Information Security Blog

Risk Assessments are a lot like a bikini

When I first became an Information Security Auditor I was inspired by the “rightness” of the mythical concept of “Return on Security Investment” (ROSI). Quantitative Risk Assessment drives risk quantification which drives controls that reduce risk by a quantifiable amount making a return on security investment calculable and the world is right.

Fast forward to today. Calculating ROSI is something I haven’t attempted in years, and I will admit to being jaded about Information Technology/Security Risk Assessments. We have tried tool based approaches, NIST 800-30, Octave, Octave-S, our own, and customer proprietary methodologies; all with limited success. I’m not suggesting that the fundamental concept of understanding risks is not important to determining which controls are most critical, rather, we (as a community) have not figured out the right way to understand/qualify/quantify/communicate our risks.

At this point Risk Assessments are a lot like a bikini; “What they reveal is suggestive, but what they conceal is vital”. Worse, it’s easy (and common) to make what they reveal what you want them to reveal.

With the growing acceptance of ISO27001 (something that I believe will be good in the long run) Risk Assessment is once again front and center, as it is integral to the ISO27001 Information Security Management System (ISMS). I suspect that there will be renewed focus on improving prevailing methodologies to make them easier to leverage and yield more consistent/standardized results across different organizations.

Interesting, and concurrently, the growing trend towards government involvement and litigation relating to Identity Theft (http://wistechnology.com/articles/5446/) (http://www.ftc.gov/opa/2009/02/compgeeks.shtm) makes risk relating to Personally Identifiable Information (PII) disclosure notably higher. This has the effect of making it easier to rationalize security investment. Another data point supporting this thought is the most recent Ponemon Institute “Annual Cost of a Data Breach Study”.

At $202 per name for a PII Data Breach, the risk associated with inadvertent disclosure of a half-million names makes it easy to demonstrate a ROSI for a Security Certification & Accreditation program. Oddly, this both reduces the need for, and increases the importance of, Risk Assessment at the same time. Life never gets boring …



Free Whitepaper: Five Best Practices for SIEM

siem-whitepaper

The promise of SIEM is the consolidation of all relevant Security Event Logs from disparate sources into a single unified and normalized data store.

Free Whitepaper: Stop Wasting Money on Penetration Testing

penetration-testing-whitepaper

Penetration Testing is most frequently performed to:

  • Substantiate the net effectiveness of a mature control environment
  • Prove to a third party that an environment is secure/trustworthy
  • Quickly assess the security of a less mature control environment (in a sense a technical risk assessment)
  • To validate that significant changes did not have unanticipated results

Free Download: ISO 27001 Implementation Roadmap

ISO 27001 RoadmapHave no fear – our “roadmap” will guide you, step by step, through the entire ISO 27001 process.

Getting to ISO 27001 certification is a process made up of things you already know – and things you may already be doing!

Free Download: A Best Practices Guide to Database Security

database security roadmap

Because data is only as secure as the systems & processes it relies on – a holistic approach to data security is essential. This roadmap is not meant to be exhaustive but rather to stimulate the necessary thought process to put you on the path to good data security.

Is ISO 27001 Right for (Y)our Organization?

iso-27001-webinar

Thinking about ISO 27001 Certification? View our free On-Demand ISO 27001 Webinar

  • How to deal with increasing threats
  • How to manage multiple regulatory requirements
  • How to handle client requests for attestation
  • To validate that significant changes did not have unanticipated results

Best Practices for Firing A Network Security Administrator

Firing A Network Security AdministratorWant to know how to fire a Network Admin? Need to know what precautions to take? Firing any employee can be a stressful event. Firing one who has significant knowledge of and privileged access to your Information Technology/Security infrastructure is even more stressful, as the risks are so notable.

Download: Information Security Attestation Guide

Information Security GuideA Best-Practices Guide to Information Security Attestation

Download our proven Information Security Guide to simplify the process of protecting your data, proving you’re secure and growing your business.

About the Author:

John Verry, CISA, 27001 Certified Lead Auditor, CCSE, CRISC - "Security Sherpa" - Information Security Auditor

Add a Comment