Conutermeasure Selection and Implementation

3 slides · 1 min read · Domain 1

Countermeasure Selection and Implementation

Countermeasures are chosen by balancing effectiveness, cost, and potential impact to optimize security while minimizing expenses and disruptions.

Security controls are methods, tools, mechanisms, and processes used in risk mitigation. Security controls can function in two general ways: as safeguards, which reduce risk impact/likelihood before the realization of the risk has occurred, and as countermeasures, which reduce the impact/likelihood afterwards.

There are various categories and types of controls an organization can select and implement, based on the risk assessment performed, the organization's risk appetite, and the organization's capabilities.

Security controls should be chosen according to a cost-benefit analysis, comparing the expense of acquiring, deploying, and maintaining the control against the control's ability to reduce the impact and likelihood of a specific risk (or set of risks) and the cost of the risk if it is realized.

Another issue that organizations must consider is the operational impact that will be caused by the control itself against the benefit of continuing that business function with the risk reduction offered by that control.

Every security control has an associated negative impact on operations, whether that is a monetary cost or a reduction in user capability or convenience; there is always a trade-off between security and productivity that makes the security team and the operations group somewhat adversarial in many organizations. The security professional is tasked with aiding the organization to find the right balance. As Dr. Eugene Spafford of Purdue University once put it, "The only truly secure system is one that is powered off, cast in a block of concrete and sealed in a lead-lined room with armed guards-and even then, I have my doubts."

Test this domain