SSCP · Domain 3
Risk Identification, Monitoring and Analysis
About 15% of the exam
Risk vocabulary
- Asset
- what has value here
- Threat
- the potential cause of harm
- Vulnerability
- the weakness that permits it
- Likelihood
- how probable in the period
- Impact
- how bad if it happens
- Inherent risk
- before any control applies
- Residual risk
- what remains afterwards
- Risk appetite
- what leadership will accept
- Risk tolerance
- acceptable variance around appetite
The process, in order
- Identify assets and threats
- Analyze likelihood and impact
- Evaluate against appetite
- Treat
- Report
- Monitor and reassess
- Identification always comes first
- A framework supplies the structure
- Reassess when the environment changes
- The register is the working record
Quantitative analysis
- Asset value
- replacement plus lost business
- Exposure factor
- share of value lost
- SLE
- asset value times exposure factor
- ARO
- expected occurrences per year
- ALE
- SLE times ARO
- Cost benefit
- control cost against loss reduction
- Limitation
- reliable data is rarely available
An ARO of 0.1 means once in ten years, so an SLE of 200,000 gives an ALE of 20,000
Qualitative analysis
- Rating scale
- high, medium and low
- Heat map
- likelihood against impact grid
- Delphi technique
- anonymous rounds of expert opinion
- Interviews
- owners describe realistic scenarios
- Fault tree
- top down failure analysis
- Limitation
- subjective and hard to compare
Treatment, register and reporting
Treatment
- Mitigate by adding controls
- Transfer through insurance or contract
- Avoid by stopping the activity
- Accept with a named owner
- Never leave a risk unowned
Register fields
- Description and affected assets
- Likelihood, impact and score
- Current controls and their status
- Treatment plan and target date
- Owner and next review date
Reporting
- Key risk indicators warn early
- Key performance indicators show delivery
- Escalate when a threshold is crossed
- Boards want exposure and direction
Operating the monitoring platform
Sources
- Operating system and security logs
- Firewall, proxy and DNS
- Identity and authentication systems
- Applications and databases
- Physical access and environmental sensors
Aggregate and correlate
- Central collection with reliable transport
- Normalize fields before correlating
- Synchronize time across every source
- Rules combine events into alerts
- Protect stored logs from modification
Analyze
- Baseline first, then flag deviation
- Look at trend, not a snapshot
- Visualize for the intended audience
- Document findings and communicate clearly
- Escalate beyond your own authority
An event of interest is only meaningful against a baseline, so build the baseline before you tune the alert
Threat modeling
- Model during design, not afterwards
- Decompose the system and data flows
- Ask what can go wrong
- Rank threats by impact and ease
- Record a mitigation for each threat
- Revisit when the architecture changes
Business impact analysis
- Critical process
- the work that cannot stop
- Dependency
- systems, people and suppliers needed
- MTD
- maximum tolerable downtime overall
- RTO
- target time to restore
- RPO
- tolerable window of data loss
- Financial impact
- cost per hour of outage
- Other impact
- reputation, safety and compliance
Vulnerability management lifecycle
- Discover assets
- Scan
- Validate findings
- Prioritize
- Remediate
- Rescan and report
- Coverage matters more than frequency
- Credentialed scans cut false positives
- Prioritize by exposure and exploitability
- Exceptions get an owner and expiry
Types of security testing
- Vulnerability scan
- finds known weaknesses automatically
- Penetration test
- proves what can be exploited
- Configuration review
- compares against the baseline
- Code review
- reads the source for flaws
- Log review
- checks what actually happened
- Tabletop
- discussion based validation
- Red team
- objective driven adversary simulation
Legal and regulatory drivers
- GDPR
- personal data of EU residents
- HIPAA
- protected health information rules
- PCI DSS
- contractual card data requirements
- SOX
- financial reporting integrity controls
- Data residency
- where the data may live
- Legal hold
- suspend deletion of records
- Chain of custody
- the evidence handling record
Findings and escalation
- Write findings for the audience
- State impact before technical detail
- Give evidence and a confidence level
- Recommend one clear next step
- Escalate on severity, not convenience
- Track every finding to closure
Key formulas
- SLE
- asset value times exposure factor
- ALE
- SLE times ARO
- Residual risk
- inherent risk minus control effect
- Control test
- annual cost under the ALE
- Risk score
- likelihood times impact
- Availability
- uptime over total time
Rapid recall
- KRI
- warns before the risk lands
- KPI
- shows how well controls perform
- Register
- the live list of risks
- Threshold
- the point that triggers escalation
- Baseline
- the normal you compare against
- Anomaly
- a deviation worth investigating
Reference strip: identify, analyze, treat, monitor
Identify
- Asset inventory and ownership
- Threat sources and threat modeling
- Vulnerability discovery and scanning
- Business impact analysis
Analyze
- Qualitative scales and heat maps
- Quantitative SLE, ARO, ALE
- Delphi, interviews, fault trees
- Inherent versus residual risk
Treat
- Mitigate, transfer, avoid, accept
- Cost benefit against the ALE
- Compensating controls and exceptions
- Owners, target dates, review dates
Monitor
- Log collection and time synchronization
- Correlation rules and alerting
- Baselines, anomalies, trends
- Dashboards and executive reporting
Comply
- GDPR, HIPAA, PCI DSS, SOX
- Data residency and retention
- Legal hold and evidence handling
- Audit evidence gathered continuously
Quick exam traps
- Trap: Quantitative analysis is always the better method
- Trap: Residual risk means the risk was eliminated
- Trap: A vulnerability scan and a penetration test are equivalent
- Trap: Key risk indicators and key performance indicators are the same
- Trap: Collecting logs centrally counts as monitoring them
- Trap: The security team owns every risk in the register
- Trap: An alert without a baseline still means something
cybercertprep.com · original revision sheet written from the public body of knowledge