YOU ARE DOWNLOADING DOCUMENT

Please tick the box to continue:

Transcript
Page 1: Risk Management 101

Risk Management 101

Barry Caplin

Chief Information Security Officer

MN Department of Human Services

MN Government IT Symposium

Thurs. Dec. 13, 2007

Session 74

Page 2: Risk Management 101

Minnesota Office of the Legislative Auditor

Agenda

• In the beginning…

• Definitions – Threat, Vulnerability, Risk

• Types of Risk

• Risk Management components

• Frameworks and standards

• Information Risk Management at DHS

Page 3: Risk Management 101

In The Beginning…

Page 4: Risk Management 101

In The Beginning…

There were Humans…

Page 5: Risk Management 101

In The Beginning…

And Beasts…

Page 6: Risk Management 101

And the concept of Risk was born...

Page 7: Risk Management 101

Risk

• Always been with us• Viewed as a negative• Attempt to reduce

Page 8: Risk Management 101

Magic?

Page 9: Risk Management 101

Definitions

Page 10: Risk Management 101

Threat

Defn: Source or warning of probable impending danger (Actor) - wikipedia

• Direct/Intended – malicious hacker, thief, malware• Indirect/Unintended – user, weather• Person or Thing

Task: Must analyze assets and environment to determine threats

Page 11: Risk Management 101

Vulnerability

Defn: the state of being exposed; liable to succumb – dictionary.com

• Measures – physical, financial, operational

Task: Must analyze vulnerability to identified threats

Page 12: Risk Management 101

Impact

Defn: to effect, influence or alter – dictionary.com

• Measures – cost, time delays, damage

Task: determine impact of action of threat to which we are vulnerable

Page 13: Risk Management 101

Threat, Vulnerability, Impact => Risk

(probability of event × impact = risk)

Page 14: Risk Management 101

Risk

Defn: Exposure to the chance of injury or loss (Event) – dictionary.com

• Based on action of threat• Components:

– Probability of occurrence– Impact of event

Task: Identification and Disposition• Accept (or Ignore)• Mitigate• Transfer

Page 15: Risk Management 101

Types of Risk

Prof. John Adams, University College LondonUK risk expert

• Direct – directly perceived – obvious• Scientific – determined via science• Virtual Risk – everything else!

Page 16: Risk Management 101

Directly perceived

Page 17: Risk Management 101

Types of Risk

Perceived through science

Page 18: Risk Management 101

Types of Risk

Virtual Risk• What we are all involved in!• Project risk/Operational risk• Physical/Data security risk• Terrorism/Homeland Security• Weather

Page 19: Risk Management 101

Virtual Risk

Virtual Risk• Difficult to “prove”• Experts don’t know or do not agree• We don’t know what we don’t know

Page 20: Risk Management 101

Risk Management

A discipline for living with the possibility that future events may cause adverse effects.

http://www.sei.cmu.edu/risk/index.html

Page 21: Risk Management 101

Risk Management

The iterative framework and processes for:

• Identifying threats (imagining virtual threats)

• Assessing• Evaluating options• Acting.

Page 22: Risk Management 101

Identify Threats

• Research• Survey• Brainstorm

Page 23: Risk Management 101

Assess

• Threat Assessment• Vulnerability Assessment• Impact Assessment• Risk Assessment

• Qualitative – subjective scoring• Quantitative – objective or measured values

Page 24: Risk Management 101

Disposition of Risk

• Accept (or Ignore) – what is the?• Mitigate – what is the cost?• Transfer – via contract or insurance – what

terms? Cost?

Page 25: Risk Management 101

Economics of Risk Management

1. Cost of control < Cost of loss

2. Cost of compliance (pain) <Cost of circumvention (gain)

Page 26: Risk Management 101

Ineffective Risk Mitigation

Page 27: Risk Management 101

Evaluate and Act

• Risk Management Committee or SMT• Document decisions

• Get it done!

Page 28: Risk Management 101

Frameworks for Risk Management

• CarnegieMellon (CMU SEI) – software• NIST/FISMA – information systems• CRESP – Consortium for Risk Evaluation with

Stakeholder Participation - nuclear• COSO – Committee Of Sponsoring Organizations – info

systems• COBIT – Control Objectives for IT• SOMAP – Security Officers Management & Analysis

Project – Open Information Security RM Handbook• OCTAVE - Operationally Critical Threat, Asset, and

Vulnerability Evaluation• Commercial - many

Page 29: Risk Management 101

Treasury Board of Canada

Integrated Risk Management Framework – 2001

• “Risk-Smart” Workforce and Environment• 4 Elements:

– Develop Risk Profile– Establish organizational function– Practice and integrate– Ensure continuous learning

http://www.tbs-sct.gc.ca/pubs_pol/dcgpubs/riskmanagement/rmf-cgr01-1_e.asp

Page 30: Risk Management 101

Security and Risk Management

• Security is a subset of Risk Management• RM -> Security Solutions -> Compliance• Security/Business balance• Act on appropriate risks• Consider the “costs”

Page 31: Risk Management 101

At DHS

Information Risk Management at DHS• Based on elements of NIST, COBIT and

OCTAVE• SLM – Security Lifecycle Management• Information Policy, Awareness and

Compliance• Business Continuity Planning

Page 32: Risk Management 101

Resources

Information Risk Management at DHS• CMU SEI – www.sei.cmu.edu/risk• COBIT – www.isaca.org/cobit• COSO – www.coso.org• CRESP – www.cresp.org• NIST/FISMA – csrc.nist.gov• SOMAP – www.somap.org• OCTAVE – www.cert.org/octave• Prof. John Adams – john-adams.co.uk

Page 33: Risk Management 101

Discussion?


Related Documents