Why Care About Cyber Risk?
Modern enterprises are dependent on automation and integration. Because systems are so connected, cyber risk cannot be managed inside a single IT silo: it has to cross IT silos and be integrated with the organization's existing levels of risk management.
The problem is a knowledge gap. According to a Nasdaq report, 91% of board members at the most vulnerable companies cannot interpret a cybersecurity report. That gap between executives and IT must be bridged:
- First, identify why cyber risk should be a business priority for any executive.
- The goal is not to turn CEOs and CFOs into technologists, but to help the business adapt to the digital landscape it operates in.
- It requires effort from both management and IT to find middle ground in a relationship that has often been difficult.
Risk and value are two sides of the same coin
Risk is inherent to all enterprises. Enterprises earn their return by taking risks, so trying to eliminate every risk can remove the very risks that drive profit. Organizations must make sure that opportunities for value creation are not missed by trying to eliminate all risk. This is why guidance was needed on how to manage and capitalize on risk effectively.
Common misconception
The aim of risk management is not zero risk. A business that avoids all risk also avoids its opportunities. The aim is to take the right risks and manage them to an acceptable level.
IT Value, IT Risk and COBIT
Three ISACA frameworks work together to connect IT investment, IT risk, and IT governance:
Risk IT complements and extends COBIT and Val IT, making a more complete IT governance guidance resource.
Where IT risk fits in
Before Risk IT, available standards and frameworks were either too generic enterprise-risk-management-oriented or too IT-security-oriented. There was no comprehensive framework connecting the two, and Risk IT filled that gap.
Memory trick · Which framework does what?
- Val ITValue from IT investments
- Risk ITRisk of using IT
- COBITthe overall Control/governance model that covers both value and risk
The Cybersecurity Triad and Business-Driven Security
Everything cybersecurity protects can be described by the three properties of the cybersecurity (CIA) triad:
Business-driven security
Business-driven security means creating a security strategy that aligns with the business's needs. Security exists to support the organization, not the other way round.
Organizational and business requirements
- Focus on the mission of the organization.
- Each type of organization has differing security requirements: a hospital, a bank, and a university protect different things.
- Security must make sense and be cost effective.
Complete security solutions
Define the security behavior of the control measure. They are selected based on the risk management process.
Provide confidence that the security function is performing as expected. Assurance is a critical part of the security program.
Functional vs assurance
Functional = what the control does. Assurance = proof that it actually does it. A firewall rule is functional; an audit showing the rule works is assurance.
Cybersecurity Management and Governance
Cybersecurity management is everything an organization does to protect its information systems and computer networks from cyber attacks, intrusions, malware, and various types of data breaches.
Cybersecurity management includes two parts: governance and risk management.
Cybersecurity governance
- Cybersecurity governance is an integral part of overall corporate governance.
- It must be fully integrated into overall risk analysis and management.
- It ensures that the IT infrastructure meets all requirements, supports the strategies and objectives of the company, and includes service level agreements (SLAs) if outsourced.
Sets direction and oversight: what the organization should achieve, and holds management accountable for it.
Plans and executes the activities that achieve that direction day to day.
Security blueprints
Security blueprints provide a structure for organizing requirements and solutions, ensure that security is considered holistically, and are used to identify and design security requirements.
The Policy Environment and Policy Infrastructure
At the top of the policy hierarchy is the overarching organizational policy, also called management's security statement. It does not exist in a vacuum: it is shaped by the environment around it.
| Environmental influence | Why it shapes policy |
|---|---|
| Laws | Legal obligations the organization must obey. |
| Regulations | Industry or government rules (e.g. data protection). |
| Organizational goals | Long-term aims the policy must support. |
| Organizational objectives | Specific, measurable targets. |
| Shareholders' interests | Owners expect assets and reputation to be protected. |
Policy infrastructure
High-level policies are interpreted into functional policies
The overarching statement is too broad to act on, so it is broken down into topic-specific functional policies.
Functional policies create the foundation
Derived from the overarching policy, they are the foundation for procedures, standards, and baselines that accomplish the objectives.
Policies gain credibility through top management buy-in
Without visible executive support, policies are ignored.
Examples of functional policies
| # | Functional policy |
|---|---|
| 1 | Data classification |
| 2 | Certification and accreditation |
| 3 | Access control |
| 4 | Outsourcing |
| 5 | Remote access |
| 6 | Acceptable mail and Internet usage |
| 7 | Privacy |
| 8 | Dissemination control |
| 9 | Sharing control |
Example
An Internet usage policy is a functional policy: it applies the security statement to one topic (how employees may use the Internet) and is then enforced through standards and procedures.
Standards, Procedures, Guidelines and Baselines
Standards, procedures, baselines, and guidelines turn management objectives and goals (functional policies) into enforceable actions for employees.
| Element | Definition | Examples |
|---|---|---|
| Standards (local) | Adoption of common hardware and software mechanisms and products throughout the enterprise. | Desktop, anti-virus, firewall |
| Procedures | Step-by-step actions that must be followed to accomplish a task. | How to create a user account |
| Guidelines | Recommendations for product implementations, procurement, and planning. | ISO 17799, Common Criteria, ITIL |
| Baselines | Benchmarks that ensure a minimum level of security configuration across implementations and systems; establish consistent implementation; platform unique. | VPN setup, IDS configuration, password rules |
Memory trick · Tell them apart
- StandardsWHAT product
- ProceduresHOW, step by step
- GuidelinesSHOULD (recommended)
- BaselinesMINIMUM configuration
Only guidelines are optional recommendations.
Classic trap
ISO 17799, Common Criteria, and ITIL are listed on the slides as examples of guidelines, not standards. Password rules and IDS configuration are baselines.
Three Levels of Security Planning
| Level | Time frame | Focus | Example |
|---|---|---|---|
| Strategic | Long term | High-level, long-range organizational requirements | Overall security policy |
| Tactical | Medium term | Events that affect the whole organization | Functional plans |
| Operational | Short term | Very specific actions reacting to an incident (fighting fires at the keyboard level); directly affects how objectives are accomplished | Responding to a specific incident |
Memory trick · S-T-O
from the boardroom's long view, to organization-wide plans, down to the keyboard-level response.
Security Transcends Technology
The chapter closes with its key message: security transcends technology. Firewalls and anti-virus are not enough on their own; security depends on business alignment, governance, policy, people, and above all risk management, which the rest of the course builds on.
Link to the next chapters
Chapter 2 defines risk precisely, Chapter 3 studies threats and vulnerabilities, and Chapters 4–6 turn them into a full risk assessment.
Exam Tips & Tricks
91% statistic
91% of board members at the most vulnerable companies cannot interpret a cybersecurity report (Nasdaq). It shows the executive–IT knowledge gap.
Risk and value
Risk and value are two sides of the same coin. Don't eliminate all risk: you would also eliminate value creation.
V-R-C frameworks
Val IT = value from IT investments; Risk IT = end-to-end view of IT risk; COBIT = IT governance model. Risk IT complements and extends COBIT and Val IT.
Management = governance + RM
Cybersecurity management includes governance and risk management. Governance is an integral part of corporate governance.
Functional vs assurance
Functional requirements define security behavior (chosen by risk management); assurance requirements give confidence it works.
Policy order
Security statement → functional policies → standards, procedures, baselines, guidelines. Policies gain credibility through top management buy-in.
Guidelines vs baselines
Guidelines are recommendations (ISO 17799, Common Criteria, ITIL). Baselines are minimum configurations (VPN setup, IDS config, password rules).
Planning levels
Strategic = long term (security policy); tactical = medium term (functional plans); operational = short term, keyboard-level incident response.
Flashcards — Test Yourself
Say the answer out loud, then flip the card to check. Shuffle the deck to test yourself in a new order.
Quick Reference — Everything at a Glance
| Topic | Key Point |
|---|---|
| Why care about cyber risk | Enterprises depend on automation/integration; risk must cross IT silos and integrate with existing risk management. |
| Board knowledge gap | 91% of board members at the most vulnerable companies can't interpret a cybersecurity report. |
| Risk vs value | Two sides of the same coin; enterprises achieve return by taking risks. |
| Val IT | Governance framework to create business value from IT investments. |
| Risk IT | End-to-end, comprehensive view of all IT-related risks; extends COBIT and Val IT. |
| COBIT | IT governance model for delivering value from IT and managing IT risks. |
| CIA triad | Confidentiality, integrity, availability. |
| Business-driven security | Security strategy aligned with business needs; mission-focused and cost effective. |
| Functional requirements | Define security behavior of a control; selected by risk management. |
| Assurance requirements | Confidence that the security function performs as expected. |
| Cybersecurity management | Protecting systems and networks from attacks, intrusions, malware, breaches; includes governance + risk management. |
| Cybersecurity governance | Part of corporate governance; IT meets requirements, supports strategy, includes SLAs if outsourced. |
| Security blueprints | Structure for organizing requirements and solutions; holistic security design. |
| Overarching policy | Management's security statement; shaped by laws, regulations, goals, objectives, shareholders. |
| Functional policies | Data classification, C&A, access control, outsourcing, remote access, mail/Internet use, privacy, dissemination, sharing. |
| Standards / procedures | Common mechanisms and products / step-by-step actions. |
| Guidelines / baselines | Recommendations (ISO 17799, CC, ITIL) / minimum security configuration (VPN, IDS, passwords). |
| Planning levels | Strategic (long), tactical (medium), operational (short). |