CYS403 Chapter 2
CYS403 · Chapter 2

Measuring the Unknown:
Risk Management Fundamentals

What risk really is, how to identify and rank it, how to put a price on it with SLE and ALE, and how to choose the right response and controls.

Risk TermsRisk RegisterSLE · ARO · ALEQualitative MatrixMitigation OptionsControl Types
scroll ↓
01 / Definition

What Is Risk?

Risk is the possibility of losing something of value. Put another way, risk is the probability that a threat will turn into a disaster.

A vulnerability (weakness) and a hazard are not dangerous when taken separately. But when they come together, they become a risk: the probability that a disaster will happen.

The NIST SP 800-30 definition

Memorize this definition

Risk is a function of the likelihood of a given threat-source's exercising a particular potential vulnerability, and the resulting impact of that adverse event on the organization's assets. (NIST SP 800-30)

FormulaRisk = Probability (threat, vulnerability, impact)

Slide 7Risk lives where threats meet the vulnerabilities in your assets.
02 / Terminology

Key Terms and Concepts

Asset
Something that is valued by the organization to accomplish its goals and objectives.
Threat
Any potential danger to information or an information system.
Attack
Any actual danger to information or an information system.
Threat agent
Anything that has the potential of causing a threat.
Attacker
Anything that is the actual cause of an attack.
Vulnerability
Any weakness that could be exploited. Vulnerabilities exist in every IT system, product, and application.
Exposure
An opportunity for a threat to cause loss.
Countermeasures and safeguards
Measures and actions taken to protect systems.
Residual risk
The amount of risk remaining after countermeasures and safeguards are applied.

Memory trick · Potential vs actual

  • ThreatAttack
  • Threat agentAttacker

the first word in each pair is potential, the second is actual.

Examples of threats

Unauthorized access Human errors
Hardware failure Neighboring hazards
Utility failure Tampering
Loss of key personnel Dissatisfied employees
Slide 14A threat agent gives rise to a threat that exploits a vulnerability, creating risk to an asset that safeguards counter.
Slide 15Risk management concept flow: owners, safeguards, vulnerabilities, threat agents, threats, risk and assets.
03 / Risk Factors

Risk Factors and Residual Risk

Risk exists where three factors overlap: threats, assets, and vulnerabilities. Remove any one of them and there is no risk.

Threats
exploit Vulnerabilities
in Assets = RISK

Once safeguards are applied, the overlap shrinks but rarely disappears. What is left is the residual risk, which should be reduced to an acceptable level.

Slide 11Controls filter risk down; whatever drips through is residual risk.

Residual risk is never zero

Controls reduce risk; they do not eliminate it. Management must decide what level of residual risk is acceptable.

04 / Overview

Risk Management: Identify, Assess, Control

Organizations must design and create safe environments in which business processes and procedures can function. Risk management is the process of identifying and controlling the risks facing an organization.

Risk identification
Examining an organization's current information technology security situation.
Risk assessment
Evaluating the risks to find a suitable control.
Risk control
Applying controls to reduce risks to the organization's data and information systems.
Know yourself

Identify, examine, and understand the information and systems currently in place.

Know the enemy

Identify, examine, and understand the threats facing the organization.

Managing risk is the responsibility of each community of interest within the organization.

Purpose of risk management

Risk management identifies and reduces risks (threats, vulnerabilities, and impact on asset value). Mitigating controls (safeguards and countermeasures) reduce risk, and residual risk should be set to an acceptable level.

Slide 21The risk equation, and the activities under assessment, mitigation and evaluation.
05 / Components

The Three Components of Risk Management

Risk assessment Risk mitigation Evaluation and assurance
Identification of risks Risk avoidance Ongoing risk assessment
Evaluation of risks Risk mitigation Periodic evaluation
Risk impact Risk acceptance Regulatory compliance
Recommendation of risk-reducing measures Risk transference
Evaluation of risks
Slide 20The components of risk management: identification, assessment and control.

Read the table top-down

Assessment finds and rates risks; mitigation decides what to do about them; evaluation and assurance keep checking that the decisions still hold.

06 / Process

The Five Risk Management Steps

1

Identify the risk

Uncover, recognize, and describe risks that might affect the system or its outcomes. Several techniques exist. You start to prepare your Risk Register.

2

Analyze the risk

Determine the likelihood and impact of each risk and understand its potential to affect business objectives. This is also input to the Risk Register.

3

Evaluate and rank the risk

Determine the risk score = combination of likelihood and impact. Decide whether the risk is acceptable or serious enough to treat. Rankings go into the Risk Register.

4

Risk control (risk response planning)

Plan to treat the highest-ranked risks to reach acceptable levels: mitigation strategies, preventive plans, and contingency plans (DRP, BCP, IRP). Treatment measures are added to the Risk Register.

5

Monitor and review the risk

Use the Risk Register to monitor, track, and review risks.

Memory trick · I-A-E-C-M

I Always Evaluate Carefully, Monthly

Identify, Analyze, Evaluate/rank, Control, Monitor.

The risk register

The Risk Register is started in step 1 and updated in every later step. Step 5 is where you use it to monitor and review.

Automated tools for risk management

Slide 46The risk management process: identify, assess, control, review.
Slide 27A sample risk register.
07 / Quantitative

Quantitative Risk Analysis

There are two types of risk analysis: quantitative and qualitative. Both provide unique capabilities, and both are often required to get a full picture.

Quantitative analysis steps

1

Determine asset value (AV)

What the asset is worth to the organization.

2

Estimate potential losses

The exposure factor (EF): the percentage of value lost in one incident.

3

Conduct a threat analysis

Probability and impact: how often the threat happens (ARO).

4

Determine annual loss expectancy (ALE)

The expected yearly loss.

FormulaSLE = Asset Value × Exposure FactorALE = SLE × AROValue of control = ALE(before) − ALE(after) − ACS

Worked example from the slides

A server is worth USD 10,000. If attacked by threat X, EF = 70%. The threat is expected 20 times a year (ARO, a subjective expert estimate).

Quantity Calculation Result
SLE 10,000 × 70% 7,000
ALE 7,000 × 20 140,000
Value of control 140,000 (ALE before) − 50,000 (ALE after) − 30,000 (annual cost of control) 60,000
Slide 32Worked quantitative example: asset value and exposure factor give SLE, ARO gives ALE, then the control's cost/benefit.

Decision rule

If the value of the control is positive, the control saves more than it costs, so it is worth buying.

08 / Qualitative

Qualitative Risk Analysis

Critical factors

Risk levels: the AS/NZS 4360 matrix

Likelihood ↓ / Consequence → 1 Insignificant 2 Minor 3 Moderate 4 Major 5 Catastrophic
A (almost certain) H H E E E
B (likely) M H H E E
C (possible) L M H E E
D (unlikely) L L M H E
E (rare) L L M H H
Level Meaning
E Extreme Immediate action required to mitigate the risk, or decide not to proceed.
H High Action should be taken to compensate for the risk.
M Moderate Action should be taken to monitor the risk.
L Low Routine acceptance of the risk.

Five top qualitative RA techniques

Quantitative

Objective, uses money values and formulas, needs lots of data and time, results are verifiable.

Qualitative

Subjective, uses ranks/words from expert judgment, scenario-based, faster, easier to perform.

Slide 38Techniques used in qualitative and quantitative risk analysis.
Slide 36AS/NZS 4360 risk levels: likelihood against consequence.
Slide 39Quantitative versus qualitative risk analysis compared.
09 / Response

Risk Mitigation Options

Risk acceptance
Accept the risk if the cost of the control is higher than the expected loss.
Risk reduction
Implement a countermeasure to reduce the risk impact.
Risk transference
Outsource or transfer to a third party (e.g. insurance).
Risk avoidance
Stop the activities that are causing the risk.

Memory trick · A-R-T-A

AcceptReduceTransferAvoid

Ask: is it cheaper to live with it, fix it, pass it on, or stop doing it?

The right amount of security

Use cost/benefit analysis (CBA): balance the cost to protect against the asset value. Security is a balancing act. Before a CBA you must understand:

10 / Selection

Countermeasure Selection Principles

Principle Meaning
Cost/benefit analysis Cost must be justified by the potential loss.
Accountability Someone is clearly responsible for the safeguard.
Absence of design secrecy Security does not rely on a secret design: safeguards are changeable, interoperable, and trusted (Common Criteria evaluation).
Audit capability The safeguard can be tested and audited.
Vendor trustworthiness The supplier is reliable.
Independence of control and subject Segregation of duties: those controlled don't control the safeguard.
Universal application Applies to everyone equally.
Compartmentalization and defense in depth Layered protection limits damage.
Isolation, economy, least common mechanism Isolate critical parts, keep it simple, minimize shared mechanisms.
Acceptance and tolerance by personnel Users must accept it or they will bypass it.
Minimum human intervention Less manual effort, fewer errors.
Sustainability Can be maintained over time.
Reaction and recovery Supports responding to and recovering from incidents.
Override and fail-safe defaults Fails into a secure state; overrides are controlled.
Residuals and reset Clears residual data and returns to a known state.
11 / Controls

Types of Security Controls

Control type Purpose Example
Directive (administrative) Advise employees of the behavior expected of them when using information systems. Acceptable use policy
Preventive Physical, administrative, and technical measures to prevent actions violating policy or increasing risk. Locks, firewalls, access control
Detective Practices, processes, and tools that identify and possibly react to security violations. IDS, audit logs, CCTV
Corrective React to a detected incident to reduce or eliminate the chance of the unwanted event recurring. Patching, removing malware
Recovery Restore the system or operation to a normal state after integrity or availability is compromised. Restoring backups, DRP
Directive
Preventive
Detective
Corrective
Recovery

Memory trick · Before, during, after

Do Please Detect, Correct, Recover

tell people (Directive), stop it (Preventive), find it (Detective), fix it (Corrective), get back to normal (Recovery).

12 / Exam Prep

Exam Tips & Tricks

NIST SP 800-30 risk

Risk is a function of the likelihood of a threat-source exercising a vulnerability and the resulting impact on assets.

Threat vs attack

Threat = potential danger; attack = actual danger. Threat agent = potential cause; attacker = actual cause.

Residual risk

The risk remaining after safeguards are applied. Set it to an acceptable level; it is never zero.

Five steps

Identify → Analyze → Evaluate and rank → Control (DRP, BCP, IRP) → Monitor and review. The Risk Register starts at step 1.

Formulas

SLE = AV × EF. ALE = SLE × ARO. Control value = ALE before − ALE after − annual cost of control.

Slide example

Server USD 10,000, EF 70% → SLE 7,000; ARO 20 → ALE 140,000; control value = 140,000 − 50,000 − 30,000 = 60,000.

Matrix levels

E = immediate action or don't proceed; H = compensate; M = monitor; L = routine acceptance.

A-R-T-A

Accept (control costs more than loss), Reduce (countermeasure), Transfer (third party), Avoid (stop the activity).

13 / Self-Test

Flashcards — Test Yourself

Say the answer out loud, then flip the card to check. Shuffle the deck to test yourself in a new order.

14 / Cheat Sheet

Quick Reference — Everything at a Glance

Topic Key Point
Risk Possibility of losing something of value; probability a threat becomes a disaster.
Risk (NIST SP 800-30) Likelihood of a threat-source exercising a vulnerability × resulting impact on assets.
Asset Something valued by the organization to accomplish its goals.
Threat / attack Potential danger / actual danger.
Threat agent / attacker Potential cause of a threat / actual cause of an attack.
Vulnerability Any weakness that could be exploited.
Exposure An opportunity for a threat to cause loss.
Residual risk Risk remaining after countermeasures are applied.
Risk identification / assessment / control Examine current security / evaluate risks to find controls / apply controls.
Risk management steps Identify, analyze, evaluate and rank, control, monitor and review.
Risk score Combination of likelihood and impact.
Quantitative analysis Objective monetary values; fully quantitative only if all elements quantified; costly.
SLE / ALE AV × EF / SLE × ARO.
Qualitative analysis Scenario oriented; no absolute numbers; ranks seriousness of threats and asset sensitivity.
AS/NZS 4360 Likelihood (A–E) × consequence (1–5) → Extreme, High, Moderate, Low.
Qualitative techniques Delphi, SWIFT, decision tree, bow-tie, probability/consequence matrix.
Mitigation options Acceptance, reduction, transference, avoidance.
Control types Directive, preventive, detective, corrective, recovery.