How do you perform a risk assessment, and what do you do with the results? Find answers to some common risk assessment questions in Part 1 of our two-part series!
Why should you perform a risk assessment?
Performing risk assessments regularly is a fundamental requirement of most security frameworks. A risk assessment should provide you with information that allows you to direct your limited security resources effectively. Take a look at the following statements from ISO 27001 and SOC 2: ISO 27001 Clause 6.1.2: “The organization shall define and apply an information security risk assessment process that… establishes and maintains information security risk criteria… identifies the information security risks… analyses the information security risks… and evaluates the information security risks.” SOC 2 Criteria CC3.1: COSO Principle 7: The entity identifies risks to achieving its objectives across the entity and analyzes risks as a basis for determining how the risks should be managed. The goal is not to meet a compliance requirement, but to identify legitimate risks to the organization, rank them, and treat them. Next, we’ll discuss what a risk assessment practically looks like.Who should be involved?
The risk assessment should be performed by top-level management. The higher the level of manager you include, the more valuable this process will be. C-level executives, directors, and other managers should be performing the risk assessment, evaluating risk, and creating action plans. Again, the goal is to identify legitimate risks at an organization-wide level. Developers, HR personnel, and other employees who work at a tactical level should be brought in as needed.How often should you assess risk?
Management should be assessing risk annually at a minimum. We recommend that management perform a full risk assessment once a year, with quarterly follow-ups. Once risk treatment plans have been developed, the teams responsible for remediation should meet regularly and report back to management.How do you identify risks?
Management should consider a wide range of categories when identifying risks. Below are some of the most common risk categories and examples of each:- Organizational: Lack of information security talent; high turnover in the technology department
- Technical: Outdated infrastructure; lack of mobile device management
- Legislative: Emerging privacy laws; international expansion
- Customers: Increased security requirements; high-value customer retention
- Physical: Fire; natural disasters
How do you rank risks?
Risk levels are based on the potential impact and likelihood should the risk materialize. We typically measure impact on a scale of 1-5, or from “negligible” to “near-fatal.” Similarly, we rank likelihood from 1-5, or “rare,” to “almost certain.” To get the final risk score, multiply the impact and likelihood scores. This initial risk score serves as your guide for risk prioritization and is based on NIST 800-30.Conclusion
In this blog, we examined how to perform a risk assessment, including the why, who, and when.
Kendall Morris
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)