Chapter 56. Understanding and Exploring Risk
Dr. Meg Layton
One thing InfoSec professionals should know is how to consider and effectively discuss risk within their environment. Risk is often explored using a common framework or set of steps: identify your assets and then identify threats and vulnerabilities to those assets. Once these are enumerated, consider the impacts that may occur should threats or vulnerabilities become a reality, and then those impacts are explored against the likelihood of that impact actually occurring. Understanding this framework means that one needs to enumerate the risks for an organization and discuss the implications of threats within the organizational context.
It is essential to understand the organizational context when it comes to risk because it is not the same and varies from organization to organization. Much like my threat model is not the same as your threat model, my organizational tolerance for risk is not the same as your organization’s tolerance.
In a study conducted a few years ago by ISACA, most respondents said that the biggest skill gap in today’s security professionals is the ability to understand the business. This is the same when discussing vulnerabilities, threats, and risks: if one does not understand its impact, one does not understand. The latest threat may be interesting from a technological perspective, and it may be ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access