Sunteți pe pagina 1din 23

Risk Analysis/ Risk

Management
Threats, Vulnerability, Assets and Risk
Risk Management and Risk Analysis
Process of Risk Analysis/Risk Management
Staged Methodology for Risk Analysis
• Three main stages in risk analysis:
• 1. Asset Evaluation
• 2. Analysis of threats and vulnerabilities
• 3. selection of safeguards
Approaches and consideration in Information
security Risk Analysis
• Quantitative risk analysis
• Qualitative risk analysis
• Valuation of Assets
• Selection of safeguards
How Quantitative risk analysis is done ?
• In this, the attempt is to assign independently the objective numeric
values in monetary terms to the components of the risk assessment
and to the assessment of the potential loss.

• Qualitative risk analysis address intangible values of a


data/information loss and its focus is on other issues rather than on
the pure hard costs.
• Risk analysis is fully quantitative when the elements of risk analysis
(asset value, impact, threat frequency, effectiveness, cost of
safeguards/countermeasures ) are measured, rated and values are
assigned to them.

• 100% quantitative Risk Analysis is not possible in real practice.


Security Risk Assessment
Approach
Qualitative Analysis

Qualitative analysis relies on the subjective judgment of the


security risk assessment team to determine the overall risk
to the information systems.

The same basic elements are required to determine risk,


such as asset value, threat frequency, impact, and safeguard
effectiveness, but these elements are now measured in
subjective terms such as ‘‘high’’ or ‘‘not likely.’’
Security Risk Assessment
Approach
 Qualitative Analysis

 Qualitative values have order.

 These values are hierarchical. For example,


 High > Medium > Low
Security Risk Assessment
Approach
 Quantitative Vs. Qualitative Analysis

 Quantitative risk - A method of determining and presenting


security risk that relies on specific formulas and calculations
to determine the value of the security risk.

 Advantages: Objective; security risk expressed in terms of


dollars

 Disadvantages: Security risk calculations are complex;


accurate values are difficult to obtain
Security Risk Assessment
Approach
 Quantitative Vs. Qualitative Analysis

 Qualitative risk - A method of determining and presenting


security risk that relies on subjective measures of asset
valuation, threats, vulnerabilities, and ultimately of the
security risk.

 Advantages: Easy to understand; provides adequate


indication of the organization’s security risk

 Disadvantages: Subjective; may not be trusted by some in


management positions
Risk Mitigation Options
 Risk Avoidance
 Avoid activities involving greaterrisk
 Use alternate solutions
 Risk Termination
 Eliminate risk by removing thesource
 Risk Reduction
 Minimize probability of occurrence ofrisk
 Risk Minimization
 Reduce the impact on theorganization
 Risk Transfer
 Insurance
Categories of controls
 Technical

 Management

 Operational

 Hybrid – combination ofabove


Technical Controls
 Supporting Controls
 Identification, Cryptographic Key Management, Security
Administration, System Protection

 Preventive Controls
 Authentication, Authorization, Access Control Lists,
Nonrepudiation,

 Detection and recovering Controls


 Audits, Antivirus, Intrusion Detection System
Management Controls
 Preventive Controls
 Assigning responsibilities, Security policies, Security awareness
and training

 Detection Controls
 Background Checks, Personnel Clearance, review of security
controls, risk management

 Recovery Controls
 Continuity plans, Incident responseplans
Operational Security Controls
 Preventive Controls
 Backups, UPS, Media access and disposal, Securing wiring
closets, Controlling humidity and temperature.

 Detection Controls
 CCTV camera, motion detectors, smoke detectors, fire
alarms.
Residual Risk

 The Risk that remains after the implementation of


controls is called the residual risk.

S-ar putea să vă placă și