go online and search for job openings for security professionals
26/09/2018
1
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Managing Risk in Information Systems
Lesson 2
Risk Management Planning
2 .
CSCI-618: Information Security Risk Management and Legal
Issues
Page 3Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Developing a Risk Management Plan
26/09/2018
2
Page 4Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Objectives of a Risk Management Plan
A list of threats
A list of vulnerabilities
Costs associated with risks
A list of recommendations to reduce the risks
Costs associated with recommendations
A cost-benefit analysis
One or more reports
Page 5Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Scope of Plan Dimensions
Extent the plan will be organized
Level of implementation
Range of view and outlook
Degree of application and operation
Measurement of effectiveness
Page 6Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Assignment of Responsibilities
Align resources
Assign responsibilities
Evaluate relationships
26/09/2018
3
Page 7Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Describing Procedures and Schedules for Accomplishment
Include a recommended solution for any threat or vulnerability, with a goal of mitigating the associated risk.
The solution will often include multiple steps.
Page 8Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Describing Procedures and Schedules for Accomplishment
Describe each step in detail.
Include a timeline for completion of each step.
Remember: • Management is responsible for choosing the controls
to implement.
• Management is responsible for residual risk.
Page 9Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Affinity Diagram
26/09/2018
4
Page 10Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Reporting Requirements
Present recommendations
Document management response to recommendations
Document and track implementation of accepted recommendations
Create plan of action and milestones (POAM)
Page 11Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Reporting Requirements (Cont.)
Report should include:
• Findings
• Recommendation cost and time frame
• Cost-benefit analysis
Reports are often summarized in risk statements
• Use risk statements to communicate a risk and the resulting impact
Page 12Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Using a Cause and Criteria Diagram
Evaluating a Web site
26/09/2018
5
Page 13Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Using a Cause and Criteria Diagram
Evaluating HIPAA compliance
Page 14Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Plan of Action and Milestones (POAM)
A document used to track progress
Used to assign responsibility and to allow management follow-up
Is a living document
Page 15Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Milestone Plan Chart
Only lists major milestones
26/09/2018
6
Page 16Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Gantt Chart
Shows a full project schedule
Page 17Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Critical Path Chart
Identifies critical tasks to be managed
Page 18Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Risk Management Functions
Senior management
IT management
System and information owners
Functional management
Information security (IS) management
Security awareness trainers
26/09/2018
7
Page 19Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Summary
Risk, threats, vulnerabilities, and exploits
Public resources for risk management
Use of threat/vulnerability pairs in managing risk
Fundamental components of a risk management plan
Objectives of a risk management plan
Objectives and scope of a risk management plan
Importance of assigning responsibilities
Significance of planning, scheduling, and documentation
Page 20Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Chapter 5: “Defining Risk Assessment Approaches”
Page 21Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Learning Objectives
Describe techniques for identifying and analyzing relevant threats, vulnerabilities, and exploits.
Describe process of performing a risk assessment.
26/09/2018
8
Page 22Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Key Concepts
Definition of a risk assessment
Components of risk assessments
Qualitative vs. quantitative risk assessment
When to perform risk assessments
Steps involved in a risk assessment
Identifying assets, threats, vulnerabilities
Evaluating controls and countermeasures
Page 23Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
What Is Risk Assessment? Key step in a risk management process
Determination of quantitative or qualitative value of risk
Conducted for concrete situation and recognized threat
Used to help identify which safeguards (controls) to implement
Required for evaluating risk or control
Often conducted after implementation of a control
Page 24Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Why Is Risk Assessment Important?
Identifies which systems/assets to protect Gives insight into which controls
provide the most value
26/09/2018
9
Page 25Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
When Should a Risk Assessment Be Conducted?
When evaluating risk
When evaluating a control
Periodically after a control has been implemented
Page 26Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Critical Components of Risk Assessment
Identify scope of assessment
Identify critical areas
Identify team
Page 27Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Identify Potential Scope for Web Server RA
Web server
Database server
Firewalls
DMZ
26/09/2018
10
Page 28Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Quantitative and Qualitative RAs
Quantitative Risk Assessments • Calculates absolute financial values, losses, and costs
Qualitative Risk Assessments • Calculates relative values, losses, and costs
Page 29Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Quantitative Risk Assessment
Uses numbers such as dollar values
Results can help you:
• Identify the priority of risks
• Determine the effectiveness of controls
Page 30Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Quantitative Risk Assessment Key Terms
Single loss expectancy (SLE)
Annual rate of occurrence (ARO)
Annual loss expectancy (ALE)
Safeguard value
26/09/2018
11
Page 31Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Quantitative Risk Assessment Benefits Becomes a simple math problem
Provides a cost-benefit analysis (CBA)
• Accurate values for SLE, ARO, and safeguard value let’s you calculate CBA
Management often familiar with quantitative assessment terminology; easy to grasp details of the assessment and its recommendations
Formulas use verifiable and objective measurements
Page 32Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Quantitative Risk Assessment Limitations
Accurate data isn’t always available
• Especially true when identifying ARO reductions
Ensuring that people use the control as expected
• May need to take additional steps, such as training, to ensure users are aware of the importance of the control
Page 33Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Qualitative Risk Assessment
Subjective
Probability
• The likelihood that a threat will exploit a vulnerability
Impact
• The negative result if a risk occurs
26/09/2018
12
Page 34Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Using a Risk Matrix
Matching probability and impact
Page 35Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Qualitative Risk Assessment Benefits
Uses the opinions of experts
Is easy to complete
Uses words that are easy to express and understand
Page 36Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Qualitative Risk Assessment Limitations
Subjective
Based on expertise of the experts
• Value of the assessment is only as valuable as the expertise of the experts
No CBA
No real standards
26/09/2018
13
Page 37Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Comparing Assessment Methods
Quantitative
Objective
Monetary values
Historical data
Key terms: • SLE, ARO, ALE
Qualitative
Subjective
Word values
Expert opinions
Key terms: • Probability
and impact
Page 38Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Risk Assessment Challenges
Using static process to evaluate a moving target
Availability
Data consistency
Estimating impact effects
Providing results that support resource allocation and risk acceptance
Page 39Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Best Practices for Risk Assessment
Start with clear goals and a defined scope.
Enlist senior management support.
Build a strong RA team.
Repeat the RA regularly.
Define a methodology to use.
Provide a report of clear risks and clear recommendations.