go online and search for job openings for security professionals

profileakshar
Lecture3_Handout.pdf

26/09/2018

1

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Managing Risk in Information Systems

Lesson 2

Risk Management Planning

2 .

CSCI-618: Information Security Risk Management and Legal

Issues

Page 3Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Developing a Risk Management Plan

26/09/2018

2

Page 4Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Objectives of a Risk Management Plan

 A list of threats

 A list of vulnerabilities

 Costs associated with risks

 A list of recommendations to reduce the risks

 Costs associated with recommendations

 A cost-benefit analysis

 One or more reports

Page 5Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Scope of Plan Dimensions

 Extent the plan will be organized

 Level of implementation

 Range of view and outlook

 Degree of application and operation

 Measurement of effectiveness

Page 6Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Assignment of Responsibilities

Align resources

Assign responsibilities

Evaluate relationships

26/09/2018

3

Page 7Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Describing Procedures and Schedules for Accomplishment

 Include a recommended solution for any threat or vulnerability, with a goal of mitigating the associated risk.

 The solution will often include multiple steps.

Page 8Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Describing Procedures and Schedules for Accomplishment

 Describe each step in detail.

 Include a timeline for completion of each step.

 Remember: • Management is responsible for choosing the controls

to implement.

• Management is responsible for residual risk.

Page 9Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Affinity Diagram

26/09/2018

4

Page 10Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Reporting Requirements

 Present recommendations

 Document management response to recommendations

 Document and track implementation of accepted recommendations

 Create plan of action and milestones (POAM)

Page 11Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Reporting Requirements (Cont.)

 Report should include:

• Findings

• Recommendation cost and time frame

• Cost-benefit analysis

 Reports are often summarized in risk statements

• Use risk statements to communicate a risk and the resulting impact

Page 12Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Using a Cause and Criteria Diagram

 Evaluating a Web site

26/09/2018

5

Page 13Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Using a Cause and Criteria Diagram

 Evaluating HIPAA compliance

Page 14Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Plan of Action and Milestones (POAM)

 A document used to track progress

 Used to assign responsibility and to allow management follow-up

 Is a living document

Page 15Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Milestone Plan Chart

 Only lists major milestones

26/09/2018

6

Page 16Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Gantt Chart

 Shows a full project schedule

Page 17Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Critical Path Chart

 Identifies critical tasks to be managed

Page 18Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Risk Management Functions

 Senior management

 IT management

 System and information owners

 Functional management

 Information security (IS) management

 Security awareness trainers

26/09/2018

7

Page 19Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Summary

 Risk, threats, vulnerabilities, and exploits

 Public resources for risk management

 Use of threat/vulnerability pairs in managing risk

 Fundamental components of a risk management plan

 Objectives of a risk management plan

 Objectives and scope of a risk management plan

 Importance of assigning responsibilities

 Significance of planning, scheduling, and documentation

Page 20Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Chapter 5: “Defining Risk Assessment Approaches”

Page 21Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Learning Objectives

 Describe techniques for identifying and analyzing relevant threats, vulnerabilities, and exploits.

 Describe process of performing a risk assessment.

26/09/2018

8

Page 22Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Key Concepts

 Definition of a risk assessment

 Components of risk assessments

 Qualitative vs. quantitative risk assessment

 When to perform risk assessments

 Steps involved in a risk assessment

 Identifying assets, threats, vulnerabilities

 Evaluating controls and countermeasures

Page 23Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

What Is Risk Assessment?  Key step in a risk management process

 Determination of quantitative or qualitative value of risk

 Conducted for concrete situation and recognized threat

 Used to help identify which safeguards (controls) to implement

 Required for evaluating risk or control

 Often conducted after implementation of a control

Page 24Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Why Is Risk Assessment Important?

 Identifies which systems/assets to protect  Gives insight into which controls

provide the most value

26/09/2018

9

Page 25Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

When Should a Risk Assessment Be Conducted?

When evaluating risk

When evaluating a control

Periodically after a control has been implemented

Page 26Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Critical Components of Risk Assessment

Identify scope of assessment

Identify critical areas

Identify team

Page 27Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Identify Potential Scope for Web Server RA

Web server

Database server

Firewalls

DMZ

26/09/2018

10

Page 28Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Quantitative and Qualitative RAs

Quantitative Risk Assessments • Calculates absolute financial values, losses, and costs

Qualitative Risk Assessments • Calculates relative values, losses, and costs

Page 29Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Quantitative Risk Assessment

 Uses numbers such as dollar values

 Results can help you:

• Identify the priority of risks

• Determine the effectiveness of controls

Page 30Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Quantitative Risk Assessment Key Terms

Single loss expectancy (SLE)

Annual rate of occurrence (ARO)

Annual loss expectancy (ALE)

Safeguard value

26/09/2018

11

Page 31Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Quantitative Risk Assessment Benefits  Becomes a simple math problem

 Provides a cost-benefit analysis (CBA)

• Accurate values for SLE, ARO, and safeguard value let’s you calculate CBA

 Management often familiar with quantitative assessment terminology; easy to grasp details of the assessment and its recommendations

 Formulas use verifiable and objective measurements

Page 32Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Quantitative Risk Assessment Limitations

 Accurate data isn’t always available

• Especially true when identifying ARO reductions

 Ensuring that people use the control as expected

• May need to take additional steps, such as training, to ensure users are aware of the importance of the control

Page 33Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Qualitative Risk Assessment

 Subjective

 Probability

• The likelihood that a threat will exploit a vulnerability

 Impact

• The negative result if a risk occurs

26/09/2018

12

Page 34Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Using a Risk Matrix

 Matching probability and impact

Page 35Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Qualitative Risk Assessment Benefits

 Uses the opinions of experts

 Is easy to complete

 Uses words that are easy to express and understand

Page 36Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Qualitative Risk Assessment Limitations

 Subjective

 Based on expertise of the experts

• Value of the assessment is only as valuable as the expertise of the experts

 No CBA

 No real standards

26/09/2018

13

Page 37Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Comparing Assessment Methods

Quantitative

Objective

Monetary values

Historical data

Key terms: • SLE, ARO, ALE

Qualitative

Subjective

Word values

Expert opinions

Key terms: • Probability

and impact

Page 38Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Risk Assessment Challenges

 Using static process to evaluate a moving target

 Availability

 Data consistency

 Estimating impact effects

 Providing results that support resource allocation and risk acceptance

Page 39Managing Risk in Information Systems © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Best Practices for Risk Assessment

 Start with clear goals and a defined scope.

 Enlist senior management support.

 Build a strong RA team.

 Repeat the RA regularly.

 Define a methodology to use.

 Provide a report of clear risks and clear recommendations.