Security + Exam Guide (Charles River Media Networking/Security)

 < Day Day Up > 


Risk/Threat Identification

Risk management is the process or processes that a company or enterprise implements in order to reduce loss of assets or financial standings that can result from theft, accidents, or lack of proper management Due Care and responsibility. In simple terms, risk management focuses on the reduction of threats to a company's assets. For more specific network and security related study needs, it can be said that risk management focuses on the implementation of information security practices in order to identify possible hardware/software threats and vulnerabilities that exist both inside and outside of an organization.

In order to prevent or offset risk and the possible financial losses that exist if proper prevention methods are not put in place, one must identify what real risks and threats exist, know what assets are at risk, and analyze what, if any, controls should be put into place to avoid loss. Identifying risks includes the following:

Knowing if the event or disaster will reoccur and at what frequency.

Risks can be categorized or isolated to give you a better understanding of how to identify them. The following are categories of risks or threats that could possibly exist:

After you have identified all risks that present a threat to your security, it is important that you evaluate what systems, people, and other assets are vulnerable to these risks. Once vulnerabilities are identified, a control process can be implemented. Once again, the type of controls, insurance, and safeguards are all determined by the mighty dollar.

Management buy-in concerning the protection of an organization against threat is a must.

Risk Analysis/Assessment

Risk analysis includes identifying important assets and identifying possible risks to these assets. Risk analysis also includes implementing safeguards to prevent or offset the risks or threats that exist.

There are three major items you should be familiar with when preparing a risk analysis. You should be able to estimate the possible losses that could occur, analyze/assess potential risks, and be able to produce an Annualized Loss Expectancy report (ALE). In order to produce an annualized loss expectancy figure, and for the exam, you should know the following:

In order to produce an ALE, you must multiply the SLE by the ARO.

Note 

ALE = SLE ï ARO. You should know this formula for the exam.

The ALE should include a list of all assets, all possible threats, the potential for threats, the financial and physical loss that can occur from these threats, and recommended remedies to reduce the risk potential.

There are several types or approaches of risk analysis that you should familiar with for the exam. They are as follows:


 < Day Day Up > 

Категории