By: Mohammad Shoab
Security Management and Risk Assessment
Overview
2
Professional Cybersecurity
Department of Computer Science
Security Management
Security Management: a process used to achieve and maintain appropriate levels of confidentiality, integrity, availability, accountability, authenticity and reliability. IT security management functions include:
∙ organizational IT security objectives, strategies and policies
∙ determining organizational IT security requirements
∙ identifying and analyzing security threats to IT assets
∙ identifying and analyzing risks
∙ specifying appropriate safeguards
∙ monitoring the implementation and operation of safeguards
∙ developing and implement a security awareness program
∙ detecting and reacting to incidents
3
Professional Cybersecurity
Department of Computer Science
ISO 27000 Security Standards
4
Professional Cybersecurity
Department of Computer Science
IT Security Management Process
5
Professional Cybersecurity
Department of Computer Science
Plan - Do - Check – Act (Deming Cycle)
establish policy; define
objectives and processes
implement and operate
policy, controls, processes
assess and measure
and report results
take corrective and
preventative actions
(based on audits)
6
Professional Cybersecurity
Department of Computer Science
Organizational Context and Security Policy
7
Professional Cybersecurity
Department of Computer Science
Security Policy: Topics to Cover
8
Professional Cybersecurity
Department of Computer Science
Management Support
9
Professional Cybersecurity
Department of Computer Science
Security Risk Assessment
10
Professional Cybersecurity
Department of Computer Science
Baseline Approach
11
Professional Cybersecurity
Department of Computer Science
Informal Approach
12
Professional Cybersecurity
Department of Computer Science
Detailed Risk Analysis
13
Professional Cybersecurity
Department of Computer Science
Combined Approach
14
Professional Cybersecurity
Department of Computer Science
Detailed Risk Analysis Process
15
Professional Cybersecurity
Department of Computer Science
Establish Context
16
Professional Cybersecurity
Department of Computer Science
Asset Identification
17
Professional Cybersecurity
Department of Computer Science
Terminology
18
Professional Cybersecurity
Department of Computer Science
Threat Identification
19
Professional Cybersecurity
Department of Computer Science
Threat Sources
20
Professional Cybersecurity
Department of Computer Science
Threat Identification
21
Professional Cybersecurity
Department of Computer Science
Vulnerability Identification
22
Professional Cybersecurity
Department of Computer Science
Analyze Risks
risk = probability threat occurs x cost to organization
23
Professional Cybersecurity
Department of Computer Science
Determine Likelihood
24
Professional Cybersecurity
Department of Computer Science
Determine Consequence
25
Professional Cybersecurity
Department of Computer Science
Determine Resultant Risk
Consequences
Likelihood
Doomsday
Catastrophic
Major
Moderate
Minor
Insignificant
Almost
Certain
E
E
E
E
H
H
Likely
E
E
E
H
H
M
Possible
E
E
E
H
M
L
Unlikely
E
E
H
M
L
L
Rare
E
H
H
M
L
L
Risk Level
Description
Extreme (E)
Will require detailed r
esearch and management planning at an
executive/director level. Ongoing planning and monitoring will be required
with regular reviews. Substantial adjustment of controls to manage the
risk are expected, with costs possibly exceeding original forecasts.
H
igh (H)
Requires management attention, but management and planning can be left
to senior project or team leaders. Ongoing planning and monitoring with
regular reviews are likely, though adjustment of controls are likely to be
met from within existing resources
Medium (M)
Can be managed by existing specific monitoring and response procedures.
Management by employees is suitable with appropriate monitoring and
reviews.
Low (L)
Can be managed through routine procedures.
26
Professional Cybersecurity
Department of Computer Science
Document in Risk Register�and Evaluate Risks
27
Professional Cybersecurity
Department of Computer Science
Risk Treatment
28
Professional Cybersecurity
Department of Computer Science
Risk Treatment Alternatives
29
Professional Cybersecurity
Department of Computer Science
Case Study: Silver Star Mines
30
Professional Cybersecurity
Department of Computer Science
Assets
31
Professional Cybersecurity
Department of Computer Science
Threats & Vulnerabilities
32
Professional Cybersecurity
Department of Computer Science
Risk Register
33
Professional Cybersecurity
Department of Computer Science
Thank You
34
Professional Cybersecurity
Department of Computer Science