It seems that you are unregistered. Please register with us by clicking Here, or if you are already registered login here
User Name: Password:
Urdu Poetry/Shayari Forum

Urdu Poetry Forum

Welcome to Urdu Community & Poetry/Shayari Forum

 


Risk Analysis: Things to Consider When Working Out How Much Risk We Carry

This is a discussion on Risk Analysis: Things to Consider When Working Out How Much Risk We Carry within the Information Technology forums, part of the Education & Learning category; Risk Analysis: Things to Consider When Working Out How Much Risk We Carry In the Information age upon us, understanding ...


Go Back   Urdu Poetry/Shayari Forum > Welcome To HallaGulla - Urdu Poetry Forum > Education & Learning > Information Technology

Video Photo Books Games Sites Register Groups FAQ Calendar Mark Forums Read Chat [8]

Notices

Rate This Thread - Risk Analysis: Things to Consider When Working Out How Much Risk We Carry.
(0)
Thread Rating: 0 votes, average.

Reply
 
Thread Tools
  #1  
Old 09-07-2008, 01:31 AM
Revolutionist's Avatar
Back To Square One!
 
Join Date: Feb 2008
Location: Beyond Wonderland!
Age: 21
Posts: 7,740

Country:

Tutorials: 2

My Mood:
Thanks: 2,114
Thanked 1,511 Times in 976 Posts
Nominated 1 Time in 1 Post
TOTW/F/M Award(s): 0
Rep Power: 1213
Revolutionist has a reputation beyond reputeRevolutionist has a reputation beyond reputeRevolutionist has a reputation beyond reputeRevolutionist has a reputation beyond reputeRevolutionist has a reputation beyond reputeRevolutionist has a reputation beyond reputeRevolutionist has a reputation beyond reputeRevolutionist has a reputation beyond reputeRevolutionist has a reputation beyond reputeRevolutionist has a reputation beyond reputeRevolutionist has a reputation beyond repute
Exclamation Risk Analysis: Things to Consider When Working Out How Much Risk We Carry

Risk Analysis: Things to Consider When Working Out How Much Risk We Carry

In the Information age upon us, understanding risk is an important element in deciding on the protection mechanism selected to protect information. Information security professionals are challenged with management of assets and other obstacles that make it difficult to implement the appropriate controls. This article will focus on the framework that will help justify the appropriate controls.

No risk can be completely removed. Usually, risks can only be reduced and controls implemented to mitigate the loss of such events.

There are two types of risk analysis in the information security arena, namely quantitative risk analysis and qualitative risk analysis. Quantitative risk analysis, quantifies risk, this means that the risk is given a value and the results are completely based on facts and figures. Qualitative risk analysis is based on subjective information, the result is a feeling of how vulnerable or how high the risk may be. The difference between the two methods is fact and opinion. However, most analysis is based on the opinion, or qualitative, version of the analysis.

Risk and the calculations

When calculating risk, it is useful to understand what the cost of the asset you are trying to protect is. When it comes to a vast business asset like data, only experienced risk assessors can quantify the cost of the asset. This requires input from various parts of the business, if the data is spread business wide. Data has always been a difficult asset to assess and quantify, for this reason consider the following…

Note:
The cost of the data is not only the measured by the impact the data will have on the business if the data was not available but their is also a cost to maintain, reproduce and reconstruct back to the same level as before the loss. Therefore all of these factors should be considered.

The formulas to calculate the value of the data can be highly complex and difficult to understand and quantify.

Let’s take an example of data stored on your mobile phone, and work on a simple calculation to calculate the value of the data, against the risk of loss.

A mobile phone that costs $500 with the operating system, has approximately 5 other payware applications loaded at a cost of $300 (software like GPS, viewers, backup tools, etc). The time it takes to load the software can be calculated at about half a day, for argument’s sake let’s say this will cost $100. The time it takes to configure the mobile phone and capture all of the contacts and information costs $100. The total cost of the asset plus the device cost is $1,000. The impact of the user not being able to access the device will cost $400; this is because the user will need to spend time reloading software, coupled with the other time lost whilst the device was offline.

The mechanism to protect the data asset could be defined as a piece of software or hardware in the form of a backup device or a replica of the software in some other form.

So how do we calculate risk?

Calculating the eventuality is the key to calculating risk. We are meant to learn from our history and in this spirit we should look at the frequency of each threat agent. Threat agents manifest themselves in many forms, below are a few examples.

Threat agents

There are various threat agents to consider when calculating risk. Here is a list, which is by no means comprehensive, but which will give you an idea of what is out there.
* Natural Disasters
* Fire
* Floods
* Freezing
* Heat
* Manmade threats
* Virus
* Malware
* Spyware
* Trojans
* Worms
* And many other similar issues

Calculations

There are multiple calculations that can be performed to quantify risk. A simple calculation is Risk = Probability of the Risk X Cost of the Eventuality.

Single Loss Expectancy (SLE) = Asset Value (AV) X Exposure Factor (EF)

Once you have calculated this you can use the following formula,

Annual Loss Expectancy (ALE) = Single Loss Expectancy (SLE) * Annual Rate of Occurrence (AR

For more information you can read Risk Assessment and Threat Identification.

Managing Risk

There are many ways to manage risk, in many cases the risks are countered by implementing a control that reduces or limits the risk, for example, to reduce the risk of fire a fire alarm and flame retardant system is installed.

Tips from the trade

When limiting the risks, remember to isolate the asset that you are protecting. If you isolate the asset when you apply the control you will find that more cost-effective than applying the control to the whole environment. It might make more sense to remove the vulnerable asset from the environment; this will in turn lessen the risk.

Controls

When managing risk, it is important to understand what the countermeasure to risk is. These come in the form of a controls, either a technical or administrative control is implemented as countermeasure.

Technical controls

These are controls types that can be installed and applied to mitigate the risks. Controls like Antivirus, backups, Encryption, Access Controls, hardware and software controls.

Logical controls are also known as technical controls. The best approach is to implement the mode of least privilege this will ensure that only the legitimate users or subjects have access to the asset in question.

Physical

Physical controls are controls that can be implemented physically to control the access to the assets, things like locks, burglar bars, cameras, barricades, fencing, security guards and dogs are good examples of physical controls. Separation of duties forms an important part of the physical controls as this is a soft part of the control.

Administrative controls

These are controls that are written like policy and standards, which are implemented to reduce the risk. Examples are security policies and such documents.

Things to consider

When analysing the risks you should always consider the input that the client has into the process. This input is often an opinion and has little bearing on the situation unless it is properly understood and filtered by an experienced risk analyst. All information should always be verified as it is easy for the client to influence the results by responding to the questions is a specific way; this is why the assessor should be accredited and experienced in the field of risk.

On many occasions the assessors that I meet have little knowledge on risk profile and how risk analysis should be performed. Typically the assessors are young folk just out of college with little experience and are only following a framework handed to them by the organisation that is consulting the client. These frameworks are designed to identify the risks if filled out correctly, but in many cases the customers being interviewed can easily change the result by carefully crafting their response. This nullifies the response and the risks are not clearly identified and the correct countermeasures are not implemented.

Data classification is something that is becoming a more common control, this is a good example of a soft control that is both logical and administrative and that can help in reducing risk as it allows the organisation to protect only sensitive data and not all data. In this way, the cost of the solution is greatly reduced as only the sensitive data is protected.

Summary
In this article we went through risk calculations and the types of controls that can be implemented. Understanding the basics around risk and the assessment mechanisms will help in defining countermeasures and controls. As a wise man once said it’s better to be two years early than one day too late.
__________________
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Submit to Yahoo!Submit to Google!Submit to Live!Submit to Facebook!Submit to Ask!Submit to StumbleUpon!Submit to Squidoo Submit to Netscape Submit to SlashDot Submit to Reddit Submit to FarkSubmit to Newsvine
Reply With Quote
The Following User Says Thank You to Revolutionist For This Useful Post:
Pink-Angel (09-07-2008)
Reply

Tags
calculations, risk, security

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
HR = High Risk sakm2010 Academic Learning 3 04-17-2008 10:57 AM
@ Ur Risk ...... LOLz *AA* Jokes n Jokes 12 09-13-2007 05:51 PM
Hr=high Risk Gumshudakoihowa Jokes n Jokes 3 07-18-2006 03:38 PM
Risk-e-Hilal sifi_tanhai Islam & Muslim Ummat 4 02-24-2006 02:15 PM
! Risk It ! CrazySam Write-Up's in English 3 01-17-2005 04:36 PM

Urdu Poetry Forum RSS Feed One of the largest message boards on the web ! Photo Gallery RSS Feed

eXTReMe Tracker


All times are GMT +1. The time now is 12:28 PM.


Copyrights: All rights reserved.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 381 382 383 384 385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 447 448 449 450 451 452 453 454 455 456 457 458 459 460 461 462 463 464 465 466 467 468 469 470 471 472 473 474 475 476 477 478 479 480 481 482 483 484 485 486 487 488 489 490 491 492 493 494 495 496 497 498 499 500 501 502 503 504 505 506 507 508 509 510 511 512 513 514 515 516 517 518 519 520 521 522 523 524 525 526 527 528 529 530 531 532 533 534 535 536 537 538 539 540 541 542 543 544 545 546 547 548 549 550 551 552 553 554 555 556 557 558 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 599 600 601 602 603 604 605 606 607 608 609 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 650 651 652 653 654 655 656 657 658 659 660 661 662 663 664 665 666 667 668 669 670 671 672 673 674 675 676 677 678 679 680 681 682 683 684 685 686 687 688 689 690 691 692 693 694 695 696 697 698 699 700 701 702 703 704 705 706 707 708 709 710 711 712 713 714 715 716 717 718 719 720 721 722 723 724 725 726 727 728 729 730 731 732 733 734 735 736 737 738 739 740 741 742 743 744 745 746 747 748 749 750 751 752 753 754 755 756 757 758 759 760 761 762 763 764 765 766 767 768 769 770 771 772 773 774 775 776 777 778 779 780 781 782 783 784 785 786 787 788 789 790 791 792 793 794 795 796 797 798 799 800 801 802 803 804 805 806 807 808 809 810 811 812 813 814 815 816 817 818 819 820 821 822 823 824 825 826 827 828 829 830 831 832 833 834 835 836 837 838 839