Four Perspectives What is at Risk
Risk management should be approached by evaluating assets, anticipating outcomes, analyzing processes, and understanding vulnerabilities and threats that could impact security objectives.
4 slides · 3 min read · Domain 1
In business terms, something is at risk if there are circumstances outside of the organization's control or influence that could cause that at-risk item to be lost, destroyed, taken away, or otherwise diminished in its value or contribution to the organization.
This gives risk to the four basic perspectives from which security professionals need to view the subject of risk management:
- Asset-based. Information assets such as files, databases, or knowledge banks are quite often the center of attention in risk management and mitigation discussions. Asset protection activities demonstrate this perspective. There are any number of ways to calculate or estimate the value of an asset, and this value is used as part of the risk management decision process.
- Outcomes-based and process-based. This viewpoint identifies the important goals or objectives the organization must achieve, and it links these to the core business processes that make those outcomes happen. Outcomes can range from amount of goods sold to the number of scheduled flights an airline gets off the ground on time and within safety constraints. Safety-critical activities are often the focus of processbased risk management and mitigation. Outcomes-based and process-based views are sometimes conflated, with the resulting gains of achieving an outcome being the value in risk management decisions.
- Vulnerability-based. This perspective uses identified (or reasonably obvious and likely) opportunities for systems to be exploited by an attacker as the preferred way of managing risk.
- Threat-based. This perspective looks at threats, which are human actors who might have deliberate intention to harm, disrupt, or misuse an organization's information, systems, and infrastructures, as the primary focal point of risk management activities.
In truth, all four of these perspectives can operate simultaneously; taken together, they are the four front lines of the defense against the cyberattacker. Small- and medium-sized business enterprises are notorious for doing little if any information security planning or management. They are encouraged by many to at least implement a common set of "cyber hygiene" measures, such as those in the Center for Internet Security (CIS) Security Implementation Group 1 set of controls, which embodies a vulnerabilities-based risk management perspective. Unfortunately, there is no commonly accepted definition for what such hygiene measures should be, nor is there a way to tell whether they are implemented correctly and working effectively.
At the other end of the spectrum, larger, more experienced, and technically sophisticated organizations will act along all the front lines:
- Threat intelligence activities. Sophisticated organizations will try to stay current on what their industry, its information security community, and law enforcement are seeing as evolving threats. They will actively manage risk using a combination of publicly available vulnerabilities and exploits information and their own internal security assessment findings.
- Continuous process maturation and improvement. These organizations focus senior management's attention on the overall benefit in financial or mission terms of the most important business processes, and thus relate those processes through outcomes to their most important goals and objectives.
- Assets and asset valuation. These are at the core of organizational budgeting, resource allocation, and planning in these organizations.
