Risk management plan project

profilerkollu
risk_ppt05_ch11.pptx

Managing Risk in Information Systems

Chapter 11

Turning Your Risk Assessment

into a Risk Mitigation Plan

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Page ‹#›

Managing Risk in Information Systems

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

1

Learning Objective and Key Concepts

Learning Objective

Describe concepts for implementing a risk mitigation plan.

Key Concepts

Developing an organizational risk mitigation plan

Best practices for implementing a risk mitigation plan

Ways to perform CBA on security controls

Page ‹#›

Managing Risk in Information Systems

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Creating a Risk Mitigation Plan

Complete a risk assessment

Identify costs

Perform cost-benefit analysis (CBA)

Implement plan

Page ‹#›

Managing Risk in Information Systems

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Creating a Risk Mitigation Plan

High-level review of risk assessment

Identify and evaluate relevant threats

Identify and evaluate relevant vulnerabilities

Identify and evaluate countermeasures

Develop mitigating recommendations

Page ‹#›

Managing Risk in Information Systems

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Reviewing Risk Assessment Countermeasures

In-place countermeasures

Planned countermeasures

Approved countermeasures

Overlapping countermeasures

Page ‹#›

Managing Risk in Information Systems

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Calculating Costs

Initial purchase

Facility

Installation

Training

Page ‹#›

Managing Risk in Information Systems

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Calculating Costs

Look for hidden costs

Is extra power required to eliminate a single point of failure?

Page ‹#›

Managing Risk in Information Systems

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Time to Implement

Simple configurations can be implemented in a shorter time period

Page ‹#›

Managing Risk in Information Systems

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Time to Implement

Complex configurations

More planning and time

Page ‹#›

Managing Risk in Information Systems

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Operational Impact

Tradeoff with security:

The more secure a system, the harder it is to use

The easier it is to use, the less secure it is

Firewall implicit deny philosophy

Page ‹#›

Managing Risk in Information Systems

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Prioritizing Risk Elements

Threat/vulnerability matrix

Determine likelihood

Determine impact

Prioritize countermeasures

Page ‹#›

Managing Risk in Information Systems

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Prioritizing Risk Elements

Page ‹#›

Managing Risk in Information Systems

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Performing a Cost-Benefit Analysis

Identify losses you expect before, or without, a countermeasure

Identify the losses you expect after implementing the countermeasure

Calculating projected benefits:

Loss Before Countermeasure ─ Loss After Countermeasure = Projected Benefits

Determining value of countermeasure:

Projected Benefits ─ Cost of Countermeasure = Countermeasure Value

Page ‹#›

Managing Risk in Information Systems

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

CBA Report Elements

Recommended countermeasure

Risk to be mitigated

Annual projected benefits

Initial costs

Annual or recurring costs

A comparison of the costs and benefits

Recommendation

Page ‹#›

Managing Risk in Information Systems

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Implementing a Risk Mitigation Plan

Stay within budget

Ensure costs calculated accurately

Stay on schedule

Use tools to manage project

Page ‹#›

Managing Risk in Information Systems

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Monitoring Implementation

Use project management tools

Page ‹#›

Managing Risk in Information Systems

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Implementation Challenges

Scope and cost overruns

Stay within budget and on schedule

Ineffective countermeasures

Ensure countermeasures work as expected

Page ‹#›

Managing Risk in Information Systems

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Following Up on the Risk Mitigation Plan

Ensure countermeasures are implemented

POAM

Ensure security gaps have been closed

Page ‹#›

Managing Risk in Information Systems

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Risk Management Best Practices

Stay within scope

Should not go outside the scope of the RA

Redo CBAs if new costs are identified

Ensure data is accurate

Prioritize countermeasures

Prioritize based on importance

Page ‹#›

Managing Risk in Information Systems

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Risk Management Best Practices

Include current countermeasures in analysis

When scoring countermeasures, ensure that current countermeasures are considered

Control costs and schedule

Costs should stay within the allocated budget

Follow up

Implement approved countermeasures

Ensure countermeasures mitigate the risk

Page ‹#›

Managing Risk in Information Systems

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Summary

Developing an organizational risk mitigation plan

Best practices for implementing a risk mitigation plan

Ways to perform CBA on security controls

Page ‹#›

Managing Risk in Information Systems

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

OPTIONAL SLIDES

Page ‹#›

Managing Risk in Information Systems

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

7/16/2014

22

Key Risk Mitigation Plan Roles

Chief operating officer (COO)

Chief financial officer (CFO)

IT management

Security manager

Page ‹#›

Managing Risk in Information Systems

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.