CYS403 Chapter 6
CYS403 · Chapter 6

From Plan to POAM:
Performing a Risk Assessment

A detailed plan for running a real risk assessment: what to prepare, the eight steps to follow, how to value assets and find threats, vulnerabilities and controls, and how to present results to management.

PreparationOperational CharacteristicsEight-Step PlanReplacement vs RecoveryVulnerability AssessmentPOAM
scroll ↓
01 / Preparation

Prepare for the Risk Assessment

Before progressing with the RA, you need to complete three preliminary actions:

1

Define the assessment

Decide what you are assessing and describe it as it is now.

2

Review previous findings

Start from where others ended.

3

Identify the management structure

Understand who owns and controls what.

Memory trick · D-R-I

Define, Review, Identify

define the system, review old reports, identify the owners.

02 / Define

Define the Assessment

Operational characteristics

Define how the system operates in your environment. Ask the relevant entities: Do you have current diagrams that show all of the current systems? Do you have documentation of the current configuration?

Mission of the system

A short sentence describing what the system does, without much detail. Compared to operational characteristics, the mission is easy to define.

Example: the email server

Operational characteristics: two email servers, an internal server and one in the DMZ, with their connections shown in a network diagram.

Mission: the e-mail server provides all e-mail services for the network, including:

Slide 4Operational characteristics and system mission for an email server.
03 / Review

Review Previous Findings

Start from where the others ended. Earlier reports can contain a lot of valuable information that makes your job easier: assets, threats, vulnerabilities, recommendations, and controls.

Pay attention to What it tells you
Recommendations Previous recommendations give insight into several issues.
Current status of accepted recommendations Measure the effectiveness of recommendations in place; find the justification for those not in place.
Unapproved recommendations Insight into the business: the level of residual risk accepted and the organization's receptiveness to the control.

Why unapproved matters

If management rejected a control before, that tells you how much residual risk they tolerate and how likely a similar recommendation is to be approved.

04 / Structure

Identify the Management Structure

The management structure refers to how responsibilities are assigned. When you define the RA scope, it's helpful to keep the scope within the ownership of a single entity.

Ask: is IT controlled by one entity or by multiple entities? Responsibilities may be split across:

Don't cross management lines

If the scope spans several owners, recommendations have no single decision maker. Match the RA to the management structure.

05 / Plan

The Risk Assessment Plan: Eight Steps

RA is not a one-day project; it is a continuous process that takes time and planning.

1

Identify assets and activities to address

2

Identify and evaluate relevant threats

3

Identify and evaluate relevant vulnerabilities

4

Identify and evaluate relevant countermeasures

5

Assess threats, vulnerabilities, and exploits

6

Evaluate risks

7

Develop recommendations to mitigate risks

8

Present recommendations to management

Memory trick · A-T-V-C then Assess, Evaluate, Recommend, Present

AssetsThreatsVulnerabilitiesCountermeasures
AssessEvaluateRecommendPresent
06 / Assets

Step 1: Identify and Value Assets

Two perspectives on asset value

Replacement value
The cost to purchase a new asset in its place. Example: a failed or stolen laptop costs $1,500 to replace with similar hardware and software.
Recovery value
The cost to get the asset operational after a failure. Example: replace a failed hard drive, reinstall the OS, and restore data. Include downtime: a 2-hour repair on a web server earning $10,000/hour adds $20,000.

Elements to consider when valuing assets

Element What to consider
System access and availability Available 24/7 or only during office hours
System functions Automated, or requires interaction
Hardware and software assets Their cost and role
Personnel assets Stable organizations vs high turnover; high turnover brings more cybersecurity issues
Data and information assets Data classification to know each item's protection level
Facilities and supplies Insurance; redundancy with hot, warm, and cold sites

Replacement vs recovery

Replacement buys a new asset. Recovery repairs the existing one and must include lost revenue during downtime.

07 / Threats and Vulnerabilities

Steps 2–3: Threats and Vulnerabilities

Identifying and evaluating relevant threats

Review historical data

Past attacks, natural events, equipment failures, and accidents.

Threat modeling

Structured methods such as STRIDE, attack trees, or OCTAVE (Chapter 3).

Identifying and evaluating relevant vulnerabilities

A vulnerability assessment gathers and captures information:

Goal Technique
Identify the IP addresses in use PING
Identify domain names WHOIS
Identify the running operating system Fingerprint attack
Identify weak passwords Password cracking
Identify open ports Port scan
Capture data NMAP, NESSUS, SATAN, SAINT

An exploit assessment goes further and actually tests whether weaknesses can be exploited, through penetration testing.

Vulnerability vs exploit assessment

A vulnerability assessment finds weaknesses. An exploit assessment (penetration test) proves they can be exploited.

08 / Countermeasures

Step 4: Identify and Evaluate Countermeasures

In-place controls
Controls currently installed in the operational system.
Planned controls
Controls with a specified implementation date.
Control categories
Administrative, technical, and physical controls.

When reviewing all of the controls, consider their purpose: whether each is directive, preventive, detective, corrective, or recovery (Chapter 2).

Category Examples
Administrative Policies, procedures, security awareness training, background checks
Technical Firewalls, encryption, IDS, access control lists
Physical Locks, guards, CCTV, fire suppression
Slide 14Control classes and their control families.
09 / Recommendations

Steps 7–8: Recommend and Present

Develop mitigating recommendations

Present the risk assessment results

Phase 1: ranked risk list to top management for approval
Phase 2: POAM
Phase one
The list of ranked risks is submitted to top management for approval.
Phase two: POAM
Plan Of Actions and Milestones: how to implement the approved items within the given budget and time.
10 / Best Practices

Best Practices for Performing Risk Assessments

1

Ensure systems are fully described

2

Review past audits

3

Review past risk assessments

4

Match the RA to the management structure

Ownership and responsibilities; don't cross management lines.

5

Identify assets within the RA boundaries

6

Identify and evaluate relevant threats

7

Identify and evaluate relevant vulnerabilities

8

Identify and evaluate countermeasures

9

Track the results

With a POAM.

11 / Exam Prep

Exam Tips & Tricks

Three preliminary actions

Define the assessment, review previous findings, identify the management structure.

Operational characteristics vs mission

Characteristics = how the system operates (diagrams, configuration docs). Mission = one short sentence of what it does; easier to define.

Previous findings

Look at recommendations, the status of accepted ones (effectiveness / justification), and unapproved ones (residual risk, receptiveness).

Management structure

Keep the scope within one owner; don't cross management lines.

Eight steps

Assets, threats, vulnerabilities, countermeasures, assess, evaluate, recommend, present.

Asset value

Replacement = buy new ($1,500 laptop). Recovery = repair + downtime (2 h × $10,000 = $20,000).

Vulnerability tools

PING (IPs), WHOIS (domains), fingerprinting (OS), password cracking, port scan; NMAP, NESSUS, SATAN, SAINT. Exploit assessment = penetration testing.

Presenting results

Phase 1: ranked risks to top management. Phase 2: POAM (Plan Of Actions and Milestones).

12 / Self-Test

Flashcards — Test Yourself

Say the answer out loud, then flip the card to check. Shuffle the deck to test yourself in a new order.

13 / Cheat Sheet

Quick Reference — Everything at a Glance

Topic Key Point
Preliminary actions Define the assessment; review previous findings; identify the management structure.
System or process Decide which is assessed; describe it as it currently is.
Operational characteristics How the system operates; current diagrams and configuration documentation.
Mission Short sentence of what the system does.
Previous findings Recommendations; status of accepted ones; unapproved ones.
Management structure How responsibilities are assigned; keep scope within one entity.
RA plan 8 steps from identifying assets to presenting recommendations.
Scope creep Evaluating assets outside the RA boundary; wastes time and resources.
Replacement value Cost to buy a new asset in its place.
Recovery value Cost to make an asset operational again, including downtime.
Valuation elements Access/availability, functions, hardware/software, personnel, data classification, facilities (insurance, hot/warm/cold sites).
Threat identification Historical data or threat modeling.
Vulnerability assessment PING, WHOIS, fingerprinting, password cracking, port scan, NMAP/NESSUS/SATAN/SAINT.
Exploit assessment Penetration testing.
Countermeasures In-place, planned; administrative, technical, physical.
Recommendations T/V pairs, cost and time, operational impact, cost-benefit analysis.
POAM Plan Of Actions and Milestones: implementing approved items within budget and time.