CISM · Domain 2
Information Security Risk Management
About 20% of the exam
The risk management process
- Establish context
- Identify
- Analyze
- Evaluate
- Treat
- Monitor and report
- Context
- scope, criteria, appetite, stakeholders
- Identify
- assets, threats, vulnerabilities, scenarios
- Analyze
- likelihood and impact, inherent level
- Evaluate
- compare against appetite and criteria
- Treat
- avoid, mitigate, transfer, accept
- Monitor
- KRIs, register reviews, reassess on change
Risk assessment is identify plus analyze plus evaluate; treatment comes after the decision
Risk vocabulary
- Asset
- anything of value to the business
- Threat
- potential cause of an unwanted incident
- Vulnerability
- weakness a threat can exploit
- Threat event
- the threat acting on the weakness
- Likelihood
- probability within a time frame
- Impact
- business consequence when realized
- Exposure
- extent open to loss
- Risk
- likelihood and impact, in business terms
Where risks come from
- Emerging technology adopted without assessment
- Threat intelligence and industry sharing
- Vulnerability scans and penetration tests
- Audit findings and control deficiencies
- Incidents, near misses, loss events
- Business change, mergers, new markets
- Third parties and the supply chain
- Regulatory and legal change
Qualitative versus quantitative
Qualitative
- High, medium, low ratings
- Fast, needs little data
- Subjective: expert judgment, Delphi rounds
- Heat map output for executives
- Good for ranking, weak for budgets
Quantitative
- Monetary values and probabilities
- SLE = asset value x exposure factor
- ALE = SLE x ARO
- Needs reliable loss history
- Justifies control spend in dollars
Semi-quantitative
- Numbers assigned to qualitative scales
- Ranked comparison without full data
- Where most programs actually land
Quantitative when data exists and money decides; qualitative when speed and consensus matter
The risk register
- Description
- scenario written in business terms
- Owner
- accountable business manager
- Inherent rating
- before controls
- Existing controls
- what already reduces it
- Residual rating
- after controls
- Treatment plan
- action, owner, due date
- Status
- open, in progress, accepted, closed
- KRI
- linked indicator and threshold
One risk, one owner; the register is a living document, not an annual artifact
Treatment options
- Avoid
- stop the activity, remove exposure
- Mitigate
- add or improve controls
- Transfer or share
- insurance, contract, outsourcing
- Accept
- documented, by the owner, within appetite
- Ignore
- never an option
Transfer moves the financial loss, not the accountability
Inherent, residual, acceptable
- Inherent risk
- before any control
- Control effect
- reduces likelihood or impact
- Residual risk
- what remains after controls
- Acceptable risk
- residual within appetite
- Above appetite
- escalate: more treatment or acceptance
Residual above appetite goes to the owner and senior management for a decision, never quietly kept
Risk and control ownership
- Ownership sits with budget and authority
- IT owns systems, the business owns risk
- Risk owner
- business manager, accepts and decides
- Control owner
- operates and maintains the control
- Security manager
- advises, facilitates, monitors
- Senior management
- accepts enterprise-level risk
- Internal audit
- independent assurance only
Control selection and baselines
- Select from the risk, not the catalog
- Cost must not exceed the risk reduced
- Baselines set the minimum for everyone
- Layer preventive, detective, corrective controls
- Compensating control when the primary is impractical
- ISO 27002 and NIST 800-53 supply the menu
- Verify design, then operating effectiveness
Key formulas
- SLE
- asset value x exposure factor
- ALE
- SLE x ARO
- ARO
- expected events per year
- Control value
- ALE before minus ALE after minus cost
- ROSI
- risk reduction minus cost, over cost
- Residual
- inherent minus control effect
Buy the control when its yearly cost sits below the ALE it removes
Legal, regulatory, contractual
- GDPR
- EU personal data, 72 hour notice, 4% fines
- HIPAA
- PHI, administrative, physical, technical safeguards
- SOX 404
- controls over financial reporting
- PCI DSS
- cardholder data, 12 requirements
- Privacy by design
- build it in from the start
- DPIA
- required when processing is high risk
- Conflicts
- legal analysis, satisfy the strictest
- Non-compliance found
- assess impact, then remediation plan
Monitoring and reporting
- KRIs warn before the risk materializes
- Thresholds that trigger a defined action
- Reassess on significant change, not only schedule
- Report residual risk against appetite
- Trends matter more than snapshots
- Board hears business impact, not scan counts
- Compliance monitoring built into daily operations
Third-party risk
- Due diligence before the contract
- Security requirements written into the contract
- Right to audit, SOC 2 Type II evidence
- Tier suppliers by criticality and data access
- Monitor through the whole relationship
- Exit and termination planned up front
- Outsourcing transfers work, never accountability
Rapid recall: the FIRST move
- Assess the risk and impact before acting
- Ask the risk owner, not the vendor
- Compare residual risk against appetite
- Escalate what exceeds appetite, do not absorb it
- Consult legal on what applies
- Fix the process gap, not one finding
- Document acceptance, never assume it
Reference strip: process, options, regimes, terms
Process in order
- Context and criteria
- Identify assets, threats, vulnerabilities
- Analyze likelihood and impact
- Evaluate against appetite
- Treat, then monitor and report
Treatment options
- Avoid: remove the activity
- Mitigate: add controls
- Transfer or share: insurance, contracts
- Accept: owner signs within appetite
Regimes
- GDPR: 72 hours, DPO, DPIA
- HIPAA: PHI safeguards, 60 day notice
- SOX 404: financial reporting controls
- PCI DSS: cardholder data
- Contracts: your standards bind suppliers
Assurance evidence
- SOC 1 for financial controls
- SOC 2 Type II: operated over time
- ISO 27001 certificate: ISMS in place
- Penetration test and scan reports
- Right to audit clause
Terms to hold apart
- Threat versus vulnerability versus risk
- Inherent versus residual
- Appetite versus tolerance versus capacity
- Risk owner versus control owner
- Assessment versus treatment
Quick exam traps
- Trap: Buying cyber insurance transfers accountability for the risk
- Trap: The security manager owns the business risk
- Trap: Risk acceptance can be informal if the risk is small
- Trap: Qualitative analysis produces a dollar loss figure
- Trap: Every identified risk must be mitigated
- Trap: Risk assessments are only repeated on the annual schedule
- Trap: A SOC 2 Type I report proves controls operated all year
- Trap: Meeting regulatory requirements means the risk is managed
cybercertprep.com · original revision sheet written from the public body of knowledge