Analyzing Risk: Analyze Organizational Risk Analyze The Business Impact of Risk
Analyzing Risk: Analyze Organizational Risk Analyze The Business Impact of Risk
Analyzing Risk: Analyze Organizational Risk Analyze The Business Impact of Risk
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 1
Risk Management
Assessmen
t
Mitigation Analysis
Response
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 2
Components of Risk Analysis
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 3
Phases of Risk Analysis
Risk analysis: The process used for assessing risk damages that can affect
an organization.
11 22 33
44 55 66
Probability Impact Countermeasure
Quantification Analysis Determination
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 4
Categories of Threat Types
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 5
Risk Analysis Methods
Method Description
• Uses descriptions and words to measure the amount and impact of risk,
such as High, Medium, and Low.
Qualitative
• Usually scenario-based.
• Can be subjective and hard to test.
• Based on solely numeric values.
Quantitative • Risk data is compared to historic records, experiences, industry best
practices, statistical theories, and tests.
• Uses descriptions and numeric values.
Semi-quantitative • Attempts to find middle ground between qualitative and quantitative
risk analysis.
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 6
Risk Calculation
Risk of Impact
Vulnerability Identification Occurrence Estimate (US Mitigation
Source
(1/Low; 5/High) Dollars)
Physical adjustments
Flood damage Physical plant 5 $950,000
and flood insurance
Generator,
Electrical failure Physical plant 2 $100,000 Uninterruptible power
supply (UPS)
Flu epidemic Personnel 4 $200,000 Flu shots
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 7
Risk Response Techniques
Response
Technique Description
• Acknowledgement of the risk and consequences that come with it.
Accept • Acceptance does not mean leaving a system completely vulnerable.
• Acceptance is recognizing that the risk involved is not entirely avoidable
or the cost of mitigation or avoidance is prohibitive.
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 8
Risk Mitigation and Control Types
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 9
Change Management
• New service pack fixes several security vulnerabilities for a production server.
• Server hosts a custom app that must remain available.
• Change management policy requires form approval for all service packs.
• The new service pack must be tested on a lab server prior to deployment.
• Test results indicate the service pack crashes the custom app.
• The custom app must be revised and retested before the service pack is deployed to the
production server.
Service Service
Pack Pack
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 11
Guidelines for Analyzing Risk
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 12
Activity: Analyzing Risks to the Organization
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 13
BIA
BIA
Probability
Probability of
of Effect
Effect of
of financial
financial
reduced efficiency
reduced efficiency loss
loss
Resources
Resources needed
needed
to
to restore
restore
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 14
Impact Scenarios
Impact Description
Natural disasters and intentional man-made attacks.
• Severe weather events
Life • Seismic events
• Arson and other fires
• Terrorist attack
Natural disasters and intentional man-made attacks:
• Severe weather events
• Seismic events
Property • Arson and other fires
• Terrorist attacks
• Break-ins
• Equipment damage
Natural disasters, intentional man-made attacks, and unintentional man-
made risks.
• Severe weather events
Safety • Seismic events
• Arson
• Terrorist attacks
• Excessive employee illnesses or epidemics
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 15
Impact Scenarios (Cont.)
Impact Description
Natural disasters, intentional man-made attacks, unintentional man-made
risks, and system risks:
• Severe weather events
• Seismic events
• Arson and other fires
• Terrorist attacks
• Break-ins
• Theft
Finance • Equipment damage
• File destruction
• Information disclosure (intentional or inadvertent)
• User error
• Social networking and cloud computing
• Excessive employee illnesses or epidemics
• Unsecure mobile and networking devices
• Unstable virtualization environments
• Email and account-management vulnerabilities
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 16
Impact Scenarios (Cont.)
Impact Description
Man-made risks and system risks.
• Response time for restoration of disrupted services or damaged files
• Frequent information disclosure
• Perception of recurring problems
Reputation
• Perception of susceptibility
Organizational response to risks:
• Price gouging during natural disasters
• Response time for addressing information disclosure
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 17
Privacy Assessments
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 18
Critical Systems and Functions
• Mission-essential
• Quantitative comparison
• MTD: Maximum tolerable downtime
• MTTF: Mean time to failure
• MTTR: Mean time to repair/replace
• MTBF: Mean time between failures
• RTO: Recovery time objective
• RPO: Recovery point objective
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 19
Maximum Tolerable Downtime
The longest time period that a business outage can occur without
causing irrecoverable business failure.
Event
Event MTD
MTD
Business Failure
Time
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 20
Recovery Point Objective
The longest period of time that an organization can tolerate lost data
being unrecoverable.
RPO
RPO Event
Event MTD
MTD
Time
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 21
Recovery Time Objective
RPO
RPO Event
Event RTO
RTO MTD
MTD
Time
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 22
Mean Time to Failure
Event MTTF
MTTF Event
Event Event
Time
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 23
Mean Time to Repair
• Less than RPO when the component is relevant to the recovery effort.
• Also referred to as mean time to recover (or replace).
RPO
RPO Event
Event RTO
RTO MTD
MTD
MTTR
MTTR
Time
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 24
Mean Time Between Failures
• Measure of reliability.
• Can indicate need for redundancy measures.
• MTBF = MTTF + MTTR
Reliability
MTBF
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 25
Guidelines for Performing a Business Impact Analysis
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 26
Activity: Performing a Business Impact Analysis
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 27
Reflective Questions
1. What types of risk does your organization face, and what methods would
you use to analyze those risks?
2. If you were developing a BIA for your organization, what types of systems
and functions would you deem essential to operations? Why?
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 28