C H A P T E R 5
Risk Management
Identification • Assessment • Control • Frameworks
Principles of Information Security, 6th Edition | Whitman & Mattord
Learning Objectives
1.
Understand the importance of risk management in information security
2.
Learn the risk identification process: assets, threats, and vulnerabilities
3.
Apply quantitative risk assessment (SLE, ARO, ALE) and perform CBA
4.
Compare qualitative vs. quantitative risk assessment methods
5.
Understand the four risk control strategies: Avoidance, Transference, Mitigation, Acceptance
6.
Apply cost-benefit analysis to security investment decisions
7.
Identify key frameworks: NIST RMF, ISO 27005, FAIR, OCTAVE
8.
Recognize roles, responsibilities, and the continuous risk management cycle
Chapter 5: Risk Management
Objectives
What Is Risk Management?
Chapter 5: Risk Management
Introduction
Risk: The probability a threat exploits a vulnerability to harm an information asset — multiplied by the expected impact. Risk = Likelihood × Impact
Identify
Assets, Threats
& Vulnerabilities
▶
Assess
Likelihood, Impact
& ALE
▶
Control
Select & Implement
Security Controls
▶
Review
Monitor & Reassess
Continuously
KEY: Risk management is NOT about eliminating all risk — it is about making informed decisions: accept, mitigate, transfer, or avoid, based on organizational priorities and resources.
Risk Identification — Assets & Threats
Chapter 5: Risk Management
Identification
Information Assets
Customer records, databases, research data, documentation
Hardware Assets
Servers, networking equipment, storage devices, endpoints
Software Assets
Applications, OS, dev tools, utilities
Personnel
Skills, knowledge, and competencies of key staff
Service Assets
IT services, communications, utilities, cloud services
Intangible Assets
Reputation, brand, goodwill, intellectual property
NOTE: A threat requires a corresponding vulnerability to create risk. Threat identification uses the 12-category framework: from Human Error and Software Attacks to Forces of Nature and Technological Obsolescence.
Threat Identification — 12 Threat Categories (Whitman & Mattord)
Chapter 5: Risk Management
Identification
Threat Category
Type
Acts of Human Error / Failure
Unintentional
Compromises to Intellectual Property
Intentional
Deliberate Acts of Espionage/Trespass
Intentional
Deliberate Acts of Information Extortion
Intentional
Deliberate Acts of Sabotage / Vandalism
Intentional
Deliberate Acts of Theft
Intentional
Threat Category
Type
Deliberate Software Attacks
Intentional
Forces of Nature
Unintentional
Deviations in Quality of Service
Either
Technical Hardware Failures / Errors
Unintentional
Technical Software Failures / Errors
Unintentional
Technological Obsolescence
Unintentional
EXAM TIP: Classify threats by type (intentional / unintentional) and category. Risk only exists when a threat has a matching vulnerability to exploit.
Quantitative Risk Assessment — Key Formulas
Chapter 5: Risk Management
Assessment
AV
Asset Value
AV = Fair Market Value of the Asset
Baseline dollar value of the asset being protected
EF
Exposure Factor
EF = % of Asset Value Lost per Incident
0.0 = no loss | 1.0 = total loss
SLE
Single Loss Expectancy
SLE = AV × EF
Expected dollar loss per single occurrence of a threat
ARO
Annualized Rate of Occurrence
ARO = Expected Frequency per Year
ARO 0.1 = once per 10 yrs | ARO 2 = twice per yr
ALE
Annualized Loss Expectancy
ALE = SLE × ARO = AV × EF × ARO
★ Primary metric for cost-benefit analysis of security controls
ALE Worked Example & Cost-Benefit Analysis
Chapter 5: Risk Management
Assessment
ALE Calculation
Customer Database
AV = $500,000
Exposure Factor (40%)
EF = 0.40
SLE = AV × EF
SLE = $200,000
Rate of Occurrence
ARO = 0.25 (1 in 4 yrs)
ALE = SLE × ARO
ALE = $50,000/yr
Cost-Benefit Analysis (CBA)
CBA = ALE(before) − ALE(after) − ACS
ALE without control
$50,000/yr
ALE with firewall
$10,000/yr
Annual Control Cost (ACS)
$8,000/yr
CBA = $50K−$10K−$8K
= $32,000 ✓
CBA > 0 ⟹ Control is cost-effective
Qualitative vs. Quantitative Risk Assessment
Chapter 5: Risk Management
Assessment
Qualitative Assessment
Quantitative Assessment
Uses H / M / L scales
Uses dollar values (ALE)
Based on expert judgment
Based on historical data & statistics
Faster, less resource-intensive
Slower, data-intensive
Harder to use directly for CBA
Directly supports cost-benefit analysis
Best when data is limited
Best when mature data is available
Risk Matrix (Likelihood × Impact):
Low Impact
Med Impact
High Impact
High Likelihood
MEDIUM
HIGH
CRITICAL
Med Likelihood
LOW
MEDIUM
HIGH
Low Likelihood
VERY LOW
LOW
MEDIUM
DELPHI METHOD: A qualitative technique using anonymous expert panel input over multiple rounds to reach consensus on risk ratings. Reduces groupthink bias.
Chapter 5: Risk Management
Assessment
Four Risk Control Strategies
Chapter 5: Risk Management
Risk Control
Avoidance
Eliminate the risky
activity entirely
Best When:
Risk too high; activity not essential to mission
Transference
Shift financial impact
to another party
Best When:
Insurance, outsourcing. Legal liability STAYS with org.
Mitigation
Reduce risk through
security controls
Best When:
MOST COMMON — risk reducible cost-effectively
Acceptance
Document & tolerate
risk without extra controls
Best When:
Control cost exceeds expected loss; within risk appetite
Security Controls — By Function & By Type
Chapter 5: Risk Management
Risk Control
By Function
Preventive
Stop threats before they occur
Firewalls, access controls, encryption
Detective
Identify threats as they happen
IDS/IPS, audit logs, anomaly detection
Corrective
Reduce impact after an incident
Backups, DR plans, incident response
Compensating
Offset weakness when primary control is infeasible
Enhanced monitoring, manual approvals
By Implementation Type
Administrative
Policies, procedures, training, background checks, separation of duties
Technical
Firewalls, encryption, IDS/IPS, access controls, MFA, authentication
Physical
Locks, guards, badge readers, fences, environmental controls (HVAC, fire)
DEFENSE IN DEPTH: Layer controls across all types and functions — each control can be both (e.g., firewall = Technical + Preventive). Multiple layers ensure no single point of failure.
Risk Management Frameworks
Chapter 5: Risk Management
Frameworks
NIST RMF
SP 800-37 — US Government
1. Categorize
2. Select
3. Implement
4. Assess
5. Authorize
6. Monitor
ISO/IEC 27005
Aligned with ISO 27001 ISMS
1. Context
2. Risk Assessment
3. Risk Treatment
4. Acceptance
5. Communicate
6. Monitor
FAIR
Factor Analysis of Information Risk
1. Define Scenario
2. Estimate TEF
3. Estimate LEF
4. Assess Vuln
5. Estimate Loss
6. Derive Risk
OCTAVE
Carnegie Mellon CERT — people & process
1. Identify Assets
2. Identify Threats
3. Assess Vulns
4. Analyze Risks
5. Develop Strategy
6. Implement Plans
NIST Risk Management Framework — Six Steps
Chapter 5: Risk Management
NIST RMF
1
Categorize
Classify the information system by impact level (FIPS 199)
Output: Security category
2
Select
Choose baseline security controls from NIST SP 800-53
Output: Control baseline
3
Implement
Deploy selected controls within the system
Output: Implemented controls
4
Assess
Evaluate control effectiveness through testing & review
Output: Security assessment report
5
Authorize
Senior official accepts residual risk; authorizes operation
Output: Authorization to Operate (ATO)
6
Monitor
Continuously monitor controls, report status, update assessments
Output: Ongoing risk posture
EXAM TIP: Memorize in order: Categorize → Select → Implement → Assess → Authorize → Monitor. The ATO (Authorization to Operate) is the output of Step 5 — Authorize.
Special Risk Topics — Insider Threat & Supply Chain
Chapter 5: Risk Management
Special Topics
Insider Threat
Risk from employees, contractors & partners with AUTHORIZED access who misuse it — maliciously or negligently.
Least Privilege:
Grant only minimum access required for job function
Separation of Duties:
Multiple approvers required for sensitive transactions
User Activity Monitoring:
Behavioral analytics to detect anomalies (UAM)
Background Checks:
Pre-employment screening; re-investigation for sensitive roles
Security Awareness:
Training employees to recognize & report suspicious behavior
Supply Chain Risk
Risk from third-party vendors, software, or services. A compromised supplier propagates attacks downstream.
Vendor Due Diligence:
Evaluate supplier security programs before procurement
Contractual Requirements:
Mandate security standards in vendor agreements
Third-Party Assessments:
Audit or assess vendor security posture periodically
SBOM:
Software Bill of Materials — track component origins & vulnerabilities
Monitor Advisories:
Track vendor security patches and vulnerability alerts
Risk Management — Roles & Responsibilities
Chapter 5: Risk Management
Governance
Role
Key Responsibilities
Board / Senior Executives
Set risk appetite; ultimate accountability; approve risk policy
CISO
Lead risk program; report risk posture to board; oversee treatments
Chief Risk Officer (CRO)
Enterprise-wide risk governance; integrate InfoSec with financial risk
InfoSec Manager
Conduct risk assessments; implement controls; maintain risk register
System / Data Owners
Accept residual risk for their systems; ensure controls are implemented
IT Staff / Analysts
Implement technical controls; monitor threats; report security events
End Users
Follow policies; report suspicious activity; complete security training
Internal Audit
Independently assess control effectiveness; verify regulatory compliance
The Risk Register
Chapter 5: Risk Management
Risk Control
Risk Register: A living document cataloguing all identified risks with description, likelihood, impact, owner, control strategy, and current status. Updated continuously throughout the risk management process.
Risk ID
Unique identifier for tracking each risk entry
Risk Description
Clear statement of the risk event, its cause, and affected asset
Likelihood
Probability of occurrence (qualitative or quantitative)
Impact
Severity of consequence if the risk is realized
Risk Rating
Combined prioritization score: Likelihood × Impact
Risk Owner
Individual accountable for managing the specific risk
Control Strategy
Avoidance / Transference / Mitigation / Acceptance
Status
Open / In Progress / Closed
Key Definitions — Quick Reference
Chapter 5: Risk Management
Exam Review
Risk
Probability × Impact of a harmful event on an information asset
Threat
Potential event that could cause harm to an asset
Vulnerability
Weakness that a threat can exploit
SLE
Expected dollar loss per single occurrence (AV × EF)
ARO
Expected annual frequency of a specific threat event
ALE
Expected annual dollar loss; ALE = SLE × ARO
Residual Risk
Risk remaining AFTER controls are applied
Defense in Depth
Multiple overlapping security layers — no single point of failure
Risk Appetite
Level of risk an organization is willing to accept
Risk Register
Living document cataloguing all identified risks + status + owner
CBA
Cost-Benefit Analysis: ALE(before) − ALE(after) − ACS
KRI
Key Risk Indicator — metric signaling increasing risk exposure
Formula Review — Must Memorize
Chapter 5: Risk Management
Exam Review
SLE
Single Loss Expectancy
SLE = AV × EF
AV = Asset Value | EF = Exposure Factor (0.0 – 1.0)
ALE
Annualized Loss Expectancy
ALE = SLE × ARO = AV × EF × ARO
ARO = Annualized Rate of Occurrence (occurrences per year)
CBA
Cost-Benefit Analysis
CBA = ALE(before) − ALE(after) − ACS
ACS = Annual Cost of Security control. CBA > 0 = cost-effective ✓
Example: AV=$500K, EF=0.40 → SLE=$200K | ARO=0.25 → ALE=$50K/yr | Control ACS=$8K → ALE drops to $10K → CBA=$32,000 ✓ Cost-effective
Practice Questions
Chapter 5: Risk Management
Exam Review
1
Q1: AV=$400K, EF=0.50, ARO=0.20 — What is the ALE?
SLE = $400K × 0.50 = $200K | ALE = $200K × 0.20 = $40,000/yr
2
Q2: Control costs $5K/yr and reduces ALE from $40K to $12K. Cost-effective?
CBA = $40K − $12K − $5K = +$23,000 → YES, cost-effective
3
Q3: A company buys cyber insurance for ransomware risk. Which strategy is this?
Risk Transference — financial impact shifted to insurer. Legal liability REMAINS with the organization.
4
Q4: What distinguishes risk acceptance from simply ignoring a risk?
Acceptance = formal, documented management decision with justification. Ignoring = negligence, NOT risk management.
5
Q5: List the six NIST RMF steps in order.
Categorize → Select → Implement → Assess → Authorize → Monitor. ATO issued at Step 5.
The Continuous Risk Management Cycle
Chapter 5: Risk Management
Risk Management
Continuous
Risk
Management
Cycle
▶
▶
▶
▶
IDENTIFY
Asset inventory
Threat ID
Vuln scanning
ASSESS
Likelihood & impact
ALE calc
Prioritize
CONTROL
Select controls
Implement
Test & update
REVIEW
Audit controls
Reassess risks
Report
KEY: The risk management cycle has NO end. The Review phase feeds back into Identification. The risk environment evolves continuously — new threats, new systems, new regulations.
Chapter 5 — Key Takeaways
1
Risk management: 4-step cycle — Identify, Assess, Control, Review. Risk = Likelihood × Impact.
2
Threats require a vulnerability to create risk. 12-category threat taxonomy applies here too.
3
Quantitative: SLE = AV × EF, ALE = SLE × ARO. Use CBA = ALE(before) − ALE(after) − ACS to justify controls.
4
Four control strategies: Avoidance (eliminate), Transference (insure), Mitigation (controls), Acceptance (document).
5
NIST RMF six steps: Categorize → Select → Implement → Assess → Authorize → Monitor. ATO at Step 5.
6
Defense in depth = layered controls. Classify by function (preventive/detective/corrective) AND type (admin/technical/physical).
7
Supply chain and insider threats are top priorities. Legal liability is NOT transferred by outsourcing.
8
Risk management is continuous — risk register is a living document. KRIs provide early warning signals.
Principles of Information Security, 6th Edition | Whitman & Mattord