Site icon Segurança Informática

Risk Management Processes And Concepts

Introduction

The risk management process is a way of achieving a structured approach to the management of risk in IT corporations. Consistently implemented, it allows risks to be identified, analyzed, evaluated, and managed in a uniform, efficient and focused manner. In this article, we will describe most of the risk management processes addressed in the CompTIA Security+ Certification which is a standard for recognizing competence in IT security landscape.

 

Understanding the Context of Risk Management

Risk assessment and a mitigation strategy is part of the process of managing risks in many organizations worldwide. This type of approach represents a critical piece of work within the security horizon, as it includes the identification and evaluation of a potential risk and its impact. The risk process includes brainstorming sessions where the team is asked to create a list of everything that could go wrong.

 

Three concepts are important to consider when risk assessment is established, namely:

The external context: the environment in which the entity operates (e.g., the type of companies, such as, cultural, financial, political) and the potential impact that a risk can produce.

The internal context: includes factors within the entity that are relevant to the risk assessment such as objectives, strategy, organizational capabilities, culture, etc.

The risk management context: the goals and objectives of the risk management activity. For example, determining who is responsible for each component and what is in scope.

 

Risk Management Concepts

Throughout this section, some of the most well-known concepts in risk management are described. These concepts are adopted by IT companies, and by information security specialists. Figure 1 below depicts the concepts herein discussed.

Figure 1: General workflow of the risk management process.

 

Risk Identification

The main goal of risk identification is to recognize all the possible risks, and not to eliminate risks from analysis neither to develop solutions for mitigating risks (because those functions are carried out during the risk treatment and mitigation steps). A disciplined process typically involves the use of checklists of potential risks and evaluating the likelihood that those events might happen. For example, some companies develop risk checklists based on experience from past incidents and projects.

The following activities can conduct risk identification:

 

Risk Analysis

A Risk analysis quantifies the statistical likelihood of an impact of a particular risk and its frequency of occurrence Afterwards, using the combination of these two factors one can determine the severity of the risk, which may be either positive or negative. Although there are many ways of calculating risk, there is a generic form based on a matrix called risk heat map, illustrated in Table 1 below.

Table 1: Example of a risk heat map matrix.

This table is a vital piece of work that provides for all organizations the capacity to map the risk of its ecosystem and get an overview of security risk its internal processes and strategy.

 

Risk Evaluation

Risk evaluation allows determining the tolerability of each risk. It should be noted that tolerability is different from severity. Tolerability allows determining which risks need treatment and relative priority. This can be achieved by comparing the risk severity established in the risk analysis step with the risk criteria generally found in the consequence criteria already defined in Table 1 above.

 

Risk Treatment / Risk Reduction

Once the particular risk has been identified, a risk mitigation plan should be developed. This is a plan to minimize and contain the impact of an unexpected event.

Risk can be grouped into different categories:

 

Communication and Consultation

Risk communication is a process that interacts bidirectionally with all other processes of risk management. Communication and consultation is an essential attribute of good risk management. Risk management cannot be controlled and managed in an isolated environment — it’s fundamentally communicative and consultative.

Good risk communication:

 

Monitoring and Review

This represents an ongoing process where security controls are monitored on an ongoing basis. Business requirements, vulnerabilities, and threats can change all the time. Monitoring and review can be both periodic and based on trigger events or changing circumstances.

In this sense, the key objectives of risk monitoring and review can include:

It is important to note that any updates, revisions, or modifications made to the Risk Management Process should be documented; and a version history kept as well.

 

Sources

[1] http://ki.pwr.edu.pl/kubiak/slides.pdf [2] http://resources.infosecinstitute.com/select-implement-effective-risk-management-standards-frameworks/ [3] https://en.wikipedia.org/wiki/IT_risk_management [4] https://wiki.en.it-processmaps.com/index.php/Risk_Management [5 ]https://iaonline.theiia.org/understanding-the-risk-management-process [6] https://en.wikipedia.org/wiki/IT_risk#Standards_organizations_and_standards [7] https://pm4id.org/chapter/11-2-risk-management-process/ [8] https://www.heflo.com/blog/risk-management/what-is-the-risk-management-process/

 


Article published in Infosec Institute by Pedro Tavares

Exit mobile version