical Role Risk Management Responsibility
FRAAP Scribe The scribe is the individual responsible for taking the oral discussions and creating a written format. The scribe ensures that the threats are properly recorded and all actions of the risk assessment team are captured accurately.
Figure 4.3 FRAAP scribe definition.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
52 ◾ Information Security Fundamentals
words) what exactly is going to be reviewed. During the pre-FRAAP meet- ing, the Risk Assessment Scope Statement should be reviewed and edited into the final language.
It is during the development of the scope statement the threat categories need to be determined. In a typical information security risk assessment, we would include the CIA triad of confidentiality, integrity, and availability.
3. Visual diagram. There will need to be a visual model. This is a one-page or foil diagram depicting the process to be reviewed. The visual model will be used during the FRAAP session to acquaint the team with where the process begins and ends.
There is a good reason to require a visual diagram or an information flow model be included as part of the FRAAP. Neural-linguistic programming is a study of how people learn. This process has identified three basic ways in which people learn. These are
a. Auditory—these people have to hear something to grasp it. During the FRAAP, the owner will present the project scope statement to the team and those that learn in this manner will be fulfilled.
b. Mechanical—this learning type must write down the element to be learned. Those taking notes during meetings are typically mechanical learners.
c. Visual—this type of learner, of which most of us are, needs to see a pic- ture or diagram to understand what is being discussed. People who learn through this method normally have whiteboards in their office and use them often. So the visual diagram or model will help these people under- stand what is being reviewed.
4. Establish the FRAAP team. A typical FRAAP has between 15 and 30 mem- bers. The team is made up of representatives from a number of business and infrastructure and business support areas.
5. Meeting mechanics. This is the business unit manager’s meeting and he or she is responsible for scheduling the room, setting the risk assessment time, and having the appropriate materials (overhead, flip charts, coffee and doughnuts) on hand.
This risk assessment meeting is the responsibility of the owner. As the facilitator, you are assisting the owner in completing this task. It is not an information security, project management office, audit, or risk management meeting. It is the owner’s meeting and that person is responsible for schedul- ing the place and inviting the team.
6. Agreement on definitions. The pre-FRAAP session is where the agreement on FRAAP definitions is completed. These definitions will eventually become a standard used in the risk assessment process. However, it is always a good idea to review the concepts that will be used in the risk assessment (Figure 4.4).
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
Risk Management ◾ 53
You will want to agree on the definitions of the business attributes to be used as these will become your review elements. For many risk assessments, we have examined integrity, confidentiality, and availability. Recently, a group of my fel- low information security professionals and I examined the idea of which attri- butes should be examined. For years, we concentrated on examining the threats associated with the security triad on confidentiality, integrity, and availability (CIA).
Although CIA is a traditional form of risk assessment, it is important to under- stand that there are other business attributes that can be used in the process. When I was in college, in our Psychology 101 class and we discussed functional fixedness, which is a cognitive bias that limits a person to using an object only in the way it is traditionally used. When you give a child a present, they oftentimes have more fun playing with the wrappings or the box. That is because the wrappings can be anything.
I use this example in my training classes to remind audit, information security, and risk management that there are a vast number of business attributes that can be used to determine risk. Even if your primary use of risk assessment is to determine threats to assets based on examining confidentiality, integrity, and availability—try to remain open to other possibilities.
I sent a question out to my colleagues and posed the following question:
“When we are conducting risk assessments, we often examine threats based on CIA. We also discussed earlier this week that instead of CIA, we could consider reliability-performance-cost (for capital) or
Term Definition
Asset A resource of value. An asset may be a person, physical object, process, or technology
Threat The potential for an event, malicious or otherwise, that would damage or compromise an asset
Probability A measure of how likely a threat may occur
Impact The effect of a threat being carried out on an asset—expressed in tangible or intangible terms
Vulnerability Any flaw or weakness in the asset’s defenses that could be exploited by a threat to create an impact on the asset
Risk The combination of threat, probability, and impact expressed as a value in a predefined range
Figure 4.4 Risk assessment definitions.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
54 ◾ Information Security Fundamentals
portability-scalability-market penetration (for software) as examples. Does the use of these categories divide our way of thinking? Could this be titled threat categories? Also, do we do it this way because it is required or because it helps us think better within set boundaries?”
CIA, reliability-performance-cost, and portability-scalability-market penetration are just nine of the hundreds of such things defined in the Sherwood Applied Business Security Architecture (SABSA) method since 1996. We call them “business attributes” and the business attri- butes profile is used as the basis for all risk management.
The default prompt list/modeling tool kit has the 80 attributes that are most often reused internationally (see www.sabsa.org), although each organization has a different context and thus a different set.
We have a whole section dedicated to users’ definitions of these things and demonstrating case studies on the Institute web site. Sadly, that part of the site (it is in the member discussion area) isn’t publicly accessible yet, but we’ve about 200 people impatiently waiting on it out of the hundreds that are now certified in the method.
Could this be titled Threat Categories? I don’t believe so. They are not threats but the areas/things of value
we want to protect from the threats, that is, ultimately, the business things that are at risk. Thus, the use of the term business attributes seems to fit best.
However, they can easily be used to create a threat modeling taxonomy and they often are used that way in daily practice. Also, although you have correctly seen potential demarcation lines between different types (you used capital and software), a whole enterprise- wide taxonomy can be constructed that defines the things of value both unique to a division/stakeholder/department/team/project and to the enterprise as a whole. That in turn provides the basis for risk aggregation.
Also, do we do it this way because it is required or because it helps us think better within set boundaries?
I believe that it is the latter. It isn’t actually required but it helps. Boundaries and structure of many kinds help remove the horren- dous subjectivity and variable response we would get from a blank unbounded or unstructured risk management canvas.
The business attributes that are going to be used in the risk assessment pro- cess must be discussed and agreed upon. A formal set of definitions must also be established. The following are examples of some of the many business attri- butes that can be used to examined threats and establish risk levels (Figures 4.5 through 4.7).
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
Risk Management ◾ 55
During the pre-FRAAP session, it will be important to discuss the process for prioritizing threats. When examining the probability and impact of threats, it will be necessary to determine before the meeting if the threats are to be exam- ined as if no controls are in place. This is typically the case when doing a risk assessment on an infrastructure resource. These resources include the information
CIA Example
Term Definition
Availability Assuring information and communications services will be ready for use when expected
Confidentiality The assurance that information is not disclosed to inappropriate entities or processes
Integrity Assuring information will not be accidentally or maliciously altered or destroyed
Figure 4.5 Business attribute definitions (CIA).
Capital Expenditure Example
Term Definition
Reliability The extent to which the same result is achieved when a measure is repeatedly applied to the same asset
Performance A quantitative measure characterizing a physical or functional attribute relating to the execution of a mission/operation or function
Cost The total spent for goods or services including money, time, and labor
Figure 4.6 Business attribute definitions (capital expenditure).
Software Procurement Example
Term Definition
Portability A measure of system independence; portable programs can be moved to a new system by recompiling without having to make any other changes
Scalability The ability to expand a computing solution to support large numbers of users without affecting performance
Market Penetration The share of a given market that is provided by a particular good or service at a given time
Figure 4.7 Business attribute definitions (software procurement).
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
56 ◾ Information Security Fundamentals
processing network, the operating system platform, and even the information secu- rity program.
For other applications, systems, and business processes, the examination of threats takes into account existing controls. When we discuss the FRAAP session, we will examine each of these methods and how they work. This decision should be made during the pre-FRAAP meeting. Once the risk assessment process has been established, this discussion will not be necessary because the organization will standardize the risk level protocol.
Pre-FRAAP Meeting Checklist When I attend a pre-FRAAP meeting, I like to take with me a checklist that will ensure that I receive all of the items I need to complete the pre-FRAAP process (Figure 4.8).
Issue Remarks
Before the Meeting
1. Date of Pre-FRAAP Meeting Record when and where the meeting is scheduled
2. Project Executive Sponsor or Owner Identify the owner or sponsor who has executive responsibility for the project
3. Project Leader Identify the individual who is the primary point of contact for the project or asset under review
4. Pre-FRAAP Meeting Objective Identify what you hope to gain from the meeting— typically the seven deliverables will be discussed
5. Project Overview Prepare a project overview for presentation to the pre-FRAAP members during the meeting
Your understanding of the project scope
The FRAAP methodology
Milestones
Prescreening methodology
6. Assumptions Identify assumptions used in developing the approach to performing the FRAAP project
Figure 4.8 Pre-FRAAP meeting checklist.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
Risk Management ◾ 57
7. Prescreening Results Record the results of the prescreening process
During the Meeting
8. Business Strategy, Goals, and Objectives Identify what the owner’s objectives are and how they relate to larger company objectives
9. Project Scope Define specifically the scope of the project and document it during the meeting so that all participating will know and agree
• Applications/Systems
• Business Processes
• Business Functions
• People and Organizations
• Locations/Facilities
10. Time Dependencies Identify time limitations and considerations the client may have
11. Risks/Constraints Identify risks and/or constraints that could affect the successful conclusion of the project
12. Budget Identify any open budget/funding issues
13. FRAAP Participants Identify by name and position the individuals whose participation in the FRAAP session is required
14. Administrative Requirements Identify facility and/or equipment needs to perform the FRAAP session
15. Documentation Identify what documentation is required to prepare for the FRAAP session (provide the client the FRAAP Document Checklist)
Figure 4.8 (Continued) Pre-FRAAP meeting checklist.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
58 ◾ Information Security Fundamentals
Figure 4.9 gives direction on filling out the pre-FRAAP meeting checklist. By completing this checklist, the elements for the project scope statement will
be nearly complete. Two of the key elements contained in the checklist, and that must be part of the project scope statement, are the categories of assumptions and constraints. It is important that we understand what these are and how they affect the risk assessment process.
Issue Activity
Before the Meeting
1. Date of Pre-FRAAP Meeting Record the date the actual pre-FRAAP meeting occurred
2. Project Executive Sponsor or Owner Record the full name and proper title of the owner of the asset that is to be reviewed
3. Project Leader Record the full name and proper title of the project lead for this specific asset or task
4. Pre-FRAAP Meeting Objective There are seven deliverables for the pre-FRAAP meeting:
• Scope statement
• Visual model
• Assessment Team
• Definitions
• Meeting Mechanics
• Prescreening results
• Mini Brainstorming Results
5. Project Overview If the FRAAP is a new concept to the owner and/or project lead, provide them with an overview of the process
Your understanding of the project scope
The FRAAP methodology
Milestones
Prescreening methodology
6. Assumptions Record any issues that are needed to support the project scope statement
7. Prescreening Results Record the prescreening results
Figure 4.9 Pre-FRAAP meeting checklist directions.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
Risk Management ◾ 59
I have a client who brings me in from time to time to conduct FRAAP refresher training for employees. It gives the employees who have previously taken the train- ing a chance to be exposed to new ideas and concepts, and for other employees to be exposed to the process for the first time. Typically, this process is done over 3 or 4 days. It consists of a day and a half of training and then in the afternoon of day two, the pre-FRAAP meeting is conducted. The following day, the FRAAP ses- sion is conducted and then, that afternoon and the following day, I work with the project leader and the facilitator to complete the risk assessment documentation.
On the afternoon of day one, the project leader and his backup informed me that they had a meeting to attend and would be back the following day. Not only did they miss the afternoon training of day one, they also did not return for any
During the Meeting
8. Business Strategy, Goals, and Objectives
Record the mission of the asset under review and how it supports the overall business objectives or mission of the enterprise
9. Project Scope Draft the FRAAP scope statement
• Applications/Systems
• Business Processes
• Business Functions
• People and Organizations
• Locations/Facilities
10. Time Dependencies Identify any time issues and enter them into the constraints section of the scope statement
11. Risks/Constraints Record any issues that may affect the results of the FRAAP
12. Budget Where appropriate, establish a work order number of project identification number that FRAAP team members can use to report time spent on specific projects.
13. FRAAP Participants Record who the stakeholders are and other team members as requested by the owner
14. Administrative Requirements Record any special requirements needed for the FRAAP session
15. Documentation Record all laws, regulations, standards, directives, policies, and/or procedures that are part of the infrastructure supporting the asset under review
Figure 4.9 (Continued) Pre-FRAAP meeting checklist directions.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
60 ◾ Information Security Fundamentals
of the day two training. On the afternoon of day two, the attendees that were there decided to try and put together a project scope statement. The audience was almost exclusively information security and audit professionals. The scope state- ment lacked the business side, but at least we were able to be ready for the following day. Because of the team makeup, we did not address assumptions or constraints.
On the day of the FRAAP session, the project leaders returned with the owner. This was the first time the owner had ever been exposed to a risk assessment pro- cess. We presented them with the scope statement that we had created and the owner said that it looked okay to her. So, after a brief introduction and an overview of the methodology, we began the process of identifying threats. After approximately 2 hours, the team had identified nearly 150 threats. As we were working through the FRAAP session, I noticed that owner’s face had initially turned red and at the break was now white. I approached her to see if there was a problem. She informed me that the system was going into production on the following Monday and there was no way she could tell her bosses that 150 threats were uncovered.
During the break, I thought about what had transpired and when she came back I sat down with her to review the scope statement and to fill in the assumption area. A number of the threats identified were directly related to elements within the information security program. Threats such as
◾ Passwords being posted on workstations ◾ Employees leaving workstations logged on and unattended ◾ Employees leaving work materials out after hours ◾ Shoulder surfing passwords or other access codes ◾ Unauthorized access to restricted areas
Although these were important threats, they were already addressed in the risk assessment conducted on the information security infrastructure previously and were not unique to the specific application under review. By modifying the assumption section of the scope statement to include a reference to the fact that it was assumed that a risk assessment had been conducted on the information security infrastructure and that compensating controls were in place or were being implemented. We also addressed the processing infrastructure and applications development methodology in the same manner. By making sure the assumptions were properly identified, we reduced the number of threats from approximately 150 to approximately 30.
The FRAAP was not diminished in any way. The 120 or so threats that were exercised from the risk assessment report had already been identified in the infra- structure risk assessments and were being acted on. If other risk assessments have been conducted, then enter that information into the assumptions area.
If the infrastructure risk assessments have not been conducted, then enter that information into the constraints area. This will allow the risk assessment to con- centrate on the specific asset at hand, but puts the organization on notice that other risk assessments must be scheduled.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
Risk Management ◾ 61
Other constraints might include the concerns about the use of obsolete operat- ing system, those that are no longer supported by the manufacturer. The back level of the patch application might also be a constraint to identify.
Assumptions and constraints allow the risk assessment team to focus on the asset at hand. The organization must conduct the other risk assessments to make certain that the infrastructure is as secure as possible.
Over the past 2 years, an extra process has been added to the pre-FRAAP por- tion of the risk assessment process. That extra element is a brief mini brainstorming process. At the end of the pre-FRAAP session, those assembled should conduct a quick threat identification process. Using each of the business attributes that are to be examined, the pre-FRAAP team will identify threats to the asset just as the entire team will during the FRAAP session. It will be important to get four or five threats for each business attribute. The FRAAP facilitator will use this information during the FRAAP session (Figure 4.10).
Pre-FRAAP Meeting Summary The pre-FRAAP meeting sets the stage for the FRAAP session and all of the work that is to follow. It is very important that each of the seven deliverables be as com- plete as possible. If they are not complete, then this could be a major constraint to the risk assessment process.
Integrity Confidentiality Availability
Data stream could be intercepted
Insecure e-mail could contain confidential information
Files stored in personal directories may not be available to other employees when needed
Faulty programming could (inadvertently) modify data
Internal theft of information Hardware failures could affect the availability of company resources
Copies of reports could be diverted (written or electronically) to unauthorized or unintended persons
Employee is not able to verify the identity of a client, example: phone masquerading
A failure in the data circuit could prohibit system access
Data could be entered incorrectly
Confidential information is left in plain view on a desk
Act of God—tsunami/ hurricane
Intentional incorrect data entry
Social discussions outside the office could result in disclosure of sensitive information
Upgrades in the software may prohibit access
Figure 4.10 Mini brainstorming results.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
62 ◾ Information Security Fundamentals
The FRAAP Session Overview The FRAAP session is typically scheduled for 4 hours. This is a very tight time- frame and can be expanded if you have the time and resources available. During the past 2 years, I have been back out in the field conducting FRAAPs for various clients. The 4-hour window is sufficient to capture threats associated with the busi- ness attributes of a specific asset. Then identify existing controls and conduct a risk level analysis of the threats to identify those risks that require risk remediation. As we discussed earlier, the key component in the development of the FRAAP was the time commitment that was available from the team members.
Think about the typical employee schedule at work each week. How much free or available time do you have each week? For many of us, we donate at least 12 hours of our workweek to meetings. For the people that will be asked to participate in the risk assessment process, there will be an effect on their available time. The FRAAP is designed to meet the needs of an effective risk assessment while affecting the team members as little as possible.
FRAAP Session Introduction Once the FRAAP session is called together, the executive responsible for the asset under review will address the team with opening remarks. This overview will help the team understand why they were asked to be part of the FRAAP and how important senior management considers the risk assessment process to be. When the overview is complete, the facilitator will present the agenda to the team. A typi- cal agenda might include the items listed in Figure 4.11.
FRAAP Session Agenda Responsibility
• Explain the FRAAP process Facilitator
• Review scope statement Owner
• Review visual diagram Technical support
• Discuss definitions Facilitator
• Review objectives
• Identify threats
• Establish risk levels
• Identify possible safeguards
Facilitator
• Identify roles and introduction Team
• Review session agreements Facilitator
Figure 4.11 FRAAP session agenda.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
Risk Management ◾ 63
The facilitator will explain the FRAAP to the team. This will include a discus- sion on the deliverables expected from each stage of the process. With the assistance of the facilitator, the team will identify threats to the asset under review. Using a formula of probability and impact, the team will then affix a risk level to each threat and, finally, the team will select possible controls to reduce the risk intensity to an acceptable level.
The business manager/owner will then present the project scope statement. It will be important to discuss the assumptions and constraints identified in the state- ment. The team should have a copy of the scope statement that they can refer to as the need arises during the FRAAP session. The assumptions and constraints will be helpful in ensuring that the deliverables are as accurate as possible.
The technical support will then give a 5-minute overview of the process using an information flow model or diagram. This will allow the team to visualize the process under review.
The facilitator will then review the term definitions to be used for this FRAAP session. Once the risk assessment process becomes part of the organization’s cul- ture, these definitions will become standard and the need for review will diminish. To expedite the process, the FRAAP session definitions should be included in the meeting notice.
The facilitator will then reiterate the objectives and deliverables of this initial stage. At this point, stage two of this process should be briefly discussed. In the meeting notice, it will be necessary to notify those individuals that are needed to be present for stage two that they will be staying for an additional hour.
At this point, the FRAAP team should introduce itself. Have each member introduce themselves and provide the following information for the scribe to capture:
◾ Team member name (first and last) ◾ Department ◾ Location ◾ Phone number
After the introductions, the facilitator will review the session agreements with the team members (Figure 4.12).
FRAAP Session Talking Points
Everyone participates—it is important to get input from everyone in attendance. There will be those that will want to sit back for the first few minutes to get the lay of the process and become comfortable. Some of this apprehension can be alleviated by having a FRAAP awareness session throughout your organization. Many times, it is the fear of the unknown that causes team
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
64 ◾ Information Security Fundamentals
members to hold back. By conducting brief awareness sessions that explain the reasons for and the process done by the risk assessment process, the team members will have a greater feeling of participation.
Stay within identified roles—introduce the facilitator and scribe. Explain that your job is to get the FRAAP completed within the limited timeframe. The scribe will record all of the agreed upon findings of the risk assessment. All others present are team members. As they enter the room, they initially take off current roles and put on the team member role.
Stick to the agenda/current focus—the reason that the scope statement and visual model are discussed early in the process is so that every one is reminded of what the focus of the FRAAP meeting is. We all have attended meetings in which the intended purpose seems to get thrown out and anything else pos- sible is discussed. It will be your job to keep the team on focus.
All ideas have equal value—this one is very difficult. As discussed above, some people are a bit intimidated by other team members. Sometimes, the users are apprehensive to discuss threats to applications or system while IT infrastruc- ture personnel are present. It will be necessary for everyone to feel that their ideas are just as important as anyone else’s.
Listen to other points of view—many times in meetings, some attendees break out of the group and carry on private conversations. At the beginning of the session, we try to remind the team that the best way we can show the respect we want is by showing respect to others.
Session Agreements
• Everyone participates
• Stay within identified roles
• Stick to the agenda/current focus
• All ideas have equal value
• Listen to other points of view
• No “plops”… all issues are recorded
• Deferred issues will be recorded
• Post the idea before discussing it
• Help scribe ensure all issues are recorded
• One conversation at a time
• One angry person at a time
Figure 4.12 FRAAP session agreements.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
Risk Management ◾ 65
No “plops”—all issues are recorded—at least once in every session, someone will comment that “This may seem stupid, but…” and then they present a unique twist to the issues being discussed. One of the many questions that arise when a risk assessment decision is being questioned is “What did you con- sider?” This very question is why it is important to record all issues.
Deferred issues will be recorded—in the FRAAP documentation, there is a spot to record any issue that is outside the scope of the current meeting. This will allow the team to record the concern and assign someone to follow up on it.
Post the idea before discussing it—there will be a period of discussion on what the threat is and then there will often be some editing and finally the scribe will post the agreed upon item.
Help the scribe ensure that all issues are recorded—although there are time con- straints on completing the session, it is vitally important to capture the issues and comments correctly.
One conversation at a time—as we discussed above, it is important for the team to keep focused on the task at hand. If a number of separate conversations break out, then the objectives of the FRAAP session may not be completed during the allotted time.
Apply the 3- to 5-minute rule—when discussing the risk level setting factors, it is important that after the first three or four discussions that a time limit be more or less adhered to.
When all of the preliminary activities have been concluded, it is time to begin the risk assessment process.
FRAAP Threat Identification When I conduct a FRAAP, I like to have the room set up in a “U” shape. This allows me to work closer to the team members and it allows the process to flow around a conference room table. By being set up in this manner, everyone is in the front row. If the room is set up classroom style it is harder to get the people in the back to feel that they are part of the team.
In the room setup, it is important to include pads of paper and pens or pencils for the team to use. The team will be writing down their ideas and it is always best to have the implements readily available than to take time to try and find them.
During the FRAAP session, I normally discourage the use of laptops or PDAs. The team has been called by the owner to assist them in meeting their due dili- gence obligation. If the team members are busy answering e-mails or distracted by other activities, the risk assessment will suffer. I also request that all cell phones and pagers be placed on “stun” or vibrate so as not to disturb the other team members.
To begin the brainstorming process, the facilitator will put the first business attribute to be reviewed up for the team to see. This will include the definition of
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
66 ◾ Information Security Fundamentals
the review element and some examples of threats that the team can use as thought starters. I normally use a PowerPoint slide for this process so that the entire team can see what it is that the FRAAP is trying to identify (Figure 4.13).
The team is given 3 to 5 minutes to write down threats that are of concern to them. The facilitator will then go around the room getting one threat from each team member. Many will have more than one threat, but the process is to get one threat and then move to the next person. This way everyone gets a turn at par- ticipating. The process continues until everyone passes (that is, there are no more threats that the team can think of).
During the first two rounds, most of the team members will participate. As the rounds progress, the number of team members with new threats will dimin- ish. When it gets down to just a few still responding, you can just ask for a new threat from anyone rather than going around the table and calling on each person again.
If a person passes, it does not mean that they are then locked out of the round. If something new comes into their mind, then they can join back in when it is their turn to do so again. They may hear a threat from someone else that will jog their thought process. This is why I recommend that there be paper and pens available for the team members to write down these quick-hitting ideas. Most all of us suffer from terminal CRS (can’t remember stuff). By providing paper and pens, the team members can capture these fleeting thoughts.
I am sad to point out that, to some people, everything is a contest. Too often, the brainstorming round will dwindle down to two team members. When this occurs, the battle to be “King of the Threats” begins. They will continue to throw out ever more absurd threats until one will finally yield. I share this with you only so that you can be on the alert for such behavior.
Integrity
Definition: assuring information will not be accidentally or maliciously altered or destroyed
Threats
Data stream could be intercepted
Faulty programming could (inadvertently) modify data
Copies of reports could be diverted (written or electronically) to unauthorized or unintended persons
Data could be entered incorrectly
Intentional incorrect data entry
Figure 4.13 FRAAP brainstorming attribute 1.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
Risk Management ◾ 67
Once all of the integrity threats have been recorded, it is time for the facilitator to display the second review element with threat examples and give the team 3 to 5 minutes to write down their threats (Figure 4.14).
During this phase, I like to start the threat identification on the opposite side of the room from where I started last time. This allows those who were last to be first and get the best threats. The collecting of threats will continue until every- one has passed and there are no more confidentiality threats. After the scribe has indicated that everything has been captured, it will be time to go to the third element (Figure 4.15).
Confidentiality
Definition: the assurance that information is not disclosed to inappropriate entities or processes
Threats
Insecure e-mail could contain confidential information
Internal theft of information
Employee is not able to verify the identity of a client, example: phone masquerading
Confidential information is left in plain view on a desk
Social discussions outside the office could result in disclosure of sensitive information
Figure 4.14 FRAAP brainstorming attribute 2.
Availability
Definition: assuring information and communications services will be ready for use when expected
Threats
Files stored in personal directories may not be available to other employees when needed
Hardware failures could affect the availability of company resources
A failure in the data circuit could prohibit system access
Act of God—tsunami/hurricane
Upgrades in the software may prohibit access
Figure 4.15 Brainstorming attribute 3.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
68 ◾ Information Security Fundamentals
Once the threats have been recorded, the FRAAP documentation will look like Figure 4.16.
Business Attribute Threat
Integrity Data stream could be intercepted
Integrity Faulty programming could (inadvertently) modify data
Integrity Copies of reports could be diverted (written or electronically) to unauthorized or unintended persons
Integrity Data could be entered incorrectly
Integrity Intentional incorrect data entry
Confidentiality Insecure e-mail could contain confidential information
Confidentiality Internal theft of information
Confidentiality Employee is not able to verify the identity of a client, example: phone masquerading
Confidentiality Confidential information is left in plain view on a desk
Confidentiality Social discussions outside the office could result in disclosure of sensitive information
Availability Files stored in personal directories may not be available to other employees when needed
Availability Hardware failures could affect the availability of company resources
Availability A failure in the data circuit could prohibit system access
Availability Act of God—tornado/hurricane
Availability Upgrades in the software may prohibit access
Figure 4.16 FRAAP worksheet 1 after threats have been identified.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
Risk Management ◾ 69
When I am conducting a FRAAP session, I use different color pens for each element. Integrity might be blue, confidentiality green, and availability recorded in black. This will allow me to keep track of the threats by color-coding them. As a flip chart page is filled up, I post it around the conference room. I record each threat sequentially within an element. For example, I will record all integrity threats in blue and number each threat in the order it was received starting with threat one. When I move to confidentiality threats, I will switch to a green marker and start the numbering over again with one. I will do the same when I get to the availability threats.
When all the threats have been posted, I recommend that the team be given a 15-minute coffee break to do three important activities:
◾ Check messages ◾ Get rid of old coffee and get new ◾ Clean up the raw threats
As the team is having its break, have them review the threats and within the specific element delete duplicate threats and combine like threats. If a threat is repeated in the integrity and confidentiality element, it is not considered to be a duplicate. It is only a duplicate if it appears more than once within a specific element. Only allow 15 minutes of the break for the clean-up process.
Identify Threats Using a Checklist During the past few years, some organizations have faced the task of doing a large number of risk assessments to become compliant with specific new laws and regu- lations. HIPAA is one specific example. A number of health care organizations contacted me to help them put together their risk assessment program. When we began to examine their specific needs, we found out that they did not have 4 hours for the risk assessment process. They found that they could get people to commit to a 2-hour window. So, from there, we worked to find ways to streamline the process. We were able to meet the 2-hour window by creating a checklist of threats to work off of. The results of this work are available for you in Appendix A: Facilitated Risk Analysis and Assessment Process (FRAAP) (see Figure 4.17).
To keep the risk assessment as clear as possible, we will concentrate on the activities that take place using the brainstorming techniques. When we have completed that discussion, we will turn our attention to the checklist style of risk assessment.
Identifying Existing Controls Once the threats list has been completed, the team should quickly review each threat and determine if there are any existing controls in place that address those
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
70 ◾ Information Security Fundamentals
threats issues. By identifying those threats that have existing controls in place, the team will be better able to determine the real current risk level. This is one of the many reasons that the FRAAP needs representation from the various infrastructure groups. They will typically know best what controls and safeguards are already implemented (Figure 4.18).
Business Attribute Threat Existing Controls
Integrity Data stream could be intercepted Vacant ports are disconnected
Integrity Faulty programming could (inadvertently) modify data
Programs are tested before going into production, and change management procedures are in place. Gramm Leach Bliley Act’s (GLBA’s) Information Technology Policies and Procedures Manual No. 5-11, ISD Documentation; Test Plan and Test Analysis Report Standard
Integrity Copies of reports could be diverted (written or electronically) to unauthorized or unintended persons
Integrity Data could be entered incorrectly
Transaction journals are used. Contracts with third parties include language that addresses data integrity and service level agreements are designed to protect against this risk
Figure 4.18 FRAAP worksheet 2 after existing controls have been identified.
Threat Applicable (Yes/No)
Environmental
Power flux
Power outage—internal
Power outage—external
Water leak/ plumbing failure
HVAC failure
Figure 4.17 Sample threat checklist.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
Risk Management ◾ 71
Integrity Intentional incorrect data entry
Transaction logs are maintained and reviewed to detect incorrect data entry
Confidentiality Insecure e-mail could contain confidential information
Confidentiality Internal theft of information GLBA’s Code of Conduct Policy
Confidentiality Employee is not able to verify the identity of a client, example: phone masquerading
Customer must provide the date of last deposit, or other confidential personal information within their file, and give to the employee before information is released
Confidentiality Confidential information is left in plain view on a desk
Confidentiality Social discussions outside the office could result in disclosure of sensitive information
Code of Conduct/Conflict of Interest Policy. Annual Awareness item
Availability Files stored in personal directories may not be available to other employees when needed
GLBA’s management has established written policies and procedures to ensure information resources are available. See GLBA’s Information Technology Policies and Procedures Manual No. 8-1 and Information Technology Policies and Procedures Manual No. 7-4
Availability Hardware failures could affect the availability of company resources
GLBA’s management has established written policies and procedures to ensure information resources are available. See GLBA’s IT P&P No. 8-1 and IT P&P No. 7-4
Vendor maintenance agreements are established to support timely resolution of hardware failures.
Files are imaged and stored to support recovery of information (ghost files)
Availability A failure in the data circuit could prohibit system access
Vendor maintenance agreements are established to support timely resolution of hardware failures.
See Information Technology Policies and Procedures Manual No. 2-2
Figure 4.18 (Continued) FRAAP worksheet 2 after existing controls have been identified.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
72 ◾ Information Security Fundamentals
Establish Risk Levels This is probably the most important portion of the FRAAP and often the most confusing and most fun. You will want to ensure that the team has had an opportu- nity to examine the definitions used to establish probability and impact threshold levels. I like to include this information in the meeting notice attachments. This process will also be discussed during your FRAAP awareness program and briefly reviewed in the FRAAP session opening remarks.
For our initial review of the risk level setting process, we will use a very simple example of the probability and impact thresholds.
At this point in the FRAAP, we have identified threats to the asset under review using the agreed upon business attributes. We then examined each threat and iden- tified those that had existing controls or safeguards in place. Our next task will be to determine how likely that threat will occur the next time and what effect to the organization there would be if the threat were to occur (Figure 4.19).
The team will discuss how likely the threat is to occur during the specified time frame. What you will want to do is to apply a good dose of common sense to the discussion. One of the examples that I like to use is the threat that an unattended workstation could be used by some other person to access the system. A good reality
Term Definition
Probability A measure of how likely a threat may occur
Threshold Level
High Very likely that the threat will occur within the next year
Medium Possible that the threat will occur within the next year
Low Highly unlikely that the threat will occur within the next year
Figure 4.19 FRAAP probability thresholds.
Availability Act of God—tornado/hurricane
Availability Upgrades in the software may prohibit access
GLBA’s management has established written policies and procedures to ensure that software is tested before use in a production environment.
See GLBA’s Information Technology Policies & Procedures Manual 3-1 and IT P&P Manual 4-18
Figure 4.18 (Continued) FRAAP worksheet 2 after existing controls have been identified.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
Risk Management ◾ 73
check is what you want to instill in this process. In the 30 years I have been in infor- mation security, this threat has always made every discussion list. I am not certain that I can cite one example of this threat actually occurring.
So when you discuss probability, you will want them to address if this threat has actually occurred. If so, when was the last time that the threat did occur? This will provide the team with an ongoing reality check. You will want to keep them focused on the fact that the threats are being examined with existing controls in place.
Once the probability has been established, you will want to identify the impact presented by that threat to the asset under review (Figure 4.20).
Here, again, it will be necessary to work with the team to ensure that the impact level is actually understood. Many times in the FRAAP, the business owner or users will get the impression that if their business unit is affected, then the impact level is rated high. Typically, that is not the case. A high impact level is used to identify those threats that would affect the entire organization. One way to help the team see the issue in the proper light is to ask if the threat has ever occurred. If it has, then we want to discuss what the effect really was.
I recently conducted a risk assessment in which the threat identified was that contractors could enter data incorrectly into the system. Initially, the discussion was that the probability of occurrence was high and that it had the possibility to severely affect the entire mission of the agency. I asked the question about the high probability and found out that this issue happened on an almost daily basis. With that information, we turned our attention to the effect. Although it was true that there was a chance that the entire agency could be affected, the fact that existing controls had prevented it from reaching that level seemed to mean that something less than a high impact was the correct answer.
It helps to work with the team for the first few threats to make certain that everyone sees how the process works. Once the probability and impact have been selected, it will be easy to identify the risk level (Figure 4.21).
Term Definition
Impact The effect of a threat being carried out on an asset—expressed in tangible or intangible terms
Threshold Level
High Entire mission or business is affected
Medium Loss limited to single business unit or business objective
Low Business as usual
Figure 4.20 FRAAP impact thresholds.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
74 ◾ Information Security Fundamentals
The team can examine where the probability and impact levels fall and then can assign a risk level (Figure 4.22).
Therefore, the results would look like Figure 4.23.
Residual Risk When examining a threat, there are typically two types of risk that will be identified. In the example below, there are three total risks identified. The first two have exist- ing controls in place and the third threat does not. After performing the probability/ impact process in the first two threats, the risk level that will be established is termed the residual risk. The risk remaining after the implementation of new or enhanced controls is the residual risk. Practically no system is risk-free, and not all implemented controls can eliminate the risk they are intended to address or reduce the risk level to zero.
For the third threat, because there are no existing controls in place, the risk level established is termed the baseline risk level. The baseline risk level (Figure 4.24) is cre- ated by establishing the probability and impact of a threat with no control selected. This is done to determine if the risk is great enough to require further action.
After the risk levels have been established, it will be necessary to assess if the risk level is acceptable. There are a number of factors that will ultimately determine if the risk level is acceptable. For the purposes of this exercise, we will state that any risk level of medium or high level must be reexamined to determine if additional controls could lower the risk level (Figure 4.25).
The final process in the FRAAP session is to identify controls for those threats identified as having a high risk level. In the example, those would be anything
Color Risk Level Action
Red High Requires immediate action
Yellow Medium May require action, must continue to monitor
Green Low No action required at this time
Figure 4.22 Risk level color key.
Probability
Impact
Low Medium High
High Medium High High
Medium Low Medium High
Low Low Low Medium
Figure 4.21 FRAAP probability/impact matrix.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
Risk Management ◾ 75
Business Attribute Threat Existing Controls
Probability/ Impact
Risk Level
Integrity Data stream could be intercepted
Vacant ports are disconnected L/M Low
Integrity Faulty programming could (inadvertently) modify data
Programs are tested before going into production, and change management procedures are in place. GLBA’s Information Technology Policies and Procedures Manual No. 5-11, ISD Documentation; Test Plan and Test Analysis Report Standard
L/L Low
Integrity Copies of reports could be diverted (written or electronically) to unauthorized or unintended persons
M/M Medium
Integrity Data could be entered incorrectly
Transaction journals are used. Contracts with third parties include language that addresses data integrity and service level agreements are designed to protect against this risk
M/L Low
Integrity Intentional incorrect data entry
Transaction logs are maintained and reviewed to detect incorrect data entry
L/M Low
Confidentiality Insecure e-mail could contain confidential information
L/H Medium
Confidentiality Internal theft of information
GLBA’s Code of Conduct Policy L/L Low
Confidentiality Employee is not able to verify the identity of a client, example: phone masquerading
Customer must provide the date of last deposit, or other confidential personal information within their file, and give to the employee before information is released
L/H Medium
Confidentiality Confidential information is left in plain view on a desk
M/M Medium
Figure 4.23 FRAAP worksheet 3 with risk levels assigned.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
76 ◾ Information Security Fundamentals
Business Attribute Threat Existing Controls
Probability/ Impact
Risk Level
Confidentiality Social discussions outside the office could result in disclosure of sensitive information
Code of Conduct/Conflict of Interest Policy. Annual Awareness item
M/M Medium
Availability Files stored in personal directories may not be available to other employees when needed
GLBA’s management has established written policies and procedures to ensure information resources are available
See GLBA’s Information Technology Policies and Procedures Manual No. 8-1 and Information Technology Policies and Procedures Manual No. 7-4
L/H Medium
Availability Hardware failures could affect the availability of company resources
GLBA’s management has established written policies and procedures to ensure information resources are available
See GLBA’s IT P&P No. 8-1 and IT P&P No. 7-4
Vendor maintenance agreements are established to support timely resolution of hardware failures
Files are imaged and stored to support recovery of information (Ghost files)
L/L Low
Availability A failure in the data circuit could prohibit system access
Vendor maintenance agreements are established to support timely resolution of hardware failures.
See Information Technology Policies and Procedures Manual No. 2-2
L/L Low
Availability Act of God— tornado/hurricane
M/H High
Availability Upgrades in the software may prohibit access
GLBA’s management has established written policies and procedures to ensure that software is tested before use in a production environment
See GLBA’s Information Technology Policies and Procedures Manual 3-1 and IT P&P Manual 4-18
L/L Low
Figure 4.23 (Continued) FRAAP worksheet 3 with risk levels assigned.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
Risk Management ◾ 77
identified as having a risk level of “high” or “medium.” A sample control list should be sent out to all team members along with the meeting notice and copies should be available for the team during the FRAAP session.
During this step, the risk assessment team will determine which security con- trols generally could best reduce the threat risk level to a more acceptable level. There are a number of sources for standards that can assist the risk assessment team in establishing an effective set of controls. These sources might include some of the following:
◾ Information Technology—Code of Practice for Information Security Management (ISO/IEC 27002)
◾ Security Technologies for Manufacturing and Control Systems (ISA-TR99.00.01-2004)
◾ Integrating Electronic Security into Manufacturing and Control Systems Environment (ISA-TR99.00.02-2004)
◾ Federal Information Processing Standards Publications (FIPS Pubs) ◾ National Institute of Standards and Technology ◾ CobiT Security Baseline ◾ Health Insurance Portability and Accountability Act (HIPAA) ◾ The Basel Accords ◾ Privacy Act of 1974
Business Attribute Existing Controls�reats
Probability/ Impact
Risk Level
Integrity Data stream could be intercepted
Vacant ports are disconnected
L/M Low
Integrity Faulty programming could (inadvertently) modify data
Programs are tested before going into production, and change management procedures are in place. GLBA’s Information Technology Policies and Procedures Manual No. 5-11, ISD Documentation; Test Plan and Test Analysis Report Standard
L/L Low
Integrity Copies of reports could be diverted (written or electronically) to unauthorized or unintended persons
M/M Medium
} }
Residual Risk
Baseline Risk Level
Figure 4.24 FRAAP residual risk/baseline risk level.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
78 ◾ Information Security Fundamentals
B us
in es
s A
tt ri
bu te
Th re
at Ex
is ti
ng C
on tr
ol s
Pr ob
ab ili
ty /
Im pa
ct R
is k
Le ve
l A
cc ep
ta bl
e Le
ve l (
Ye s/
N o)
In te
gr ity
D at
a st
re am
c ou
ld b
e in
te rc
ep te
d Va
ca nt
p or
ts a
re d
is co
nn ec
te d
L/ M
Lo w
Ye s
In te
gr ity
Fa ul
ty p
ro gr
am m
in g
co ul
d (in
ad ve
rt en
tly ) m
od ify
d at
a Pr
og ra
m s a
re te
st ed
b ef
or e
go in
g in
to p
ro du
ct io
n, a
nd
ch an
ge m
an ag
em en
t p ro
ce du
re s a
re in
p la
ce . G
LB A’
s In
fo rm
at io
n Te
ch no
lo gy
P ol
ic ie
s a nd
P ro
ce du
re s M
an ua
l N
o. 5
-1 1,
IS D
D oc
um en
ta tio
n; T
es t P
la n
an d
Te st
A na
ly si
s Re
po rt
S ta
nd ar
d
L/ L
Lo w
Ye s
In te
gr ity
C op
ie s o
f r ep
or ts
c ou
ld b
e di
ve rt
ed
(w ri
tte n
or e
le ct
ro ni
ca lly
) t o
un au
th or
iz ed
o r u
ni nt
en de
d pe
rs on
s
M /M
M ed
iu m
N o
In te
gr ity
D at
a co
ul d
be e
nt er
ed in
co rr
ec tly
Tr an
sa ct
io n
jo ur
na ls
ar e
us ed
. C on
tr ac
ts w
ith th
ird p
ar tie
s in
cl ud
e la
ng ua
ge th
at a
dd re
ss es
d at
a in
te gr
ity a
nd se
rv ic
e le
ve l a
gr ee
m en
ts a
re d
es ig
ne d
to p
ro te
ct a
ga in
st th
is ri
sk
M /L
Lo w
Ye s
In te
gr ity
In te
nt io
na l i
nc or
re ct
d at
a en
tr y
Tr an
sa ct
io n
lo gs
a re
m ai
nt ai
ne d
an d
re vi
ew ed
to d
et ec
t in
co rr
ec t d
at a
en tr
y L/
M Lo
w Ye
s
C on
fid en
tia lit
y In
se cu
re e
-m ai
l c ou
ld c
on ta
in
co nfi
de nt
ia l i
nf or
m at
io n
L/ H
M ed
iu m
N o
C on
fid en
tia lit
y In
te rn
al th
ef t o
f i nf
or m
at io
n G
LB A’
s C od
e of
C on
du ct
P ol
ic y
L/ L
Lo w
Ye s
C on
fid en
tia lit
y Em
pl oy
ee is
n ot
a bl
e to
v er
ify th
e id
en tit
y of
a c
lie nt
, e xa
m pl
e: p
ho ne
m
as qu
er ad
in g
C us
to m
er m
us t p
ro vi
de th
e da
te o
f l as
t d ep
os it,
o r o
th er
co
nfi de
nt ia
l p er
so na
l i nf
or m
at io
n w
ith in
th ei
r fi le
, a nd
g iv
e to
th e
em pl
oy ee
b ef
or e
in fo
rm at
io n
is re
le as
ed
L/ H
M ed
iu m
N o
C on
fid en
tia lit
y C
on fid
en tia
l i nf
or m
at io
n is
le ft
in p
la in
vi
ew o
n a
de sk
M /M
M ed
iu m
N o
Fi gu
re 4
.2 5
FR A
A P
w or
ks he
et 4
a cc
ep ta
bl e
ri sk
le ve
l d et
er m
in ed
.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
Risk Management ◾ 79
C on
fid en
tia lit
y So
ci al
d is
cu ss
io ns
o ut
sid e
th e
offi ce
c ou
ld re
su lt
in d
is cl
os ur
e of
se ns
iti ve
in fo
rm at
io n
C od
e of
C on
du ct
/C on
fli ct
o f I
nt er
es t P
ol ic
y. A
nn ua
l A w
ar en
es s
ite m
M /M
M ed
iu m
N o
Av ai
la bi
lit y
Fi le
s s to
re d
in p
er so
na l
di re
ct or
ie s m
ay n
ot b
e av
ai la
bl e
to o
th er
e m
pl oy
ee s w
he n
ne ed
ed
G LB
A’ s m
an ag
em en
t h as
e st
ab lis
he d
w rit
te n
po lic
ie s a
nd
pr oc
ed ur
es to
e ns
ur e
in fo
rm at
io n
re so
ur ce
s a re
a va
ila bl
e.
Se e
G LB
A’ s I
nf or
m at
io n
Te ch
no lo
gy P
ol ic
ie s a
nd P
ro ce
du re
s M
an ua
l N o.
8 -1
a nd
In fo
rm at
io n
Te ch
no lo
gy P
ol ic
ie s a
nd
Pr oc
ed ur
es M
an ua
l N o.
7 -4
L/ H
M ed
iu m
N o
Av ai
la bi
lit y
H ar
dw ar
e fa
ilu re
s c ou
ld a
ffe ct
th
e av
ai la
bi lit
y of
c om
pa ny
re
so ur
ce s
G LB
A’ s m
an ag
em en
t h as
e st
ab lis
he d
w rit
te n
po lic
ie s a
nd
pr oc
ed ur
es to
e ns
ur e
in fo
rm at
io n
re so
ur ce
s a re
a va
ila bl
e.
Se e
G LB
A’ s I
T P
& P
N o.
8 -1
a nd
IT P
& P
N o.
7 -4
.
Ve nd
or m
ai nt
en an
ce a
gr ee
m en
ts a
re e
st ab
lis he
d to
su pp
or t t
im el
y re
so lu
tio n
of h
ar dw
ar e
fa ilu
re s.
Fi le
s a re
im ag
ed a
nd st
or ed
to su
pp or
t r ec
ov er
y of
in fo
rm at
io n
(G ho
st fi
le s)
L/ L
Lo w
Ye s
Av ai
la bi
lit y
A fa
ilu re
in th
e da
ta c
irc ui
t c ou
ld
pr oh
ib it
sy st
em a
cc es
s Ve
nd or
m ai
nt en
an ce
a gr
ee m
en ts
a re
e st
ab lis
he d
to su
pp or
t t im
el y
re so
lu tio
n of
h ar
dw ar
e fa
ilu re
s.
Se e
In fo
rm at
io n
Te ch
no lo
gy P
ol ic
ie s a
nd P
ro ce
du re
s M an
ua l N
o.
2- 2
L/ L
Lo w
Ye s
Av ai
la bi
lit y
A ct
o f G
od —
to rn
ad o/
hu rr
ic an
e M
/H H
ig h
N o
Av ai
la bi
lit y
U pg
ra de
s i n
th e
so ftw
ar e
m ay
pr
oh ib
it ac
ce ss
G LB
A’ s m
an ag
em en
t h as
e st
ab lis
he d
w rit
te n
po lic
ie s a
nd
pr oc
ed ur
es to
e ns
ur e
th at
so ftw
ar e
is te
st ed
b ef
or e
us e
in a
pr
od uc
tio n
en vi
ro nm
en t.
Se e
G LB
A’ s I
nf or
m at
io n
Te ch
no lo
gy P
ol ic
ie s a
nd P
ro ce
du re
s M
an ua
l 3 -1
a nd
IT P
& P
M an
ua l 4
-1 8
L/ L
Lo w
Ye s
Fi gu
re 4
.2 5
(C on
ti nu
ed )
FR A
A P
w or
ks he
et 4
a cc
ep ta
bl e
ri sk
le ve
l d et
er m
in ed
.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
80 ◾ Information Security Fundamentals
◾ Gramm Leach Bliley Act (GLBA) ◾ Sarbanes Oxley Act (SOX) ◾ Information Security for Banking and Finance (ISO/TR 13569) ◾ FFEIC Examination Guidelines
For this example, we will be using a set of controls based on the IT organiza- tions and groups that support the business processes. There are 34 controls that the team can select from. It is not necessary to try to select the one perfect control at this time. Remember, one of the goals of risk assessment is to record all of the alternatives that were considered (Figure 4.26).
The team will be selecting controls for only those threats that registered as high risks (those with “high” or “medium” levels). Those threats with a risk level of “low” will be monitored for change. All possible controls should be entered into the FRAAP worksheet (Figure 4.27).
Control No. IT Group
Control Category Definition
1 Operations controls
Backup Backup requirements will be determined and communicated to Operations including a request that an electronic notification that backups were completed be sent to the application System Administrator. Operations will be requested to test the backup procedures
2 Operations controls
Recovery plan Develop, document, and test recovery procedures designed to ensure that the application and information can be recovered, using the backups created, in the event of loss
3 Operations controls
Risk assessment Conduct a risk assessment to determine the level of exposure to identified threats and identify possible safeguards or controls
4 Operations controls
Antivirus (1) Ensure LAN Administrator installs the corporate standard antiviral software on all computers. (2) Training and awareness of virus prevention techniques will be incorporated in the organization IP program
5 Operations controls
Interface dependencies
Systems that feed information will be identified and communicated to Operations to stress the effect on the functionality if these feeder applications are unavailable
6 Operations controls
Maintenance Time requirements for technical maintenance will be tracked and a request for adjustment will be communicated to management if experience warrants
7 Operations controls
Service level agreement
Acquire service level agreements to establish level of customer expectations and assurances from supporting operations
8 Operations controls
Maintenance Acquire maintenance and/or supplier agreements to facilitate the continued operational status of the application
Figure 4.26 FRAAP controls list by IT organization.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
Risk Management ◾ 81
9 Operations controls
Change management
Production migration controls such as search and remove processes to ensure data stores are clean
10 Operations controls
Business impact analysis
A formal business impact analysis will be conducted to determine the asset’s relative criticality with other enterprise assets
11 Operations controls
Backup Training for a backup to the System Administrator will be provided and duties rotated between them to ensure the adequacy of the training program
12 Operations controls
Backup A formal employee security awareness program has been implemented and is updated and presented to the employees at least on an annual basis
13 Operations controls
Recovery plan Access sourced: implement a mechanism to limit access to confidential information to specific network paths or physical locations
14 Operations controls
Risk assessment Implement user authentication mechanisms (such as firewalls, dial-in controls, secure ID) to limit access to authorized personnel
15 Application controls
Application control
Design and implement application controls (data entry edit checking, fields requiring validation, alarm indicators, password expiration capabilities, check-sums) to ensure the integrity, confidentiality, and/or availability of application information
16 Application controls
Acceptance testing
Develop testing procedures to be followed during applications development and/or during modifications to the existing application that include user participation and acceptance
17 Application controls
Training Implement user programs (user performance evaluations) designed to encourage compliance with policies and procedures in place to ensure the appropriate utilization of the application
18 Application controls
Training Application developers will provide documentation, guidance, and support to the operations staff (Operations) in implementing mechanisms to ensure that the transfer of information between applications is secure
19 Application controls
Corrective strategies
The Development Team will develop corrective strategies such as reworked processes, revised application logic, etc.
20 Security controls
Policy Develop policies and procedures to limit access and operating privileges to those with business need
21 Security controls
Training User training will include instruction and documentation on the proper use of the application. The importance of maintaining the confidentiality of user accounts, passwords, and the confidential and competitive nature of information will be stressed
Figure 4.26 (Continued) FRAAP controls list by IT organization.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
82 ◾ Information Security Fundamentals
22 Security controls
Review Implement mechanisms to monitor, report, and audit activities identified as requiring independent reviews, including periodic reviews of user IDs to ascertain and verify business need
23 Security controls
Asset classification
The asset under review will be classified using enterprise policies, standards, and procedures on asset classification
24 Security controls
Access control Mechanisms to protect the database against unauthorized access, and modifications made from outside the application, will be determined and implemented
25 Security controls
Management support
Request management support to ensure the cooperation and coordination of various business units
26 Security controls
Proprietary Processes are in place to ensure that company proprietary assets are protected and that the company is in compliance with all third-party license agreements
27 Security controls
Security awareness
Implement an access control mechanism to prevent unauthorized access to information. This mechanism will include the capability of detecting, logging, and reporting attempts to breach the security of this information
28 Security controls
Access control Implement encryption mechanisms (data, end-to-end) to prevent unauthorized access to protect the integrity and confidentiality of information
29 Security controls
Access control Adhere to a change management process designed to facilitate a structured approach to modifications of the application to ensure appropriate steps and precautions are followed. “Emergency” modifications should be included in this process
30 Security controls
Access control Control procedures are in place to ensure that appropriate system logs are reviewed by independent third parties to review system update activities
31 Security controls
Access control In consultation with Facilities Management, facilitate the implementation of physical security controls designed to protect the information, software, and hardware required of the system
32 Systems controls
Change management
Backup requirements will be determined and communicated to Operations including a request that an electronic notification that backups were completed be sent to the application System Administrator. Operations will be requested to test the backup procedures
33 Systems controls
Monitor system logs
Develop, document, and test recovery procedures designed to ensure that the application and information can be recovered, using the backups created, in the event of loss
34 Physical security
Physical security
Conduct a risk assessment to determine the level of exposure to identified threats and identify possible safeguards or controls
Figure 4.26 (Continued) FRAAP controls list by IT organization.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
Risk Management ◾ 83
Th re
at Ex
is ti
ng C
on tr
ol Se
le ct
N ew
o r E
nh an
ce d
C on
tr ol
(s )
N ew
Pr
ob ab
ili ty
/ Im
pa ct
N ew
R
is k
Le ve
l
A cc
ep ta
bl e
Le ve
l (Y
es /N
o)
C op
ie s o
f r ep
or ts
c ou
ld
be d
iv er
te d
(w rit
te n
or
el ec
tr on
ic al
ly ) t
o un
au th
or iz
ed o
r un
in te
nd ed
p er
so ns
In fo
rm at
io n
cl as
sifi ca
tio n
po lic
y in
pl
ac e.
In fo
rm at
io n
ha nd
lin g
st an
da rd
s ar
e be
in g
de ve
lo pe
d
In fo
rm at
io n
cl as
sifi ca
tio n
po lic
y in
pl
ac e.
In fo
rm at
io n
ha nd
lin g
st an
da rd
s ar
e be
in g
de ve
lo pe
d
L/ M
Lo w
Ye s
In se
cu re
e -m
ai l c
ou ld
co
nt ai
n co
nfi de
nt ia
l in
fo rm
at io
n
In fo
rm at
io n
ha nd
lin g
st an
da rd
s a re
be
in g
de ve
lo pe
d.
C on
ce rn
to b
e ad
dr es
se d
in G
LB A’
s em
pl oy
ee a
w ar
en es
s p ro
gr am
a nd
n ew
em
pl oy
ee o
rie nt
at io
n
In fo
rm at
io n
ha nd
lin g
st an
da rd
s a re
be
in g
de ve
lo pe
d.
C on
ce rn
to b
e ad
dr es
se d
in G
LB A’
s em
pl oy
ee a
w ar
en es
s p ro
gr am
a nd
ne
w e
m pl
oy ee
o rie
nt at
io n.
L/ M
Lo w
Ye s
Em pl
oy ee
is n
ot a
bl e
to
ve ri
fy th
e id
en tit
y of
a
cl ie
nt , e
xa m
pl e:
p ho
ne
m as
qu er
ad in
g
In a
dd iti
on to
e xi
st in
g co
nt ro
ls . C
on ce
rn
to b
e ad
dr es
se d
in G
LB A’
s e m
pl oy
ee
aw ar
en es
s p ro
gr am
a nd
n ew
e m
pl oy
ee
or ie
nt at
io n.
C on
tin ue
to m
on ito
r
In a
dd iti
on to
e xi
st in
g co
nt ro
ls .
C on
ce rn
to b
e ad
dr es
se d
in G
LB A’
s em
pl oy
ee a
w ar
en es
s p ro
gr am
a nd
ne
w e
m pl
oy ee
o rie
nt at
io n.
C on
tin ue
to m
on ito
r
L/ M
Lo w
Ye s
C on
fid en
tia l i
nf or
m at
io n
is le
ft in
p la
in v
ie w
o n
a de
sk
In fo
rm at
io n
ha nd
lin g
st an
da rd
s a re
be
in g
de ve
lo pe
d.
C on
ce rn
to b
e ad
dr es
se d
in G
LB A’
s em
pl oy
ee a
w ar
en es
s p ro
gr am
a nd
n ew
em
pl oy
ee o
rie nt
at io
n
In fo
rm at
io n
ha nd
lin g
st an
da rd
s a re
be
in g
de ve
lo pe
d.
C on
ce rn
to b
e ad
dr es
se d
in G
LB A’
s em
pl oy
ee a
w ar
en es
s p ro
gr am
a nd
ne
w e
m pl
oy ee
o rie
nt at
io n
L/ M
Lo w
Ye s
Fi gu
re 4
.2 7
FR A
A P
w or
ks he
et 5
s ho
w in
g ad
di ti
on al
c on
tr ol
s an
d ne
w r
is k
le ve
ls .
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
84 ◾ Information Security Fundamentals
Th re
at Ex
is ti
ng C
on tr
ol Se
le ct
N ew
o r E
nh an
ce d
C on
tr ol
(s )
N ew
Pr
ob ab
ili ty
/ Im
pa ct
N ew
R
is k
Le ve
l
A cc
ep ta
bl e
Le ve
l (Y
es /N
o)
So ci
al d
is cu
ss io
ns
ou ts
id e
th e
offi ce
c ou
ld
re su
lt in
d is
cl os
ur e
of
se ns
iti ve
in fo
rm at
io n
C od
e of
C on
du ct
/C on
fli ct
o f I
nt er
es t
Po lic
y. In
fo rm
at io
n ha
nd lin
g st
an da
rd s a
re
be in
g de
ve lo
pe d.
C on
ce rn
to b
e ad
dr es
se d
in G
LB A’
s em
pl oy
ee a
w ar
en es
s p ro
gr am
a nd
n ew
em
pl oy
ee o
rie nt
at io
n
C od
e of
C on
du ct
/C on
fli ct
o f I
nt er
es t
Po lic
y.
In fo
rm at
io n
ha nd
lin g
st an
da rd
s a re
be
in g
de ve
lo pe
d. C
on ce
rn to
b e
ad dr
es se
d in
G LB
A’ s
em pl
oy ee
a w
ar en
es s p
ro gr
am a
nd n
ew
em pl
oy ee
o rie
nt at
io n
L/ M
Lo w
Ye s
Fi le
s s to
re d
in p
er so
na l
di re
ct or
ie s m
ay n
ot b
e av
ai la
bl e
to o
th er
em
pl oy
ee s w
he n
ne ed
ed
G LB
A’ s m
an ag
em en
t h as
e st
ab lis
he d
w rit
te n
po lic
ie s a
nd p
ro ce
du re
s t o
en su
re in
fo rm
at io
n re
so ur
ce s a
re
av ai
la bl
e. E
m pl
oy ee
a w
ar en
es s p
ro gr
am
w ill
re in
fo rc
e th
e re
qu ire
m en
ts
G LB
A’ s m
an ag
em en
t h as
e st
ab lis
he d
w rit
te n
po lic
ie s a
nd p
ro ce
du re
s t o
en su
re in
fo rm
at io
n re
so ur
ce s a
re
av ai
la bl
e. E
m pl
oy ee
a w
ar en
es s
pr og
ra m
w ill
re in
fo rc
e th
e re
qu ire
m en
ts . V
er ify
c om
pl ia
nc e
L/ M
Lo w
Ye s
A ct
o f G
od —
to rn
ad o/
hu rr
ic an
e Se
ni or
m an
ag em
en t t
o ch
am pi
on
Bu sin
es s C
on tin
ui ty
P la
nn in
g pr
og ra
m .
Th e
BC P
w ill
a ls
o dr
iv e
Em er
ge nc
y Re
sp on
se P
ro ce
du re
s a nd
a n
IT D
is as
te r
Re co
ve ry
P la
n
Se ni
or m
an ag
em en
t t o
ch am
pi on
Bu
sin es
s C on
tin ui
ty P
la nn
in g
pr og
ra m
. Th
e BC
P w
ill a
ls o
dr iv
e Em
er ge
nc y
Re sp
on se
P ro
ce du
re s a
nd a
n IT
D
is as
te r R
ec ov
er y
Pl an
M /M
M ed
Ye s
FI gu
re 4
.2 7
(C on
ti nu
ed )
FR A
A P
w or
ks he
et 5
s ho
w in
g ad
di ti
on al
c on
tr ol
s an
d ne
w r
is k
le ve
ls .
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
Risk Management ◾ 85
The FRAAP team must understand that trade-offs must be made between busi- ness objectives and controls. Every control or safeguard will affect the business process in some manner as resources are expended to implement the control. Accidents, errors, and omissions generally account for more losses than deliberate acts. No control can or should be 100% effective. The ultimate goal is to achieve an acceptable level of security.
The FRAAP will not eliminate every threat. Management has the duty to deter- mine which threats it will implement controls on and which ones to accept. The FRAAP team is to assist management in making that informed business decision.
Using a Threat Identification Checklist As we briefly examined earlier in this chapter, it is possible to use a checklist to help the team through the threat identification process. Appendix A contains a sample threat checklist and a sample procedure on how to use a checklist approach to risk management.
FRAAP Session Summary At this point, the FRAAP session is complete. The team was given an overview of the risk assessment process and what will be expected of them. The owner then dis- cussed the scope of the risk assessment and a technical support person reviewed the information flow model. The facilitator then walked the team through the review business attributes (integrity, confidentiality, and availability). Once all threats were identified and recorded, the team took a few minutes to edit and consolidate the threats. Once the consolidation was complete, the team examined each threat and identified any existing controls or safeguards in place. When that process was completed, the team examined each threat for the probability of occurrence and then its effect on the business process. The team examined each threat using the existing controls as a guide. The result of this activity was to assign a relative risk level to each threat.
Once the risk levels were established, the team then used a list of possible con- trols and identified possible controls that could reduce the threat risk level to an acceptable range. The team then did a probability and impact review of those spe- cific threats to see if the new or additional controls would be effective. For each new control, the team identified either a person or group that would be responsible for the implementation of the control.
When this process is complete, the FRAAP session is complete and the meeting is adjourned. A total of four deliverables come out of the FRAAP sessions:
◾ Threats were identified ◾ Risk level established
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
86 ◾ Information Security Fundamentals
◾ Compensating controls selected ◾ Control “owner” identified
Post-FRAAP Process The FRAAP session will typically take the entire 4 hours scheduled for it. I like to take a break for lunch and then begin the process of creating the reports that after- noon. One important element that needs to be stressed is the presence of the scribe. This person (oftentimes, it is me doing both roles) will record the activities on the FRAAP as the 4-hour session is unfolding. Nowadays, I typically use my computer and a projector to show the risk action plan on a screen or wall in the FRAAP workroom. Using this, all of the threats and following decisions are recorded in real time. This allows the facilitator and scribe to begin the process of preparing the final documents.
In the movie The Big Chill, Jeff Goldblum plays a writer for People Magazine named Michael Gold. When they asked him what he wrote, he told them that it didn’t matter what he wrote, he just had to make certain that the length of the article was about the same time the average person spends in the bathroom. Here is a hint about the length of your Management Summary Report, it should be no longer than the average time an executive would spend in the restroom. That is probably where it is going to be read, so you need to be prepared.
The following Management Summary Report is put together in a format that I use. The components of the report will be consistent for the most part, but the order of things may change based on the culture and standards of your organization. The format I use is as follows:
◾ Title Page ◾ Table of Contents ◾ Attendee List ◾ Scope Statement Summary ◾ Assessment Methodology Used ◾ Summary of Assessment Findings ◾ Where to Obtain Full Documentation ◾ Conclusions
After the standards Title Page and the Table of Contents, I like to establish right away who took part in the FRAAP. This is a result of my early training in the business world in which typically the first question from management was to tell them who had been part of this process. When you read NIST Special Publication 800-30, Risk Management Guide for Information Technology Systems, they recom- mend that the Attendee List be attached in an appendix to the report. Neither style is right nor wrong, they are both correct based on the specific culture of the
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
Risk Management ◾ 87
organization. When you prepare your Management Summary Report, be certain to abide by the norms of your organization.
One more thing about the Attendee List makeup. I have no qualms about iden- tifying those individuals that had been invited but did not attend. This again is a cultural morass that must be explored and researched before attempting to include in the report.
A summary of the Risk Assessment Scope Statement is discussed next. This should be two or three paragraphs at a maximum and contain a high-level over- view of what the assessment was. Include when and where the risk assessment was conducted. If there was a compelling reason to conduct the assessment at this time, then that should be identified here. Be sure to include any assumptions and or con- straints that you feel affected the process.
A brief description of the actual risk assessment methodology needs to be part of the documentation. Spend a few brief paragraphs creating the picture of how the team reached the conclusions that it did. The full details documentation will provide the intricate details; here, an overview will be sufficient.
In the Management Summary Report, I like to take the top high-level risks and present them to management in a brief description and a visual to reinforce the discussion. This discussion will give a brief synopsis of the key high-level risks and what actions are going to be taken to reduce the risks to acceptable levels (Figure 4.28).
Risk Level No. of Similar
Threats Description of Threat Scenario
A 4 Physical intrusion
A 2 Power failure
B 10 Information handling and classification
B 4 Password weakness or sharing
B 4 People masquerading as customers
B 3 Firewall concerns
B 2 Computer viruses
B 2 Workstations left unattended
B 2 Employee training
B 27 Individual threats identified
Figure 4.28 FRAAP Management Summary Report visual.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
88 ◾ Information Security Fundamentals
Risk assessment identified five key areas of concern:
1. Restricted physical access areas should be considered throughout GLBA Action Plan: A physical security risk assessment will be conducted to deter-
mine if there is a need to create restricted access areas and/or increase physical access controls.
2. Power failure could cause corruption of information or prevent access to the system
Action Plan: Network UPS may not be adequate for a power outage out of regular business hours. Install a backup domain controller at Ualena Street and connect it to the Ualena Street UPS.
3. Information classification scheme is incomplete Action Plan: GLBA has created a draft information classification policy
that addresses five categories: public, internal use, restricted, confidential, and classified. The new policy requirements are to be disseminated to the GLBA staff and will become part of the new employee orientation and the annual employee awareness program.
4. Concern that the weakness of passwords for some information systems user accounts could allow compromise of the password and permit unauthorized access to GLBA systems and information
Action Plan: The GLBA Passwords Policy is to be modified to require strong passwords. GLBA ISD will investigate software solutions to enforce a strong password requirement.
5. Someone could impersonate a customer to corrupt or access bank records or accounts
Action Plan: Concern to be addressed in GLBA employee awareness pro- gram and new employee orientation.
Finally, there is the Conclusion section. Here, you can wrap up the overall process and tell management that the issues of risk are being addressed. Here too is the place where you can identify those risks that the owner decided to accept. This would also be the place where any constraints that affected the results of the risk assessment process should be identified.
During the risk assessment process, sometimes issues that are beyond the scope of the assessment under review rise to the surface. The Conclusion section offers a vehicle to identify and have these issues addressed.
As you complete the Management Summary Report, you will be faced with the question of whether or not the report needs to be published. This again is a cultural issue. Two corporations that I have worked for required only that the report be published.
The risk assessment report and documentation is a lot like an audit report. Typically, both sides work together to uncover deficiencies and then both work to establish a mutually acceptable solution. When putting together the report documen- tation, the facilitator works directly with the owner and project lead to determine the
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
Risk Management ◾ 89
best course of action and the timeframe for compliance. In the cases in which both sides work together, the publication of the report may not require a signature. Check with your management to ensure that the proper protocol is followed.
Complete the Action Plan When last we left the FRAAP action plan, the worksheet contained the informa- tion shown in Figures 4.29 and 4.30.
The final element that must be determined is who will be responsible for the implementation of the new or enhanced control and when the task will be com- pleted. The establishment of the timeframe for implementation will take a bit of
Business Attribute Threat Existing Controls
Probability/ Impact
Risk Level
Acceptable Level
(Yes/No)
Integrity Data stream could be intercepted
Vacant ports are disconnected
L/M Low Yes
Integrity Faulty programming could (inadvertently) modify data
Programs are tested before going into production, and change management procedures are in place. Fred’s Information Technology Policies and Procedures Manual No. 5-11, ISD Documentation; Test Plan and Test Analysis Report Standard
L/L Low Yes
Integrity Copies of reports could be diverted (written or electronically) to unauthorized or unintended persons
M/M Medium No
Figure 4.29 Post-FRAAP worksheet section 1.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
90 ◾ Information Security Fundamentals
B us
in es
s A
tt ri
bu te
Th re
at Ex
is ti
ng C
on tr
ol s
R is
k Le
ve l
N ew
o r E
nh an
ce d
C on
tr ol
Pr ob
ab ili
ty /
Im pa
ct R
is k
Le ve
l
A cc
ep ta
bl e
Le ve
l (Y
es /N
o)
In te
gr ity
D at
a st
re am
c ou
ld b
e in
te rc
ep te
d Va
ca nt
p or
ts a
re d
is co
nn ec
te d
Lo w
In te
gr ity
Fa ul
ty p
ro gr
am m
in g
co ul
d (in
ad ve
rt en
tly )
m od
ify d
at a
Pr og
ra m
s a re
te st
ed b
ef or
e go
in g
in to
p ro
du ct
io n,
a nd
c ha
ng e
m an
ag em
en t p
ro ce
du re
s a re
in
pl ac
e. F
re d’
s I nf
or m
at io
n Te
ch no
lo gy
P ol
ic ie
s a nd
P ro
ce du
re s
M an
ua l N
o. 5
-1 1,
IS D
D
oc um
en ta
tio n;
T es
t P la
n an
d Te
st
A na
ly si
s R ep
or t S
ta nd
ar d
Lo w
In te
gr ity
C op
ie s o
f r ep
or ts
c ou
ld b
e di
ve rt
ed (w
rit te
n or
el
ec tr
on ic
al ly
) t o
un au
th or
iz ed
o r
un in
te nd
ed p
er so
ns
M ed
In fo
rm at
io n
cl as
sifi ca
tio n
po lic
y in
p la
ce .
In fo
rm at
io n
ha nd
lin g
st an
da rd
s ar
e be
in g
de ve
lo pe
d
L/ M
Lo w
Ye s
Fi gu
re 4
.3 0
Po st
-F R
A A
P w
or ks
he et
s ec
ti on
2 .
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
Risk Management ◾ 91
work. This information needs to be entered into the worksheet. I typically use an Excel worksheet and it gives me the flexibility I need to enter all of the information into one document (Figure 4.31).
The risk assessment is not complete until the paperwork is done. The action plan must have the threats identified, the risk levels established, and the controls selected. Once the controls have seen selected, the action plan must identify who will implement the control and by what date. If the management owner decides to accept the risk, then this action must be identified in the action plan and in the Management Summary Report.
Like all important tasks, the proof in how well it went lies in the documenta- tion that supports the process. Remember, the results of a risk assessment will be used twice, once when a decision must be made and then again when something goes wrong. By having complete documentation, management will be able to show when the decision was made, who was involved in the process, what was discussed and what alternatives were considered.
Conclusion Capturing the threats and selecting controls is important, but the most important element in an effective risk assessment process is establishing the risk levels. Before any organization can decide what to do, it must have a clear picture of where the problems are. As you will see in the next chapter, there are any numbers of ways to modify the risk assessment process to meet the organization’s needs. The process requires that the facilitator be flexible and work with the owner to establish needs before the risk assessment process begins.
Appendix A contains a procedure that discusses an updated version of the FRAAP. The appendix includes the procedure process and a sample threat checklist that is currently being used throughout the industry.
Business Attribute Threat
New or Enhanced
Control Probability/
Impact Risk Level
Acceptable Level
(Yes/No) Responsible
Entity Compliance
Date
Integrity Copies of reports could be diverted (written or electronically) to unauthorized or unintended persons
Information classification policy in place. Information handling standards are being developed
L/M Low Yes Information Security Team
Third quarter this year
Figure 4.31 Post-FRAAP worksheet section 3.
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-25 00:12:27.
C op
yr ig
ht ©
2 01
3. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .