1 of 20

C H A P T E R 5

Risk Management

Identification • Assessment • Control • Frameworks

Principles of Information Security, 6th Edition | Whitman & Mattord

2 of 20

Learning Objectives

1.

Understand the importance of risk management in information security

2.

Learn the risk identification process: assets, threats, and vulnerabilities

3.

Apply quantitative risk assessment (SLE, ARO, ALE) and perform CBA

4.

Compare qualitative vs. quantitative risk assessment methods

5.

Understand the four risk control strategies: Avoidance, Transference, Mitigation, Acceptance

6.

Apply cost-benefit analysis to security investment decisions

7.

Identify key frameworks: NIST RMF, ISO 27005, FAIR, OCTAVE

8.

Recognize roles, responsibilities, and the continuous risk management cycle

Chapter 5: Risk Management

Objectives

3 of 20

What Is Risk Management?

Chapter 5: Risk Management

Introduction

Risk: The probability a threat exploits a vulnerability to harm an information asset — multiplied by the expected impact. Risk = Likelihood × Impact

Identify

Assets, Threats

& Vulnerabilities

Assess

Likelihood, Impact

& ALE

Control

Select & Implement

Security Controls

Review

Monitor & Reassess

Continuously

KEY: Risk management is NOT about eliminating all risk — it is about making informed decisions: accept, mitigate, transfer, or avoid, based on organizational priorities and resources.

4 of 20

Risk Identification — Assets & Threats

Chapter 5: Risk Management

Identification

Information Assets

Customer records, databases, research data, documentation

Hardware Assets

Servers, networking equipment, storage devices, endpoints

Software Assets

Applications, OS, dev tools, utilities

Personnel

Skills, knowledge, and competencies of key staff

Service Assets

IT services, communications, utilities, cloud services

Intangible Assets

Reputation, brand, goodwill, intellectual property

NOTE: A threat requires a corresponding vulnerability to create risk. Threat identification uses the 12-category framework: from Human Error and Software Attacks to Forces of Nature and Technological Obsolescence.

5 of 20

Threat Identification — 12 Threat Categories (Whitman & Mattord)

Chapter 5: Risk Management

Identification

Threat Category

Type

Acts of Human Error / Failure

Unintentional

Compromises to Intellectual Property

Intentional

Deliberate Acts of Espionage/Trespass

Intentional

Deliberate Acts of Information Extortion

Intentional

Deliberate Acts of Sabotage / Vandalism

Intentional

Deliberate Acts of Theft

Intentional

Threat Category

Type

Deliberate Software Attacks

Intentional

Forces of Nature

Unintentional

Deviations in Quality of Service

Either

Technical Hardware Failures / Errors

Unintentional

Technical Software Failures / Errors

Unintentional

Technological Obsolescence

Unintentional

EXAM TIP: Classify threats by type (intentional / unintentional) and category. Risk only exists when a threat has a matching vulnerability to exploit.

6 of 20

Quantitative Risk Assessment — Key Formulas

Chapter 5: Risk Management

Assessment

AV

Asset Value

AV = Fair Market Value of the Asset

Baseline dollar value of the asset being protected

EF

Exposure Factor

EF = % of Asset Value Lost per Incident

0.0 = no loss | 1.0 = total loss

SLE

Single Loss Expectancy

SLE = AV × EF

Expected dollar loss per single occurrence of a threat

ARO

Annualized Rate of Occurrence

ARO = Expected Frequency per Year

ARO 0.1 = once per 10 yrs | ARO 2 = twice per yr

ALE

Annualized Loss Expectancy

ALE = SLE × ARO = AV × EF × ARO

★ Primary metric for cost-benefit analysis of security controls

7 of 20

ALE Worked Example & Cost-Benefit Analysis

Chapter 5: Risk Management

Assessment

ALE Calculation

Customer Database

AV = $500,000

Exposure Factor (40%)

EF = 0.40

SLE = AV × EF

SLE = $200,000

Rate of Occurrence

ARO = 0.25 (1 in 4 yrs)

ALE = SLE × ARO

ALE = $50,000/yr

Cost-Benefit Analysis (CBA)

CBA = ALE(before) − ALE(after) − ACS

ALE without control

$50,000/yr

ALE with firewall

$10,000/yr

Annual Control Cost (ACS)

$8,000/yr

CBA = $50K−$10K−$8K

= $32,000 ✓

CBA > 0 ⟹ Control is cost-effective

8 of 20

Qualitative vs. Quantitative Risk Assessment

Chapter 5: Risk Management

Assessment

Qualitative Assessment

Quantitative Assessment

Uses H / M / L scales

Uses dollar values (ALE)

Based on expert judgment

Based on historical data & statistics

Faster, less resource-intensive

Slower, data-intensive

Harder to use directly for CBA

Directly supports cost-benefit analysis

Best when data is limited

Best when mature data is available

Risk Matrix (Likelihood × Impact):

Low Impact

Med Impact

High Impact

High Likelihood

MEDIUM

HIGH

CRITICAL

Med Likelihood

LOW

MEDIUM

HIGH

Low Likelihood

VERY LOW

LOW

MEDIUM

DELPHI METHOD: A qualitative technique using anonymous expert panel input over multiple rounds to reach consensus on risk ratings. Reduces groupthink bias.

Chapter 5: Risk Management

Assessment

9 of 20

Four Risk Control Strategies

Chapter 5: Risk Management

Risk Control

Avoidance

Eliminate the risky

activity entirely

Best When:

Risk too high; activity not essential to mission

Transference

Shift financial impact

to another party

Best When:

Insurance, outsourcing. Legal liability STAYS with org.

Mitigation

Reduce risk through

security controls

Best When:

MOST COMMON — risk reducible cost-effectively

Acceptance

Document & tolerate

risk without extra controls

Best When:

Control cost exceeds expected loss; within risk appetite

10 of 20

Security Controls — By Function & By Type

Chapter 5: Risk Management

Risk Control

By Function

Preventive

Stop threats before they occur

Firewalls, access controls, encryption

Detective

Identify threats as they happen

IDS/IPS, audit logs, anomaly detection

Corrective

Reduce impact after an incident

Backups, DR plans, incident response

Compensating

Offset weakness when primary control is infeasible

Enhanced monitoring, manual approvals

By Implementation Type

Administrative

Policies, procedures, training, background checks, separation of duties

Technical

Firewalls, encryption, IDS/IPS, access controls, MFA, authentication

Physical

Locks, guards, badge readers, fences, environmental controls (HVAC, fire)

DEFENSE IN DEPTH: Layer controls across all types and functions — each control can be both (e.g., firewall = Technical + Preventive). Multiple layers ensure no single point of failure.

11 of 20

Risk Management Frameworks

Chapter 5: Risk Management

Frameworks

NIST RMF

SP 800-37 — US Government

1. Categorize

2. Select

3. Implement

4. Assess

5. Authorize

6. Monitor

ISO/IEC 27005

Aligned with ISO 27001 ISMS

1. Context

2. Risk Assessment

3. Risk Treatment

4. Acceptance

5. Communicate

6. Monitor

FAIR

Factor Analysis of Information Risk

1. Define Scenario

2. Estimate TEF

3. Estimate LEF

4. Assess Vuln

5. Estimate Loss

6. Derive Risk

OCTAVE

Carnegie Mellon CERT — people & process

1. Identify Assets

2. Identify Threats

3. Assess Vulns

4. Analyze Risks

5. Develop Strategy

6. Implement Plans

12 of 20

NIST Risk Management Framework — Six Steps

Chapter 5: Risk Management

NIST RMF

1

Categorize

Classify the information system by impact level (FIPS 199)

Output: Security category

2

Select

Choose baseline security controls from NIST SP 800-53

Output: Control baseline

3

Implement

Deploy selected controls within the system

Output: Implemented controls

4

Assess

Evaluate control effectiveness through testing & review

Output: Security assessment report

5

Authorize

Senior official accepts residual risk; authorizes operation

Output: Authorization to Operate (ATO)

6

Monitor

Continuously monitor controls, report status, update assessments

Output: Ongoing risk posture

EXAM TIP: Memorize in order: Categorize → Select → Implement → Assess → Authorize → Monitor. The ATO (Authorization to Operate) is the output of Step 5 — Authorize.

13 of 20

Special Risk Topics — Insider Threat & Supply Chain

Chapter 5: Risk Management

Special Topics

Insider Threat

Risk from employees, contractors & partners with AUTHORIZED access who misuse it — maliciously or negligently.

Least Privilege:

Grant only minimum access required for job function

Separation of Duties:

Multiple approvers required for sensitive transactions

User Activity Monitoring:

Behavioral analytics to detect anomalies (UAM)

Background Checks:

Pre-employment screening; re-investigation for sensitive roles

Security Awareness:

Training employees to recognize & report suspicious behavior

Supply Chain Risk

Risk from third-party vendors, software, or services. A compromised supplier propagates attacks downstream.

Vendor Due Diligence:

Evaluate supplier security programs before procurement

Contractual Requirements:

Mandate security standards in vendor agreements

Third-Party Assessments:

Audit or assess vendor security posture periodically

SBOM:

Software Bill of Materials — track component origins & vulnerabilities

Monitor Advisories:

Track vendor security patches and vulnerability alerts

14 of 20

Risk Management — Roles & Responsibilities

Chapter 5: Risk Management

Governance

Role

Key Responsibilities

Board / Senior Executives

Set risk appetite; ultimate accountability; approve risk policy

CISO

Lead risk program; report risk posture to board; oversee treatments

Chief Risk Officer (CRO)

Enterprise-wide risk governance; integrate InfoSec with financial risk

InfoSec Manager

Conduct risk assessments; implement controls; maintain risk register

System / Data Owners

Accept residual risk for their systems; ensure controls are implemented

IT Staff / Analysts

Implement technical controls; monitor threats; report security events

End Users

Follow policies; report suspicious activity; complete security training

Internal Audit

Independently assess control effectiveness; verify regulatory compliance

15 of 20

The Risk Register

Chapter 5: Risk Management

Risk Control

Risk Register: A living document cataloguing all identified risks with description, likelihood, impact, owner, control strategy, and current status. Updated continuously throughout the risk management process.

Risk ID

Unique identifier for tracking each risk entry

Risk Description

Clear statement of the risk event, its cause, and affected asset

Likelihood

Probability of occurrence (qualitative or quantitative)

Impact

Severity of consequence if the risk is realized

Risk Rating

Combined prioritization score: Likelihood × Impact

Risk Owner

Individual accountable for managing the specific risk

Control Strategy

Avoidance / Transference / Mitigation / Acceptance

Status

Open / In Progress / Closed

16 of 20

Key Definitions — Quick Reference

Chapter 5: Risk Management

Exam Review

Risk

Probability × Impact of a harmful event on an information asset

Threat

Potential event that could cause harm to an asset

Vulnerability

Weakness that a threat can exploit

SLE

Expected dollar loss per single occurrence (AV × EF)

ARO

Expected annual frequency of a specific threat event

ALE

Expected annual dollar loss; ALE = SLE × ARO

Residual Risk

Risk remaining AFTER controls are applied

Defense in Depth

Multiple overlapping security layers — no single point of failure

Risk Appetite

Level of risk an organization is willing to accept

Risk Register

Living document cataloguing all identified risks + status + owner

CBA

Cost-Benefit Analysis: ALE(before) − ALE(after) − ACS

KRI

Key Risk Indicator — metric signaling increasing risk exposure

17 of 20

Formula Review — Must Memorize

Chapter 5: Risk Management

Exam Review

SLE

Single Loss Expectancy

SLE = AV × EF

AV = Asset Value | EF = Exposure Factor (0.0 – 1.0)

ALE

Annualized Loss Expectancy

ALE = SLE × ARO = AV × EF × ARO

ARO = Annualized Rate of Occurrence (occurrences per year)

CBA

Cost-Benefit Analysis

CBA = ALE(before) − ALE(after) − ACS

ACS = Annual Cost of Security control. CBA > 0 = cost-effective ✓

Example: AV=$500K, EF=0.40 → SLE=$200K | ARO=0.25 → ALE=$50K/yr | Control ACS=$8K → ALE drops to $10K → CBA=$32,000 ✓ Cost-effective

18 of 20

Practice Questions

Chapter 5: Risk Management

Exam Review

1

Q1: AV=$400K, EF=0.50, ARO=0.20 — What is the ALE?

SLE = $400K × 0.50 = $200K | ALE = $200K × 0.20 = $40,000/yr

2

Q2: Control costs $5K/yr and reduces ALE from $40K to $12K. Cost-effective?

CBA = $40K − $12K − $5K = +$23,000 → YES, cost-effective

3

Q3: A company buys cyber insurance for ransomware risk. Which strategy is this?

Risk Transference — financial impact shifted to insurer. Legal liability REMAINS with the organization.

4

Q4: What distinguishes risk acceptance from simply ignoring a risk?

Acceptance = formal, documented management decision with justification. Ignoring = negligence, NOT risk management.

5

Q5: List the six NIST RMF steps in order.

Categorize → Select → Implement → Assess → Authorize → Monitor. ATO issued at Step 5.

19 of 20

The Continuous Risk Management Cycle

Chapter 5: Risk Management

Risk Management

Continuous

Risk

Management

Cycle

IDENTIFY

Asset inventory

Threat ID

Vuln scanning

ASSESS

Likelihood & impact

ALE calc

Prioritize

CONTROL

Select controls

Implement

Test & update

REVIEW

Audit controls

Reassess risks

Report

KEY: The risk management cycle has NO end. The Review phase feeds back into Identification. The risk environment evolves continuously — new threats, new systems, new regulations.

20 of 20

Chapter 5 — Key Takeaways

1

Risk management: 4-step cycle — Identify, Assess, Control, Review. Risk = Likelihood × Impact.

2

Threats require a vulnerability to create risk. 12-category threat taxonomy applies here too.

3

Quantitative: SLE = AV × EF, ALE = SLE × ARO. Use CBA = ALE(before) − ALE(after) − ACS to justify controls.

4

Four control strategies: Avoidance (eliminate), Transference (insure), Mitigation (controls), Acceptance (document).

5

NIST RMF six steps: Categorize → Select → Implement → Assess → Authorize → Monitor. ATO at Step 5.

6

Defense in depth = layered controls. Classify by function (preventive/detective/corrective) AND type (admin/technical/physical).

7

Supply chain and insider threats are top priorities. Legal liability is NOT transferred by outsourcing.

8

Risk management is continuous — risk register is a living document. KRIs provide early warning signals.

Principles of Information Security, 6th Edition | Whitman & Mattord