CH14-CompSec3e-IT Security Management
CH14-CompSec3e-IT Security Management
IT Security Management
and Risk Assessment
Formal process of answering the
questions:
Monitoring the
implementation
and operation
Determining Identifying and of safeguards Developing
organizational Determining analyzing Identifying that are and Detecting
Specifying
IT security organizationa security threats and necessary in implementing and
appropriate
objectives, l IT security to IT assets analyzing order to cost a security reacting to
safeguards effectively
strategies, and requirements within the risks awareness incidents
policies organization protect the program
information and
services within
the organization
Organizational
IT Security Policy
Aspects
Selection of Controls
Implementation
Follow-Up
Security
Maintenance
Compliance
Change Incident
Management Handling
Plan Check
Information
Security Do Managed
Needs Security
Judgments can be
made about
Some risks may be Skewed by analyst’s
vulnerabilities and risks
incorrectly assessed views, varies over time
that baseline approach
would not address
Assess using
formal Suitable for large
structured organizations
process with IT systems
•Number of stages critical to their
•Identify threats and business
vulnerabilities to assets
•Identify likelihood of objectives
risk occurring and
consequences
Combined Approach
Results in the development
of a strategic picture of the IT
resources and where major
risks are likely to occur
Highest cost
Determine Risk
• Risk appetite
o The level of risk the organization views as acceptable
Media Utilities Banking &
Finance
Asset
Anything that
might hinder or
prevent an asset
from providing
appropriate
levels of the key
security services
• Threats may be
o Natural “acts of God”
o Man-made
o Accidental or deliberate
•Motivation
•Capability
•Resources
•Probability of attack
•Deterrence
Uneconomic
so accept
Low
$ Cost of Treatment $$$$$
Not proceeding
Risk with the activity
or system that
avoidance creates this risk
Sharing
Risk responsibility for
the risk with a
transfer third party
Availability, integrity of
maintenance/production system