Risk management plan project
Managing Risk in Information Systems
Chapter 11
Turning Your Risk Assessment
into a Risk Mitigation Plan
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Page ‹#›
Managing Risk in Information Systems
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
1
Learning Objective and Key Concepts
Learning Objective
Describe concepts for implementing a risk mitigation plan.
Key Concepts
Developing an organizational risk mitigation plan
Best practices for implementing a risk mitigation plan
Ways to perform CBA on security controls
Page ‹#›
Managing Risk in Information Systems
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Creating a Risk Mitigation Plan
Complete a risk assessment
Identify costs
Perform cost-benefit analysis (CBA)
Implement plan
Page ‹#›
Managing Risk in Information Systems
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Creating a Risk Mitigation Plan
High-level review of risk assessment
Identify and evaluate relevant threats
Identify and evaluate relevant vulnerabilities
Identify and evaluate countermeasures
Develop mitigating recommendations
Page ‹#›
Managing Risk in Information Systems
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Reviewing Risk Assessment Countermeasures
In-place countermeasures
Planned countermeasures
Approved countermeasures
Overlapping countermeasures
Page ‹#›
Managing Risk in Information Systems
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Calculating Costs
Initial purchase
Facility
Installation
Training
Page ‹#›
Managing Risk in Information Systems
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Calculating Costs
Look for hidden costs
Is extra power required to eliminate a single point of failure?
Page ‹#›
Managing Risk in Information Systems
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Time to Implement
Simple configurations can be implemented in a shorter time period
Page ‹#›
Managing Risk in Information Systems
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Time to Implement
Complex configurations
More planning and time
Page ‹#›
Managing Risk in Information Systems
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Operational Impact
Tradeoff with security:
The more secure a system, the harder it is to use
The easier it is to use, the less secure it is
Firewall implicit deny philosophy
Page ‹#›
Managing Risk in Information Systems
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Prioritizing Risk Elements
Threat/vulnerability matrix
Determine likelihood
Determine impact
Prioritize countermeasures
Page ‹#›
Managing Risk in Information Systems
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Prioritizing Risk Elements
Page ‹#›
Managing Risk in Information Systems
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Performing a Cost-Benefit Analysis
Identify losses you expect before, or without, a countermeasure
Identify the losses you expect after implementing the countermeasure
Calculating projected benefits:
Loss Before Countermeasure ─ Loss After Countermeasure = Projected Benefits
Determining value of countermeasure:
Projected Benefits ─ Cost of Countermeasure = Countermeasure Value
Page ‹#›
Managing Risk in Information Systems
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
CBA Report Elements
Recommended countermeasure
Risk to be mitigated
Annual projected benefits
Initial costs
Annual or recurring costs
A comparison of the costs and benefits
Recommendation
Page ‹#›
Managing Risk in Information Systems
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Implementing a Risk Mitigation Plan
Stay within budget
Ensure costs calculated accurately
Stay on schedule
Use tools to manage project
Page ‹#›
Managing Risk in Information Systems
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Monitoring Implementation
Use project management tools
Page ‹#›
Managing Risk in Information Systems
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Implementation Challenges
Scope and cost overruns
Stay within budget and on schedule
Ineffective countermeasures
Ensure countermeasures work as expected
Page ‹#›
Managing Risk in Information Systems
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Following Up on the Risk Mitigation Plan
Ensure countermeasures are implemented
POAM
Ensure security gaps have been closed
Page ‹#›
Managing Risk in Information Systems
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Risk Management Best Practices
Stay within scope
Should not go outside the scope of the RA
Redo CBAs if new costs are identified
Ensure data is accurate
Prioritize countermeasures
Prioritize based on importance
Page ‹#›
Managing Risk in Information Systems
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Risk Management Best Practices
Include current countermeasures in analysis
When scoring countermeasures, ensure that current countermeasures are considered
Control costs and schedule
Costs should stay within the allocated budget
Follow up
Implement approved countermeasures
Ensure countermeasures mitigate the risk
Page ‹#›
Managing Risk in Information Systems
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Summary
Developing an organizational risk mitigation plan
Best practices for implementing a risk mitigation plan
Ways to perform CBA on security controls
Page ‹#›
Managing Risk in Information Systems
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
OPTIONAL SLIDES
Page ‹#›
Managing Risk in Information Systems
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
7/16/2014
22
Key Risk Mitigation Plan Roles
Chief operating officer (COO)
Chief financial officer (CFO)
IT management
Security manager
Page ‹#›
Managing Risk in Information Systems
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.