Controlling Risk
Running Head: ASSESSING RISK 1
ASSESSING RISK 5
Assessing Risk
Brian Dennison
CTU
IT454
John Denson
12/18/2015
Assessing Risk
In organizations, risk assessment is considered as the first step in the risk management. The risk assessment is useful for the organizations in determining the potential threat as well as the risk associated with a particular information technology system. According to Alexander, Finch, Sutton, & Taylor, (2013) risk occurs as a function of the likelihood of a certain source of a threat that exercises a given vulnerability and results in an impact of the adverse occurrence in the particular organization.
Methodology for Conducting a Risk Assessment
In an organization, the risk assessment methodology has nine steps. The first step involves system characterization whereby there is the establishment of the extent of the effort used in the risk assessment. The characterization provides information concerning the hardware, software among others that are of importance in defining risk and in addition to that delineates the operational accreditation. The second step identifies the risk such as the history of any attack and makes a threat statement. The vulnerability is then identified together with the list of the possible vulnerabilities and any reports given from any previous attack (Anton, & United States 2003).
The fourth step involves the control analysis whereby there is a list of the planned controls. The likelihood is then determined and rated, and it’s followed by the analyzing the impact. The impact could be such as leading to the loss of integrity or confidentiality. The following step involves determining the risk and the associated levels of the risk and the control recommendation. The final step of the methodology involves documenting the results as well as the report of the risk assessment.
Methods for Dealing with Identified Risk
The main reason for assessing any risk in an organization is so that the management can get a clear picture of the areas to direct the organization's resources. In dealing with the identified risk, there exist at least four strategies. They include mitigating the risk, accepting the risk, transferring the risk or even avoiding the risk.
Risk mitigation is the commonest strategy used for risk management. The mitigation involves the fixing of the flaw or risk and makes provision for some compensation control to promote the reduction of the likelihood or the associated impact with the given flaw. In transferring the risk, another party is allowed to accept the given risk on behalf your behalf. The strategy is uncommon in the information technology system but very common in personal lives of individuals (Vellani, 2007).
The acceptance of the assessed risk involves allowing the given system to continue operating with a given known risk. In most instances, the risks considered low are accepted. The risks too with high mitigation cost are in addition accepted. The fourth method of dealing with identified risk is the avoidance. Avoidance deals with removing an aspect considered vulnerable of the system and sometimes the whole system (Vellani, 2007). Therefore, it is essential to identify the best method to deal with the given identified risk.
In assessing risks, vulnerabilities refer to either a flaw or a certain weakness in the system implementation, its security procedures or in the internal controls that can be intentionally or accidentally exercised. On the other hand, threats refer to the potential for an exercise of a given vulnerability. The threats must be accompanied by the source of the threat for them to be rated as dangerous. As such in the assessment of risk, it is essential to note that every threat is to have a different likelihood that may affect the management of the risk. Exploit refers to an attack on the system that can take advantage of a given vulnerability that may be offered to intruders by the system. In the assessment of risk, these aspects become of importance in protecting the system (Anton, & United States 2003).
References
Alexander, D., Finch, A., Sutton, D., & Taylor, A. (2013). Information security management principles. Swindon, U.K: BCS Learning & Development Ltd.
Antón, P. S., & United States. (2003). Finding and fixing vulnerabilities in information systems: The vulnerability assessment & mitigation methodology. Santa Monica, CA: Rand.
Vellani, K. H. (2007). Strategic security management: A risk assessment guide for decision makers. Amsterdam: Butterworth-Heinemann.