Part Two: dealing with risk – Risk Management and Risk Assessment.
Part Two: dealing with risk – Risk Management and Risk Assessment.
This section can be divided into two categories: risk management and assessment. Both categories are equally important and should not be overlooked.
Risk Assessment-
Security gaps all have one thing in common: lack of visibility. Simply put, you can’t protect what you can’t see. A cyber risk assessment equals visibility and visibility equals trust.
risk Assessment process.-
1. Identify assets – which mission-critical devices need to be protected? Software, Hardware, Data, End-users, IT security policies, Network, Physical equipment
2. Identify threats- how can assets be attacked?
3. Identify consequences- impact analysis to determine the worst-case scenario and the fallout
4. Identify solutions. what solutions can best deter or prevent the threats? Make an action plan.
5. implement the solutions and monitor the effects- have the threats been eliminated? If not start again.
Risk assessment is an ongoing process that involves identifying, analyzing, evaluating, and addressing an organization’s cybersecurity threats. It is important to note that this process is continuous, meaning it is not a one-time solution that can be implemented and then forgotten. Cybersecurity risk management is a constantly evolving process that should grow and change along with your business.
Risk Management –
Every organization has to make difficult decisions about how much time and money to spend protecting their technology and services. One of the main goals of cyber risk management is to inform and improve these decisions. Broadly speaking, the cybersecurity risk management process involves six stages:
1. Identify the risks that might compromise your cyber security. This usually involves identifying cyber security vulnerabilities in your system and the threats that might exploit them.
2. Analyse the severity of each risk by assessing how likely it is to occur and how significant the impact might be if it does.
Evaluate how each risk fits within your risk appetite (your predetermined level of acceptable risk).
3. Prioritise the risks.
4. Decide how to respond to each risk. There are generally four options:
Treat – modify the risk’s likelihood and/or impact typically by implementing security controls.
Tolerate – make an active decision to retain the risk (e.g., it falls within the established risk acceptance criteria).
Terminate – avoid the risk entirely by ending or completely changing the activity causing the risk.
Transfer – share the risk with another party, usually by outsourcing or taking out insurance.
5. Since cyber risk management is a continual process, monitor your risks to ensure they are still acceptable, review your controls to ensure they are still fit for purpose, and make changes as required. Remember that your risks continually change as the cyber threat landscape evolves, and your systems and activities change.
Next, we’ll cover – Implementing effective cybersecurity measures