Enterprise Risk
- Problems with immature technology
- Use of the wrong tools
- Software that is untested or fails to work properly, Requirement changes with no change management
- Failure to understand or account for product complexity
- Integration problems
- Software/hardware performance issues--poor response times, bugs, errors
- Inadequate resolution of priorities or conflicts
- Failure to designate authority to key people
- Insufficient communication or lack of communication plan,
- Size of transaction volumes--too great or too small
- Rollout and implementation risks--too much, too soon
- Access Control Administration
- Firewall Policy Administration
- Security Incident Detection
- Security Incident Response
- Security Policy Awareness
- Data Backup
- Data Recovery
- Threat & Vulnerability Monitoring and Management
- Virus Control
- Business disruption, the inability of the client to access business services
- Business failure, the inability of internal operations to process any business process
- Increase in software licensing cost, or unanticipated software licensing cost
- Increase in hardware-related expense or unanticipated hardware expense
- Hardware Software Integration or compatibility issues
- Network/LAN availability including general and secure access to file shares
- Personnel resource and availability, general attendance by consultants and internal employees
- Loss of key personnel due to illness, resignation or reassignment
- Change in market impacting fiscal viability of engagement
- Natural disaster such as flood or fire
Mature Cybersecurity Translates Monitored Enterprise Activities to Control Domains and Program Objectives
- Identify – CMDB, People, Process, Technology, relationships, alignment to controls
- Protect – Architecture, Infrastructure, Monitoring
- Detect – Defined Sources, Collection, Interpretation, Reporting Methods
- Respond – RCA, Corrective Action, Management Meetings, Plans, Optimization Targets
- Recover – Configuration baselines, response plans, lessons learned, documentation, BIA
Outputs of a functioning Cybersecurity & Enterprise Risk Management Process
- Threats are identified and categorized to risks
- Events are captured and reported
- Risks have context
- Risk Treatment provides for risk analysis
- Risk response plans - Treat risks
- Routine activities evaluate risk and their treatment
- Monitor and review
- Communicate and consult – GC committee
- Tools, Process, Measures, and Continuous Improvement
Looking for weaknesses and vulnerabilities is good but failing to adapt process and culture based on those findings is bad
- Phase II. Assess Cybersecurity and Business Risk
- Security Assessment
- Security assessment is comprehensive review of systems and applications performed by trained security professionals (CISSP/ CCIE/ CCNA/ CISM)
- Security assessments normally include use of testing tools and goes beyond automated scanning
- Involves thoughtful review of the threat environment, current and future risk, and value definition of the targeted environments
- The output of assessment is a report addressed to management with recommendations in both technical and non technical language
- Audit velocity increases resilience
- An approach: Find a flaw, fix a flaw
- Approach: Find a lot of flaws and keep a list
- Best approach: align vulnerability metrics into a continual service improvement model
Auditing Security Assessment & Verification
- Compliance checks
- Internal and external
- Frequency of review
- Standard of due care
Internal Audit typically performs an assessment for internal audience
External Audits are performed for external investors and as part of third-party due diligence requirements
Third Party review is emphasized to avoid “conflict of interest”
- At Moderate Maturity, GRC/ERM includes Incident Response and Continuous Improvement
- Phase II: Assess Cybersecurity and Business Risk
- Communicating Risk- Inputs and Agenda
- Execute – Program, Meetings, Risk Response
- Measure – Risk Measurement & Impact Analysis, Performance
- Record – Meeting Minutes, Management Reporting
- Archive – Meeting Minutes, KPI Results
- Enterprise Risk Management Can Start Small. To be effective you need a GRC.
- Phase II. Assessing Business Risk - Tools and Deliverables
RiskWatch is a free POC tool offered in our consulting practice. We use it to stage risk information that is implemented to fully functioning GRC products. It is not meant to take the place of the selected GRC tool.
- Significance of Risk – Analyze the Risks - So What?
- Risk analysis determines cadence + magnitude of events and their consequences.
- The significance of risk is consequence or impact on business objectives
- Consequence and likelihood may be accounted for using a qualitative, semi-qualitative or quantitative approach.
- The likelihood criteria are expressed as a probability of the annual occurrence on a descriptive scale from rare to almost certain. Impact is described on a scale from 1 insignificant to 5 catastrophic.
- Significance as a scale of 1 to 5 in Likelihood factored against a scale of 1 to 5 in Impact.
- On a scale of 1 to 25, the organization can establish criteria for action and a matrix of activity that would meet that criterion.
- Phase II Tool: Risk Heat Map
- Phase III. Develop Risk Response
- Responsibilities that must be adopted
- Phase III. Develop Risk Response
Key activities within this phase
- Determine appropriate risk response
- Key Outputs
Risk Management Action Plans
- Phase III. Develop Risk Response
- Risk Mitigation
- Phase III: we collectively define our risk appetite
- Risk management demonstrates a methodology and criteria
- Risk management provides evidence of the criteria behind our choices
- Corporate Risk Management Tools address
- Corporate level reviews company-specific risk
- Assignment of relative risk criteria
- Owner communicates risk to shareholders
- Governs how corporate leadership interprets & assigns weighted value
- Initial risk assessment & accountability rests at the individual company level
- Disclosure committee reviews & determines disclosure requirements
Risks and Response - Ongoing Risk Tracking
- respond
- report
- reduce
Technology Risk Tracking – by Service, Asset, Policy
- technology Controls Map
- report Classification
- key Vs. Non-Key
- definition of Terms and Controls
- Project Risk Management
- Facilitates the effective management of risk within an enterprise project
- Enables project team to collaborate in

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics