Top Banner
Risk Management 101 Barry Caplin Chief Information Security Officer MN Department of Human Services MN Government IT Symposium Thurs. Dec. 13, 2007 Session 74
33
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Risk Management 101

Risk Management 101

Barry Caplin

Chief Information Security Officer

MN Department of Human Services

MN Government IT Symposium

Thurs. Dec. 13, 2007

Session 74

Page 2: Risk Management 101

Minnesota Office of the Legislative Auditor

Agenda

• In the beginning…

• Definitions – Threat, Vulnerability, Risk

• Types of Risk

• Risk Management components

• Frameworks and standards

• Information Risk Management at DHS

Page 3: Risk Management 101

In The Beginning…

Page 4: Risk Management 101

In The Beginning…

There were Humans…

Page 5: Risk Management 101

In The Beginning…

And Beasts…

Page 6: Risk Management 101

And the concept of Risk was born...

Page 7: Risk Management 101

Risk

• Always been with us• Viewed as a negative• Attempt to reduce

Page 8: Risk Management 101

Magic?

Page 9: Risk Management 101

Definitions

Page 10: Risk Management 101

Threat

Defn: Source or warning of probable impending danger (Actor) - wikipedia

• Direct/Intended – malicious hacker, thief, malware• Indirect/Unintended – user, weather• Person or Thing

Task: Must analyze assets and environment to determine threats

Page 11: Risk Management 101

Vulnerability

Defn: the state of being exposed; liable to succumb – dictionary.com

• Measures – physical, financial, operational

Task: Must analyze vulnerability to identified threats

Page 12: Risk Management 101

Impact

Defn: to effect, influence or alter – dictionary.com

• Measures – cost, time delays, damage

Task: determine impact of action of threat to which we are vulnerable

Page 13: Risk Management 101

Threat, Vulnerability, Impact => Risk

(probability of event × impact = risk)

Page 14: Risk Management 101

Risk

Defn: Exposure to the chance of injury or loss (Event) – dictionary.com

• Based on action of threat• Components:

– Probability of occurrence– Impact of event

Task: Identification and Disposition• Accept (or Ignore)• Mitigate• Transfer

Page 15: Risk Management 101

Types of Risk

Prof. John Adams, University College LondonUK risk expert

• Direct – directly perceived – obvious• Scientific – determined via science• Virtual Risk – everything else!

Page 16: Risk Management 101

Directly perceived

Page 17: Risk Management 101

Types of Risk

Perceived through science

Page 18: Risk Management 101

Types of Risk

Virtual Risk• What we are all involved in!• Project risk/Operational risk• Physical/Data security risk• Terrorism/Homeland Security• Weather

Page 19: Risk Management 101

Virtual Risk

Virtual Risk• Difficult to “prove”• Experts don’t know or do not agree• We don’t know what we don’t know

Page 20: Risk Management 101

Risk Management

A discipline for living with the possibility that future events may cause adverse effects.

http://www.sei.cmu.edu/risk/index.html

Page 21: Risk Management 101

Risk Management

The iterative framework and processes for:

• Identifying threats (imagining virtual threats)

• Assessing• Evaluating options• Acting.

Page 22: Risk Management 101

Identify Threats

• Research• Survey• Brainstorm

Page 23: Risk Management 101

Assess

• Threat Assessment• Vulnerability Assessment• Impact Assessment• Risk Assessment

• Qualitative – subjective scoring• Quantitative – objective or measured values

Page 24: Risk Management 101

Disposition of Risk

• Accept (or Ignore) – what is the?• Mitigate – what is the cost?• Transfer – via contract or insurance – what

terms? Cost?

Page 25: Risk Management 101

Economics of Risk Management

1. Cost of control < Cost of loss

2. Cost of compliance (pain) <Cost of circumvention (gain)

Page 26: Risk Management 101

Ineffective Risk Mitigation

Page 27: Risk Management 101

Evaluate and Act

• Risk Management Committee or SMT• Document decisions

• Get it done!

Page 28: Risk Management 101

Frameworks for Risk Management

• CarnegieMellon (CMU SEI) – software• NIST/FISMA – information systems• CRESP – Consortium for Risk Evaluation with

Stakeholder Participation - nuclear• COSO – Committee Of Sponsoring Organizations – info

systems• COBIT – Control Objectives for IT• SOMAP – Security Officers Management & Analysis

Project – Open Information Security RM Handbook• OCTAVE - Operationally Critical Threat, Asset, and

Vulnerability Evaluation• Commercial - many

Page 29: Risk Management 101

Treasury Board of Canada

Integrated Risk Management Framework – 2001

• “Risk-Smart” Workforce and Environment• 4 Elements:

– Develop Risk Profile– Establish organizational function– Practice and integrate– Ensure continuous learning

http://www.tbs-sct.gc.ca/pubs_pol/dcgpubs/riskmanagement/rmf-cgr01-1_e.asp

Page 30: Risk Management 101

Security and Risk Management

• Security is a subset of Risk Management• RM -> Security Solutions -> Compliance• Security/Business balance• Act on appropriate risks• Consider the “costs”

Page 31: Risk Management 101

At DHS

Information Risk Management at DHS• Based on elements of NIST, COBIT and

OCTAVE• SLM – Security Lifecycle Management• Information Policy, Awareness and

Compliance• Business Continuity Planning

Page 32: Risk Management 101

Resources

Information Risk Management at DHS• CMU SEI – www.sei.cmu.edu/risk• COBIT – www.isaca.org/cobit• COSO – www.coso.org• CRESP – www.cresp.org• NIST/FISMA – csrc.nist.gov• SOMAP – www.somap.org• OCTAVE – www.cert.org/octave• Prof. John Adams – john-adams.co.uk

Page 33: Risk Management 101

Discussion?