2 Risk Management
This chapter covers
- Risk management terminology
- Overview of the Risk management process
- Risk management methodologies
- Strategies for prioritizing risk
In the previous chapter, we learned that assets (i.e., resources such as data, systems, or physical equipment) can be vulnerable, meaning they may be susceptible to harm or attack. The primary objective of cybersecurity is to protect these assets from threats by selecting and implementing appropriate security measures, referred to as security controls. We also learned that assets have distinct value and importance, which is called sensitivity when discussing data assets.
Any organization that sets out to implement security measures, or security controls, quickly encounters fundamental constraints. First, the number of assets (resources at risk) is large, exposing numerous vulnerabilities (weaknesses that could be exploited). Security controls are not foolproof because threats (potential causes of harm) continuously evolve. Resources, both financial and human, are limited. As a result, implementing the full range of security controls across all assets is not feasible in practice.