Prepare for the Risk Assessment
Before progressing with the RA, you need to complete three preliminary actions:
Define the assessment
Decide what you are assessing and describe it as it is now.
Review previous findings
Start from where others ended.
Identify the management structure
Understand who owns and controls what.
Memory trick · D-R-I
Define, Review, Identify
define the system, review old reports, identify the owners.
Define the Assessment
- Will you assess a SYSTEM or a PROCESS?
- Because things always change, describe the system or process as its current situation.
- Focus on two primary areas:
Define how the system operates in your environment. Ask the relevant entities: Do you have current diagrams that show all of the current systems? Do you have documentation of the current configuration?
A short sentence describing what the system does, without much detail. Compared to operational characteristics, the mission is easy to define.
Example: the email server
Operational characteristics: two email servers, an internal server and one in the DMZ, with their connections shown in a network diagram.
Mission: the e-mail server provides all e-mail services for the network, including:
- Routing e-mail between internal clients
- Accepting e-mail from external servers and routing it to internal clients
- Accepting e-mail from internal clients and routing it to external servers
- Scanning all attachments and removing malware
- Scanning all e-mail for spam and stripping confirmed spam
Review Previous Findings
Start from where the others ended. Earlier reports can contain a lot of valuable information that makes your job easier: assets, threats, vulnerabilities, recommendations, and controls.
| Pay attention to | What it tells you |
|---|---|
| Recommendations | Previous recommendations give insight into several issues. |
| Current status of accepted recommendations | Measure the effectiveness of recommendations in place; find the justification for those not in place. |
| Unapproved recommendations | Insight into the business: the level of residual risk accepted and the organization's receptiveness to the control. |
Why unapproved matters
If management rejected a control before, that tells you how much residual risk they tolerate and how likely a similar recommendation is to be approved.
Identify the Management Structure
The management structure refers to how responsibilities are assigned. When you define the RA scope, it's helpful to keep the scope within the ownership of a single entity.
Ask: is IT controlled by one entity or by multiple entities? Responsibilities may be split across:
- Network infrastructure
- User and computer management
- E-mail servers
- Web servers
- Database servers
- Configuration and change management (systematic and consistent, with proper documentation)
Don't cross management lines
If the scope spans several owners, recommendations have no single decision maker. Match the RA to the management structure.
The Risk Assessment Plan: Eight Steps
RA is not a one-day project; it is a continuous process that takes time and planning.
Identify assets and activities to address
Identify and evaluate relevant threats
Identify and evaluate relevant vulnerabilities
Identify and evaluate relevant countermeasures
Assess threats, vulnerabilities, and exploits
Evaluate risks
Develop recommendations to mitigate risks
Present recommendations to management
Memory trick · A-T-V-C then Assess, Evaluate, Recommend, Present
Step 1: Identify and Value Assets
- Evaluate only assets within the boundary of the RA.
- Scope creep occurs when you start evaluating assets outside the scope, which wastes time and resources.
Two perspectives on asset value
Elements to consider when valuing assets
| Element | What to consider |
|---|---|
| System access and availability | Available 24/7 or only during office hours |
| System functions | Automated, or requires interaction |
| Hardware and software assets | Their cost and role |
| Personnel assets | Stable organizations vs high turnover; high turnover brings more cybersecurity issues |
| Data and information assets | Data classification to know each item's protection level |
| Facilities and supplies | Insurance; redundancy with hot, warm, and cold sites |
Replacement vs recovery
Replacement buys a new asset. Recovery repairs the existing one and must include lost revenue during downtime.
Steps 2–3: Threats and Vulnerabilities
Identifying and evaluating relevant threats
Past attacks, natural events, equipment failures, and accidents.
Structured methods such as STRIDE, attack trees, or OCTAVE (Chapter 3).
Identifying and evaluating relevant vulnerabilities
A vulnerability assessment gathers and captures information:
| Goal | Technique |
|---|---|
| Identify the IP addresses in use | PING |
| Identify domain names | WHOIS |
| Identify the running operating system | Fingerprint attack |
| Identify weak passwords | Password cracking |
| Identify open ports | Port scan |
| Capture data | NMAP, NESSUS, SATAN, SAINT |
An exploit assessment goes further and actually tests whether weaknesses can be exploited, through penetration testing.
Vulnerability vs exploit assessment
A vulnerability assessment finds weaknesses. An exploit assessment (penetration test) proves they can be exploited.
Step 4: Identify and Evaluate Countermeasures
When reviewing all of the controls, consider their purpose: whether each is directive, preventive, detective, corrective, or recovery (Chapter 2).
| Category | Examples |
|---|---|
| Administrative | Policies, procedures, security awareness training, background checks |
| Technical | Firewalls, encryption, IDS, access control lists |
| Physical | Locks, guards, CCTV, fire suppression |
Steps 7–8: Recommend and Present
Develop mitigating recommendations
- Based on threat/vulnerability pairs
- Include an estimate of cost and time to implement
- Include an estimate of operational impact
- Justify with a cost-benefit analysis
Present the risk assessment results
Best Practices for Performing Risk Assessments
Ensure systems are fully described
Review past audits
Review past risk assessments
Match the RA to the management structure
Ownership and responsibilities; don't cross management lines.
Identify assets within the RA boundaries
Identify and evaluate relevant threats
Identify and evaluate relevant vulnerabilities
Identify and evaluate countermeasures
Track the results
With a POAM.
Exam Tips & Tricks
Three preliminary actions
Define the assessment, review previous findings, identify the management structure.
Operational characteristics vs mission
Characteristics = how the system operates (diagrams, configuration docs). Mission = one short sentence of what it does; easier to define.
Previous findings
Look at recommendations, the status of accepted ones (effectiveness / justification), and unapproved ones (residual risk, receptiveness).
Management structure
Keep the scope within one owner; don't cross management lines.
Eight steps
Assets, threats, vulnerabilities, countermeasures, assess, evaluate, recommend, present.
Asset value
Replacement = buy new ($1,500 laptop). Recovery = repair + downtime (2 h × $10,000 = $20,000).
Vulnerability tools
PING (IPs), WHOIS (domains), fingerprinting (OS), password cracking, port scan; NMAP, NESSUS, SATAN, SAINT. Exploit assessment = penetration testing.
Presenting results
Phase 1: ranked risks to top management. Phase 2: POAM (Plan Of Actions and Milestones).
Flashcards — Test Yourself
Say the answer out loud, then flip the card to check. Shuffle the deck to test yourself in a new order.
Quick Reference — Everything at a Glance
| Topic | Key Point |
|---|---|
| Preliminary actions | Define the assessment; review previous findings; identify the management structure. |
| System or process | Decide which is assessed; describe it as it currently is. |
| Operational characteristics | How the system operates; current diagrams and configuration documentation. |
| Mission | Short sentence of what the system does. |
| Previous findings | Recommendations; status of accepted ones; unapproved ones. |
| Management structure | How responsibilities are assigned; keep scope within one entity. |
| RA plan | 8 steps from identifying assets to presenting recommendations. |
| Scope creep | Evaluating assets outside the RA boundary; wastes time and resources. |
| Replacement value | Cost to buy a new asset in its place. |
| Recovery value | Cost to make an asset operational again, including downtime. |
| Valuation elements | Access/availability, functions, hardware/software, personnel, data classification, facilities (insurance, hot/warm/cold sites). |
| Threat identification | Historical data or threat modeling. |
| Vulnerability assessment | PING, WHOIS, fingerprinting, password cracking, port scan, NMAP/NESSUS/SATAN/SAINT. |
| Exploit assessment | Penetration testing. |
| Countermeasures | In-place, planned; administrative, technical, physical. |
| Recommendations | T/V pairs, cost and time, operational impact, cost-benefit analysis. |
| POAM | Plan Of Actions and Milestones: implementing approved items within budget and time. |