CRISC · Domain 2
IT Risk Assessment
About 22% of the exam
Risk identification sources
- Asset inventory and business process maps
- Threat intelligence and industry reports
- Vulnerability scans, penetration tests
- Audit findings and control deficiencies
- Incident and loss event history
- Interviews and workshops with owners
- Change requests and new projects
- Third-party and supply chain reviews
Risk scenarios
- Threat actor
- Threat type
- Event
- Asset or resource
- Time and duration
Building one
- Top down from business objectives
- Bottom up from known events
- Written in business impact language
- Realistic, relevant, not exhaustive
- Owner named for each scenario
Using them
- Anchor for likelihood and impact estimates
- Reused in workshops and tabletop exercises
- Feed the register as candidate risks
- Refresh when the environment changes
- Aggregate related scenarios, avoid duplicates
A scenario is a story with an actor, an event, an asset and a consequence; rate the story, not the vulnerability
Threats and vulnerabilities
- Threat
- potential cause of harm
- Threat actor
- who or what triggers it
- Vulnerability
- weakness the threat exploits
- Control deficiency
- control missing or not working
- Exposure
- how open you are
- Root cause
- why the weakness exists
- Risk
- threat meets vulnerability, impacts asset
A vulnerability with no threat and no asset value is not a risk yet
The assessment process
- Scope and context
- Identify
- Analyze
- Evaluate
- Rank
- Document
- Scope
- systems, processes, criteria, appetite
- Identify
- scenarios, threats, vulnerabilities, assets
- Analyze
- likelihood, impact, existing controls
- Evaluate
- compare to appetite and tolerance
- Rank
- prioritize for response and resources
- Document
- register updated, owners informed
Reassess on significant change: new threats, new systems, new business processes, not only on the calendar
Likelihood and impact scales
- Likelihood
- probability within a defined period
- Impact
- financial, operational, reputational, regulatory
- Scale
- consistent, defined, enterprise-wide
- Rating
- likelihood combined with impact
- Velocity
- how fast the impact arrives
- High impact, rare
- document, consider transfer or accept
Use the enterprise scale so IT risks roll up beside every other risk
Inherent versus residual
- Residual above appetite escalates to management
- Control effectiveness sets the difference
- Inherent
- before any controls
- Current
- with controls as they operate today
- Residual
- after planned responses
- Target
- residual inside appetite
- Gap
- residual above appetite, needs decision
Qualitative versus quantitative
Qualitative
- High, medium, low categories
- Quick, consensus based, subjective
- Bias and inconsistency are the weakness
- Output: heat map and ranked list
Quantitative
- Money and probabilities
- SLE = asset value x exposure factor
- ALE = SLE x ARO
- Needs quality historical loss data
- Monte Carlo gives a distribution, not a point
Semi-quantitative
- Numbers on qualitative scales
- Finer ranking without full data
- Common enterprise compromise
When the two methods disagree, check the assumptions and data quality of both before choosing
Heat map and register
- Heat map: likelihood by impact grid
- Upper right is high and high
- Visual prioritization for executives
- Register holds the detail behind it
- Owner, rating, controls, response, status
- One risk, one owner, one entry
- Review dates and KRIs attached
Assessing controls
- Design effectiveness
- would it work if followed
- Operating effectiveness
- does it work over time
- Gap analysis
- current controls versus required
- Test
- inspect, observe, reperform, inquire
- Compensating
- different control, same objective
- Deficiency
- raises current and residual risk
Design first, then operation; a well designed control nobody runs reduces nothing
Analysis techniques
- Delphi
- anonymous expert rounds to consensus
- Monte Carlo
- many simulated outcomes, a distribution
- Bow tie
- causes, event, consequences, barriers
- Fault tree
- top event down to root causes
- FMEA
- failure modes, severity, occurrence, detection
- BIA
- impact of outage over time
- Scenario analysis
- structured what-if for complex risk
When to reassess
- Significant change to systems or processes
- New threat intelligence or major incident
- Regulatory or contractual change
- Merger, acquisition, divestiture
- Control failure or audit finding
- New technology, cloud, AI adoption
- Scheduled cycle as the minimum
Key formulas
- SLE
- asset value x exposure factor
- ALE
- SLE x ARO
- ARO
- expected occurrences per year
- Exposure factor
- percent of asset value lost
- Control value
- ALE reduced minus annual control cost
- Worked example
- 50,000 loss twice a year, ALE 100,000
Rapid recall: the FIRST move
- Understand the business context first
- Confirm scope and criteria before rating
- Ask the process owner, not the tool
- Assess existing controls before adding new
- Residual above appetite: escalate for decision
- No history: expert judgment plus benchmarks
- Rank before you respond
Reference strip: steps, scales, methods, words
Assessment steps
- Scope, context, criteria
- Identify scenarios and assets
- Analyze likelihood and impact
- Evaluate against appetite
- Rank and document
Risk levels
- Inherent: no controls
- Current: controls as operating
- Residual: after response
- Target: within appetite
- Acceptable: owner has signed
Methods
- Qualitative: categories, heat map
- Quantitative: SLE, ALE, Monte Carlo
- Semi-quantitative: scored scales
- Delphi, bow tie, fault tree, FMEA
- BIA for outage impact
Control assessment
- Design effectiveness first
- Operating effectiveness second
- Inquiry, observation, inspection, reperformance
- Gap analysis to required state
- Compensating controls documented
Impact dimensions
- Financial loss and cost
- Operational disruption to processes
- Reputational damage with customers
- Regulatory and legal penalties
- Health, safety, environment
Quick exam traps
- Trap: Every vulnerability found by a scanner is a risk
- Trap: Qualitative assessment produces reliable dollar figures
- Trap: Quantitative results are objective regardless of input data
- Trap: A well designed control is by definition effective
- Trap: Risk assessments only need repeating on the annual schedule
- Trap: Rare high-impact risks can be dropped from the register
- Trap: Inherent risk already accounts for existing controls
- Trap: The practitioner decides which risks the business will accept
cybercertprep.com · original revision sheet written from the public body of knowledge