chapter two

2 Risk Management

 

This chapter covers

  • Risk management terminology
  • Overview of the Risk management process
  • Risk management methodologies
  • Strategies for prioritizing risk

In the previous chapter, we learned that assets (i.e., resources such as data, systems, or physical equipment) can be vulnerable, meaning they may be susceptible to harm or attack. The primary objective of cybersecurity is to protect these assets from threats by selecting and implementing appropriate security measures, referred to as security controls. We also learned that assets have distinct value and importance, which is called sensitivity when discussing data assets.

Any organization that sets out to implement security measures, or security controls, quickly encounters fundamental constraints. First, the number of assets (resources at risk) is large, exposing numerous vulnerabilities (weaknesses that could be exploited). Security controls are not foolproof because threats (potential causes of harm) continuously evolve. Resources, both financial and human, are limited. As a result, implementing the full range of security controls across all assets is not feasible in practice.

2.1 Understanding Risk

2.1.1 Impact

2.1.2 Likelihood

2.1.3 The Definition of Risk

2.2 Risk Management

2.2.1 Risk Management Process Overview

2.2.2 Risk Assessment

2.2.3 Risk Treatment

2.3 Closing Thoughts

2.4 Summary

2.5 Review Questions

2.6 Answers to Review Questions