1
1

00:00:00,360  -->  00:00:02,613
<v Lecturer>Risk identification process.</v>
2

2

00:00:03,480  -->  00:00:06,120
In this lesson, we are going to talk about risk
3

3

00:00:06,120  -->  00:00:08,100
and how you can identify it.
4

4

00:00:08,100  -->  00:00:10,470
Now, one of the big things we're going to talk about with risk
5

5

00:00:10,470  -->  00:00:13,620
is the idea of enterprise risk management.
6

6

00:00:13,620  -->  00:00:16,650
Now, enterprise risk management is the comprehensive process
7

7

00:00:16,650  -->  00:00:19,860
of evaluating, measuring and mitigating the many
8

8

00:00:19,860  -->  00:00:22,890
different risks that pervade an organization.
9

9

00:00:22,890  -->  00:00:25,500
This is important, because in all of our organizations,
10

10

00:00:25,500  -->  00:00:27,030
we face risk.
11

11

00:00:27,030  -->  00:00:29,970
There are risk to our systems, there's risk from attackers
12

12

00:00:29,970  -->  00:00:31,800
and there's risk from the environment
13

13

00:00:31,800  -->  00:00:33,180
and we're going to talk about all of this,
14

14

00:00:33,180  -->  00:00:35,310
throughout our risk management journey.
15

15

00:00:35,310  -->  00:00:36,960
Now, what is risk management
16

16

00:00:36,960  -->  00:00:39,690
and why is it adopted by organizations?
17

17

00:00:39,690  -->  00:00:42,810
Well, quite simply put, we have to manage risk
18

18

00:00:42,810  -->  00:00:45,150
and adopt risk management so we can see
19

19

00:00:45,150  -->  00:00:46,890
all of the different risks that is out there
20

20

00:00:46,890  -->  00:00:48,390
and then put controls in place
21

21

00:00:48,390  -->  00:00:51,900
to help bring the level of risk down to an acceptable level.
22

22

00:00:51,900  -->  00:00:54,570
Now, when we start talking about enterprise risk management
23

23

00:00:54,570  -->  00:00:57,060
there are lots of reasons that we adopt it.
24

24

00:00:57,060  -->  00:00:59,940
For example, we might want to keep our confidential data,
25

25

00:00:59,940  -->  00:01:00,960
confidential.
26

26

00:01:00,960  -->  00:01:03,000
We want to make sure that all that customer data
27

27

00:01:03,000  -->  00:01:04,500
and all that corporate data we have
28

28

00:01:04,500  -->  00:01:07,200
doesn't get into the hands of unauthorized parties.
29

29

00:01:07,200  -->  00:01:10,260
We also want to make sure that we avoid financial losses.
30

30

00:01:10,260  -->  00:01:12,390
This can occur by people attacking our systems
31

31

00:01:12,390  -->  00:01:15,120
and damaging our resources or attacking our data
32

32

00:01:15,120  -->  00:01:16,620
and having data leaks.
33

33

00:01:16,620  -->  00:01:18,630
All of this are things that can cost us money
34

34

00:01:18,630  -->  00:01:20,610
and so by doing proper risk management,
35

35

00:01:20,610  -->  00:01:23,670
we can minimize that and avoid those financial losses.
36

36

00:01:23,670  -->  00:01:26,160
We also want to make sure we can avoid legal troubles.
37

37

00:01:26,160  -->  00:01:27,720
If we have our systems hacked,
38

38

00:01:27,720  -->  00:01:29,160
that data can then be breached,
39

39

00:01:29,160  -->  00:01:32,040
and if it is we can have legal consequences to that,
40

40

00:01:32,040  -->  00:01:33,210
such as civil lawsuits
41

41

00:01:33,210  -->  00:01:35,250
for not protecting that data appropriately
42

42

00:01:35,250  -->  00:01:36,150
and so we want to make sure
43

43

00:01:36,150  -->  00:01:37,620
that we're avoiding any legal issues
44

44

00:01:37,620  -->  00:01:39,330
by doing proper risk management.
45

45

00:01:39,330  -->  00:01:42,510
Also, we want to maintain a positive brand image.
46

46

00:01:42,510  -->  00:01:43,410
Now this is important
47

47

00:01:43,410  -->  00:01:45,390
because even though you might be protected
48

48

00:01:45,390  -->  00:01:47,100
from the legal ramifications
49

49

00:01:47,100  -->  00:01:49,560
or you might have been able to mitigate the costs,
50

50

00:01:49,560  -->  00:01:51,510
if you have some sort of a data breach
51

51

00:01:51,510  -->  00:01:53,190
you can have your brand tarnished
52

52

00:01:53,190  -->  00:01:56,160
and that is something that you can't get back very easily.
53

53

00:01:56,160  -->  00:01:58,380
They say it takes decades to build a brand,
54

54

00:01:58,380  -->  00:01:59,850
but only moments to lose it.
55

55

00:01:59,850  -->  00:02:01,260
So we want to make sure we can maintain
56

56

00:02:01,260  -->  00:02:03,060
a positive brand image.
57

57

00:02:03,060  -->  00:02:06,330
Also, we want to ensure continuity of business operations,
58

58

00:02:06,330  -->  00:02:10,080
also known COOP, the continuity of operations plan.
59

59

00:02:10,080  -->  00:02:11,550
By doing this, we can make sure that
60

60

00:02:11,550  -->  00:02:14,760
even if there is a natural disaster or a man-made disaster,
61

61

00:02:14,760  -->  00:02:17,130
we can survive that and keep our businesses running.
62

62

00:02:17,130  -->  00:02:19,440
We'll talk more about that as we go through this lesson.
63

63

00:02:19,440  -->  00:02:21,270
Another great reason for doing risk management
64

64

00:02:21,270  -->  00:02:23,190
is to ensure that you can establish trust
65

65

00:02:23,190  -->  00:02:25,080
and mitigate your liability.
66

66

00:02:25,080  -->  00:02:27,420
All of this is involved in your business relationships
67

67

00:02:27,420  -->  00:02:28,860
between you and other businesses
68

68

00:02:28,860  -->  00:02:30,690
as well as you and your clients
69

69

00:02:30,690  -->  00:02:32,190
and finally, we want to make sure
70

70

00:02:32,190  -->  00:02:34,620
we're meeting the stakeholders objectives.
71

71

00:02:34,620  -->  00:02:36,090
We have different stakeholders,
72

72

00:02:36,090  -->  00:02:38,220
whether those are shareholders in our company,
73

73

00:02:38,220  -->  00:02:40,140
whether that's executives in the company,
74

74

00:02:40,140  -->  00:02:42,960
managers or technicians, or even our customers.
75

75

00:02:42,960  -->  00:02:44,850
All of these stakeholders have objectives,
76

76

00:02:44,850  -->  00:02:46,680
and if we're not doing proper risk management,
77

77

00:02:46,680  -->  00:02:48,000
we can't meet their objectives
78

78

00:02:48,000  -->  00:02:49,950
and we can't get them what they need.
79

79

00:02:49,950  -->  00:02:52,170
Now, just for a moment, I want to take a sidebar
80

80

00:02:52,170  -->  00:02:54,060
and talk a little bit more about these stakeholders,
81

81

00:02:54,060  -->  00:02:56,490
because this is a critical concept.
82

82

00:02:56,490  -->  00:02:59,580
You as a cybersecurity technician or cybersecurity analysts
83

83

00:02:59,580  -->  00:03:02,130
are not going to be making all the risk decisions.
84

84

00:03:02,130  -->  00:03:04,170
You're just not. That's not your job.
85

85

00:03:04,170  -->  00:03:06,240
Instead, these decisions had to be made
86

86

00:03:06,240  -->  00:03:08,070
by the different business stakeholders
87

87

00:03:08,070  -->  00:03:10,290
or by a different project management team
88

88

00:03:10,290  -->  00:03:12,180
or by the customer service team
89

89

00:03:12,180  -->  00:03:15,570
or whoever is the relevant stakeholder in that situation.
90

90

00:03:15,570  -->  00:03:17,220
Now, as the cybersecurity analyst,
91

91

00:03:17,220  -->  00:03:18,840
you are in a unique position though
92

92

00:03:18,840  -->  00:03:21,000
to understand all the different technical risks
93

93

00:03:21,000  -->  00:03:24,690
that exist out there and so it is your job to take those,
94

94

00:03:24,690  -->  00:03:27,090
make them easier to understand and bring them back
95

95

00:03:27,090  -->  00:03:29,520
to the attention of those key decision makers
96

96

00:03:29,520  -->  00:03:31,170
and that's why it's important for you to understand
97

97

00:03:31,170  -->  00:03:33,480
risk management and the risk management process
98

98

00:03:33,480  -->  00:03:35,250
because you're going to have to plug into that
99

99

00:03:35,250  -->  00:03:36,900
to be able to get your points across
100

100

00:03:36,900  -->  00:03:38,700
and be able to get the right controls in place
101

101

00:03:38,700  -->  00:03:40,500
to mitigate that risk.
102

102

00:03:40,500  -->  00:03:42,210
Now, when we talk about risk management,
103

103

00:03:42,210  -->  00:03:43,620
the go-to guide for this
104

104

00:03:43,620  -->  00:03:45,990
is Managing Information Security Risk,
105

105

00:03:45,990  -->  00:03:48,240
which is a publication put out by NIST.
106

106

00:03:48,240  -->  00:03:52,050
This is the NIST special publication 800-39.
107

107

00:03:52,050  -->  00:03:54,630
This is a great starting point for applying a process
108

108

00:03:54,630  -->  00:03:57,120
for risk identification and assessment.
109

109

00:03:57,120  -->  00:03:59,670
When you look inside this guide you're going to see a diagram
110

110

00:03:59,670  -->  00:04:01,110
that looks like this.
111

111

00:04:01,110  -->  00:04:02,520
You're going to see here the components
112

112

00:04:02,520  -->  00:04:04,710
of information security, risk management.
113

113

00:04:04,710  -->  00:04:06,540
This is a framework as described
114

114

00:04:06,540  -->  00:04:09,750
by the special publication 800-39.
115

115

00:04:09,750  -->  00:04:12,750
Now notice we have three main corners to this triangle.
116

116

00:04:12,750  -->  00:04:15,630
We have assess, respond, and monitor
117

117

00:04:15,630  -->  00:04:18,510
and in between all of these, you see the word frame.
118

118

00:04:18,510  -->  00:04:20,430
Now, in between all four of these things,
119

119

00:04:20,430  -->  00:04:22,230
we have information and communication flows
120

120

00:04:22,230  -->  00:04:24,420
going up and down and left and right,
121

121

00:04:24,420  -->  00:04:25,860
because all of these different pieces
122

122

00:04:25,860  -->  00:04:27,390
of the risk management framework
123

123

00:04:27,390  -->  00:04:30,000
are going to talk to each other so we can get information
124

124

00:04:30,000  -->  00:04:31,620
and pass it between them.
125

125

00:04:31,620  -->  00:04:34,470
Let's take a look at what each of these four dots represent.
126

126

00:04:34,470  -->  00:04:36,930
When we talk about frame, this is our goal to establish
127

127

00:04:36,930  -->  00:04:39,030
a strategic risk management framework
128

128

00:04:39,030  -->  00:04:42,060
that is supported by decision makers, those key stakeholders
129

129

00:04:42,060  -->  00:04:44,490
at the top tier of the organization.
130

130

00:04:44,490  -->  00:04:45,720
When we talk about Frame,
131

131

00:04:45,720  -->  00:04:47,670
our goal here is to create this framework
132

132

00:04:47,670  -->  00:04:49,830
that everything else is going to reside around.
133

133

00:04:49,830  -->  00:04:51,540
Now, as a cybersecurity analyst
134

134

00:04:51,540  -->  00:04:54,480
you're not going to be the one creating the frame portion.
135

135

00:04:54,480  -->  00:04:57,030
Instead, you're going to be working a lot more in the assess,
136

136

00:04:57,030  -->  00:05:00,450
respond, and monitor. but frame is going to dictate
137

137

00:05:00,450  -->  00:05:02,550
all three of those because it puts out
138

138

00:05:02,550  -->  00:05:05,043
the strategic framework for your organization.
139

139

00:05:05,880  -->  00:05:07,770
Now, next, we're going to talk about assess
140

140

00:05:07,770  -->  00:05:09,090
and this is something you're going to do
141

141

00:05:09,090  -->  00:05:10,680
as a cybersecurity analyst.
142

142

00:05:10,680  -->  00:05:12,420
It is going to be your job to identify
143

143

00:05:12,420  -->  00:05:14,640
and prioritize the different business processes
144

144

00:05:14,640  -->  00:05:17,160
and workflows in the organization.
145

145

00:05:17,160  -->  00:05:19,770
When you start looking at this from the assess perspective,
146

146

00:05:19,770  -->  00:05:21,540
this is where you're doing systems assessments
147

147

00:05:21,540  -->  00:05:23,460
to determine which assets are there
148

148

00:05:23,460  -->  00:05:26,940
and which assets support which workflows in the business.
149

149

00:05:26,940  -->  00:05:28,320
As you start to identify that,
150

150

00:05:28,320  -->  00:05:30,120
you're going to be able to identify different risks
151

151

00:05:30,120  -->  00:05:31,500
to each of those systems.
152

152

00:05:31,500  -->  00:05:33,390
Maybe there's software that's not been patched,
153

153

00:05:33,390  -->  00:05:34,530
that is a risk.
154

154

00:05:34,530  -->  00:05:36,990
Maybe there's an attacker going after that type of system.
155

155

00:05:36,990  -->  00:05:39,420
That's a risk, and these are things you have to assess
156

156

00:05:39,420  -->  00:05:41,310
to understand what the risk level is.
157

157

00:05:41,310  -->  00:05:43,530
We'll talk more about that later as well.
158

158

00:05:43,530  -->  00:05:46,050
The second area we want to look at is respond.
159

159

00:05:46,050  -->  00:05:48,150
Now, when you're going to respond, you have to mitigate
160

160

00:05:48,150  -->  00:05:51,030
each risk factor through the deployment of managerial,
161

161

00:05:51,030  -->  00:05:53,820
operational and technical security controls.
162

162

00:05:53,820  -->  00:05:56,220
It's our job here to put things in place
163

163

00:05:56,220  -->  00:05:57,660
to help lower that risk,
164

164

00:05:57,660  -->  00:05:59,430
and we're going to talk all about what we can do
165

165

00:05:59,430  -->  00:06:02,670
to control risk as we go through this section of the course
166

166

00:06:02,670  -->  00:06:04,830
and finally, we need to monitor.
167

167

00:06:04,830  -->  00:06:07,110
When we monitor, we're going to evaluate the effectiveness
168

168

00:06:07,110  -->  00:06:08,850
of the risk response measures
169

169

00:06:08,850  -->  00:06:11,370
and identify changes that could affect risk management
170

170

00:06:11,370  -->  00:06:12,990
and those processes.
171

171

00:06:12,990  -->  00:06:15,420
Now, monitor is our last thing we're going to do here,
172

172

00:06:15,420  -->  00:06:17,520
because what we're going to do is we're going to assess something,
173

173

00:06:17,520  -->  00:06:19,050
we're going to figure out what risk it has.
174

174

00:06:19,050  -->  00:06:20,640
We're going to put some controls in place,
175

175

00:06:20,640  -->  00:06:22,860
and then we're going to monitor to make sure those controls
176

176

00:06:22,860  -->  00:06:24,510
are effective and are giving us
177

177

00:06:24,510  -->  00:06:26,640
the risk results that we want.
178

178

00:06:26,640  -->  00:06:29,070
Now, as we start with risk identification remember,
179

179

00:06:29,070  -->  00:06:31,890
this takes place by evaluating all the threats,
180

180

00:06:31,890  -->  00:06:33,300
identifying the vulnerabilities
181

181

00:06:33,300  -->  00:06:36,060
and assessing the probability or likelihood
182

182

00:06:36,060  -->  00:06:39,090
of an event affecting an asset or a process.
183

183

00:06:39,090  -->  00:06:41,910
Now, risk identification really is this first step
184

184

00:06:41,910  -->  00:06:44,460
inside of risk management that we as cybersecurity analysts
185

185

00:06:44,460  -->  00:06:45,630
are going to take.
186

186

00:06:45,630  -->  00:06:47,190
As we start this identification,
187

187

00:06:47,190  -->  00:06:48,840
that helps us to assess things
188

188

00:06:48,840  -->  00:06:50,850
and then we can respond to them and monitor them
189

189

00:06:50,850  -->  00:06:52,290
as we go forward.
190

190

00:06:52,290  -->  00:06:54,480
Now, the final thing I want to briefly mention here
191

191

00:06:54,480  -->  00:06:56,340
is how do we measure risk?
192

192

00:06:56,340  -->  00:06:58,260
Well, there are two main methods.
193

193

00:06:58,260  -->  00:07:00,450
The first is quantitative methods.
194

194

00:07:00,450  -->  00:07:02,310
This is where you can count something.
195

195

00:07:02,310  -->  00:07:04,290
If I can look at the risk and quantify it
196

196

00:07:04,290  -->  00:07:07,500
in dollars and cents, that is a quantitative method.
197

197

00:07:07,500  -->  00:07:09,960
We're going to dig into this more later in this section
198

198

00:07:09,960  -->  00:07:12,150
and the second way is qualitative methods.
199

199

00:07:12,150  -->  00:07:13,950
When we talk about qualitative methods,
200

200

00:07:13,950  -->  00:07:16,620
these are things where we kind of feel or have an opinion
201

201

00:07:16,620  -->  00:07:18,360
about how risky something is.
202

202

00:07:18,360  -->  00:07:20,970
We categorize these as high, medium, and low.
203

203

00:07:20,970  -->  00:07:22,860
We don't have an exact dollar amount,
204

204

00:07:22,860  -->  00:07:26,490
but we can kind of understand how risky something is.
205

205

00:07:26,490  -->  00:07:29,160
Without even calculating the damage, I know how risky it is
206

206

00:07:29,160  -->  00:07:31,740
for me to get in my car and drive to work every day.
207

207

00:07:31,740  -->  00:07:33,450
It's a relatively low risk.
208

208

00:07:33,450  -->  00:07:36,000
I've been driving to work for 30 years now
209

209

00:07:36,000  -->  00:07:38,700
and I've never gotten into an accident on my way to work,
210

210

00:07:38,700  -->  00:07:41,010
so I find that to be a low risk event.
211

211

00:07:41,010  -->  00:07:42,720
That is a qualitative measurement though,
212

212

00:07:42,720  -->  00:07:44,610
it is not a quantitative measurement
213

213

00:07:44,610  -->  00:07:46,650
'cause I don't have a dollars and cents calculation to it.
214

214

00:07:46,650  -->  00:07:48,660
I just know that it's a low risk.
215

215

00:07:48,660  -->  00:07:50,010
We'll talk more about these concepts
216

216

00:07:50,010  -->  00:07:52,163
as we go through this section of the course.
