Download presentation
Presentation is loading. Please wait.
Published byUtami Hartanto Modified over 5 years ago
1
Information Security Risks; All-in-One Terminology
2
Information Security Risk Management Lifecycle with some Basic Elements
(controls)
3
Qualitative Risk Analysis (Nitel Risk Analizi)
Generally used in Information Security Hard to make meaningful valuations and meaningful probabilities Relative ordering is faster and more important Many approaches to performing qualitative risk analysis Same basic steps as quantitative analysis Still identifying asserts, threats, vulnerabilities, and controls Just evaluating importance differently 3
4
Qual. Risk Analysis in 10 steps
Step 1: Identify Scope Bound the problem Step 2: Assemble team Include subject matter experts, management in charge of implementing, users Step 3: Identify Threats Pick from lists of known threats Brainstorm new threats Mixing threats and vulnerabilities here... 4
5
Step 4: Threat prioritization
Prioritize threats for each assert Likelihood of occurrence (note that this is likelihood because it is not a statistical probability value) Define a fixed threat rating E.g., Low(1) … High(5) Associate a rating with each threat Note: Approximation to the risk probability in quantitative approach 5
6
Step 5: Loss Impact With each threat determine loss impact
Define a fixed ranking E.g., Low(1) … High(5) Used to prioritize damage to asset from threat 6
7
Step 6: Total impact 6 3 2 Theft 10 5 Water 15 Fire Risk Factor
Example 2: Another alternative method, where the scaled qualitative values are multiplied) 6 3 2 Theft 10 5 Water 15 Fire Risk Factor Impact Priority Threat Priority Threat 7
8
Step 7: Identify Controls/Safeguards
Potentially come into the analysis with an initial set of possible controls Associate controls with each threat Starting with high priority risks Do cost-benefits and coverage analysis (Step 8) Rank controls (Step 9) 8
9
Step 8: Safeguard (Control) Evaluation
Step 9: Rank these Controls ! 9
10
Step 10: Communicate Results
Most risk analysis projects result in a written report Generally not read Make a good executive summary Beneficial to track decisions. Real communication done in meetings an presentations 10
11
Another Qualitative Inf. Sec
Another Qualitative Inf. Sec. Risk Assessment Example (by multiplying the scaled values)
Similar presentations
© 2024 SlidePlayer.com. Inc.
All rights reserved.