1
00:00:06,540 --> 00:00:08,310
- In this lesson 24.3,

2
00:00:08,310 --> 00:00:12,360
we're gonna talk about risk
response and risk treatment.

3
00:00:12,360 --> 00:00:14,700
Now risk appetite, risk tolerance,

4
00:00:14,700 --> 00:00:18,720
cost, and external
considerations are all factors

5
00:00:18,720 --> 00:00:21,780
in determining the
appropriate response to risk

6
00:00:21,780 --> 00:00:23,613
and the appropriate treatment.

7
00:00:24,930 --> 00:00:27,660
Now risk response is the responsibility

8
00:00:27,660 --> 00:00:30,240
to determine how to respond to the outcome

9
00:00:30,240 --> 00:00:31,980
of a risk analysis,

10
00:00:31,980 --> 00:00:35,250
where risk treatment is to
select one or more options

11
00:00:35,250 --> 00:00:37,773
to address an identified risk.

12
00:00:38,700 --> 00:00:40,230
So who responds to risk?

13
00:00:40,230 --> 00:00:41,760
Well, I wanna do a risk response

14
00:00:41,760 --> 00:00:43,710
authority illustration with you

15
00:00:43,710 --> 00:00:46,230
just to talk about
different levels of risk

16
00:00:46,230 --> 00:00:47,760
and who in an organization

17
00:00:47,760 --> 00:00:50,550
might be responsible for responding to it.

18
00:00:50,550 --> 00:00:52,470
Again, this is just an illustration,

19
00:00:52,470 --> 00:00:53,700
but it will give you a good sense

20
00:00:53,700 --> 00:00:55,233
of how risk is responded to.

21
00:00:57,030 --> 00:00:58,650
First, let's talk about timing.

22
00:00:58,650 --> 00:01:01,222
Perhaps there's a policy in
the organization that says,

23
00:01:01,222 --> 00:01:04,470
initial results of all risk
analysis must be presented

24
00:01:04,470 --> 00:01:07,560
to executive management
and business process owners

25
00:01:07,560 --> 00:01:09,780
within seven days of completion.

26
00:01:09,780 --> 00:01:12,240
Okay, so we got to report
out within seven days.

27
00:01:12,240 --> 00:01:16,230
Now the question is, what
do we do about the results?

28
00:01:16,230 --> 00:01:18,600
How do we respond to low risk,

29
00:01:18,600 --> 00:01:22,230
elevated risk, and severe risk?

30
00:01:22,230 --> 00:01:24,390
You may have a policy that says low risk

31
00:01:24,390 --> 00:01:26,690
can be accepted by the
business process owner.

32
00:01:27,630 --> 00:01:31,020
Elevated risk must be
responded to within 15 days

33
00:01:31,020 --> 00:01:33,000
by the business process owner,

34
00:01:33,000 --> 00:01:36,273
and treatment is at the
discretion of senior management.

35
00:01:37,320 --> 00:01:39,780
And then for severe risk,
our policy might read,

36
00:01:39,780 --> 00:01:42,690
severe risk must be responded
to within three days.

37
00:01:42,690 --> 00:01:44,411
And treatment is at the discretion

38
00:01:44,411 --> 00:01:46,500
of executive management.

39
00:01:46,500 --> 00:01:48,510
Because the higher level of risk, right?

40
00:01:48,510 --> 00:01:50,280
The higher in the organization

41
00:01:50,280 --> 00:01:53,550
we wanna go for saying this
is okay or this is not okay

42
00:01:53,550 --> 00:01:55,700
or this is what we're
going to do about it.

43
00:01:56,970 --> 00:01:59,940
So what our options if we
do wanna treat the risk?

44
00:01:59,940 --> 00:02:04,940
Well, we can avoid, transfer,
mitigate, or accept.

45
00:02:05,130 --> 00:02:09,030
Now avoiding risk is to
either eliminate the cause,

46
00:02:09,030 --> 00:02:10,620
which is very difficult,

47
00:02:10,620 --> 00:02:13,470
or to terminate the associated activity.

48
00:02:13,470 --> 00:02:16,104
So in our previous
security in action, right?

49
00:02:16,104 --> 00:02:18,810
When we had our e-commerce platform,

50
00:02:18,810 --> 00:02:20,640
if we really thought
the risk was too high,

51
00:02:20,640 --> 00:02:23,400
we could stop doing e-commerce.

52
00:02:23,400 --> 00:02:25,710
Now it was a ransomware
attack that we talked about

53
00:02:25,710 --> 00:02:28,530
and we probably can't
eliminate the cause, right?

54
00:02:28,530 --> 00:02:29,700
Of the ransomware attack.

55
00:02:29,700 --> 00:02:31,560
We can't stop that adversary.

56
00:02:31,560 --> 00:02:33,330
So our choice there would be to terminate

57
00:02:33,330 --> 00:02:35,160
the associated activity.

58
00:02:35,160 --> 00:02:36,930
We could transfer the risk.

59
00:02:36,930 --> 00:02:39,270
Now transferring risk means
that we're gonna assign the risk

60
00:02:39,270 --> 00:02:42,900
to another party, which
is generally insurance.

61
00:02:42,900 --> 00:02:45,870
The risk is typically transferred

62
00:02:45,870 --> 00:02:49,683
when the likelihood is low
but the impact is high.

63
00:02:51,690 --> 00:02:55,228
We can mitigate the risk,
which is to reduce the impact

64
00:02:55,228 --> 00:02:58,380
or the likelihood by
implementing additional controls

65
00:02:58,380 --> 00:03:01,800
or safeguards or process change.

66
00:03:01,800 --> 00:03:03,390
Or we can say, that's cool.

67
00:03:03,390 --> 00:03:04,560
We're good with it, right?

68
00:03:04,560 --> 00:03:07,530
We can accept the risk,
which means to acknowledge it

69
00:03:07,530 --> 00:03:10,710
and to accept the level of
risk and then monitor it.

70
00:03:10,710 --> 00:03:12,030
Just make sure it stays stable.

71
00:03:12,030 --> 00:03:13,500
That it doesn't change.

72
00:03:13,500 --> 00:03:17,310
So avoid, transfer, mitigate, and accept.

73
00:03:17,310 --> 00:03:19,380
Let's talk a little bit
more about acceptance.

74
00:03:19,380 --> 00:03:20,940
Risk acceptance is normally

75
00:03:20,940 --> 00:03:23,310
when the risk level is acceptable

76
00:03:23,310 --> 00:03:27,330
within predefined appetite
and tolerance criteria.

77
00:03:27,330 --> 00:03:28,860
And we don't need any further measures.

78
00:03:28,860 --> 00:03:31,110
No further measures are
needed to be considered.

79
00:03:31,110 --> 00:03:32,400
We don't have to do anything else,

80
00:03:32,400 --> 00:03:34,983
any other treatment except for monitoring.

81
00:03:36,420 --> 00:03:39,273
Remember that risk appetite
was broadly defined

82
00:03:39,273 --> 00:03:40,710
as the level of risk

83
00:03:40,710 --> 00:03:43,620
an entity was willing to accept
in pursuit of its mission

84
00:03:43,620 --> 00:03:46,200
and risk tolerance is tactical

85
00:03:46,200 --> 00:03:49,413
and specific to the
target being evaluated.

86
00:03:52,410 --> 00:03:56,430
Now it's not always
possible to avoid, transfer,

87
00:03:56,430 --> 00:03:59,430
or mitigate a risk to an acceptable level.

88
00:03:59,430 --> 00:04:01,230
Sometimes we're going to have to do

89
00:04:01,230 --> 00:04:04,350
exceptions and exemptions.

90
00:04:04,350 --> 00:04:07,320
A risk exception is a
formal acknowledgement

91
00:04:07,320 --> 00:04:09,210
that a risk has been identified,

92
00:04:09,210 --> 00:04:12,690
but it's not feasible or
practical to implement

93
00:04:12,690 --> 00:04:15,600
our standard risk treatment
or control measures.

94
00:04:15,600 --> 00:04:18,120
Now workarounds may be implemented.

95
00:04:18,120 --> 00:04:22,500
Exception handling is the
process of approving an exception

96
00:04:22,500 --> 00:04:25,473
on either a temporary
or a permanent basis.

97
00:04:26,370 --> 00:04:29,100
You know, maybe we're not going
to do something about a risk

98
00:04:29,100 --> 00:04:31,050
because it's a system
that's gonna be retired

99
00:04:31,050 --> 00:04:33,600
in two weeks or three weeks.

100
00:04:33,600 --> 00:04:35,310
You know, maybe it's a risk exception

101
00:04:35,310 --> 00:04:39,780
because the system is managed
and monitored by somebody else

102
00:04:39,780 --> 00:04:41,640
and we can't do anything about it,

103
00:04:41,640 --> 00:04:45,420
but we may put some additional
controls or some workarounds.

104
00:04:45,420 --> 00:04:49,140
Now a risk exemption is a formal decision

105
00:04:49,140 --> 00:04:51,330
not to address a risk at all.

106
00:04:51,330 --> 00:04:52,680
Now it's generally implemented

107
00:04:52,680 --> 00:04:55,470
when the potential
impact of the risk is low

108
00:04:55,470 --> 00:04:59,700
and the cost and the effort
required to mitigate that risk

109
00:04:59,700 --> 00:05:03,660
are disproportionate to
the potential impact.

110
00:05:03,660 --> 00:05:06,690
Now very critical component
of the risk management program

111
00:05:06,690 --> 00:05:11,343
is on-going monitoring,
documentation, and reporting.

112
00:05:12,900 --> 00:05:15,133
Risk monitoring is a continuous activity

113
00:05:15,133 --> 00:05:17,880
that's used to identify trends,

114
00:05:17,880 --> 00:05:20,190
failures, and/or opportunities

115
00:05:20,190 --> 00:05:23,370
and respond in an efficient
and appropriate manner.

116
00:05:23,370 --> 00:05:26,070
Risk reporting is the
process of communicating

117
00:05:26,070 --> 00:05:27,540
our real-time risk

118
00:05:27,540 --> 00:05:30,543
and our performance data
to our stakeholders.

119
00:05:31,920 --> 00:05:34,260
So here are some risk
monitoring and reporting tools.

120
00:05:34,260 --> 00:05:39,060
Risk registers, heat maps,
dashboards, and metrics.

121
00:05:39,060 --> 00:05:42,480
A risk register is a
dynamic central repository

122
00:05:42,480 --> 00:05:44,540
for all of our risk-related documentation,

123
00:05:44,540 --> 00:05:47,460
our tracking, and accountability.

124
00:05:47,460 --> 00:05:50,790
And it includes information
about acceptance,

125
00:05:50,790 --> 00:05:53,493
exceptions, and exemptions.

126
00:05:54,390 --> 00:05:57,300
Heat maps are a visualization tool

127
00:05:57,300 --> 00:06:01,920
that we can use to convey
likelihood and impact.

128
00:06:01,920 --> 00:06:04,200
Dashboards are a visualization tool

129
00:06:04,200 --> 00:06:06,450
to convey our security posture.

130
00:06:06,450 --> 00:06:08,370
And then there are metrics we can use.

131
00:06:08,370 --> 00:06:10,800
And these are predefined measures,

132
00:06:10,800 --> 00:06:14,070
usually in the form of
what's known as a KRI,

133
00:06:14,070 --> 00:06:15,990
a key risk indicator.

134
00:06:15,990 --> 00:06:19,680
So let's talk more about
KRIs or key risk indicators.

135
00:06:19,680 --> 00:06:21,900
A key risk indicator are predictors

136
00:06:21,900 --> 00:06:25,860
or early warning signals
of unfavorable events

137
00:06:25,860 --> 00:06:29,660
that can adversely impact an organization.

138
00:06:29,660 --> 00:06:33,030
KRIs are indicators of emerging risks

139
00:06:33,030 --> 00:06:36,510
and we have two types of KRI indicators.

140
00:06:36,510 --> 00:06:40,170
We have leading indicators
and lagging indicators.

141
00:06:40,170 --> 00:06:41,580
A leading indicator

142
00:06:41,580 --> 00:06:44,522
looks forward at future
outcomes and events.

143
00:06:44,522 --> 00:06:46,503
Now leading KRIs are measures

144
00:06:46,503 --> 00:06:49,170
that are considered predictive in nature.

145
00:06:49,170 --> 00:06:50,970
And they're derived from metrics

146
00:06:50,970 --> 00:06:54,930
that help us to forecast
future occurrences.

147
00:06:54,930 --> 00:06:57,120
Where a lagging indicator looks back,

148
00:06:57,120 --> 00:06:59,550
it looks back at what has happened.

149
00:06:59,550 --> 00:07:03,660
Lagging KRIs are metrics
based on historical measures

150
00:07:03,660 --> 00:07:07,653
and lagging KRIs are
used to identify trends.

151
00:07:10,350 --> 00:07:12,720
So let's take a look at just some examples

152
00:07:12,720 --> 00:07:14,760
of some key risk indicators.

153
00:07:14,760 --> 00:07:16,410
We've got three categories here.

154
00:07:16,410 --> 00:07:18,660
We've got some information system KRIs,

155
00:07:18,660 --> 00:07:22,574
vendor management KRIs, and
project management KRIs.

156
00:07:22,574 --> 00:07:24,750
So our information system KRIs

157
00:07:24,750 --> 00:07:26,970
may include percentage of applications

158
00:07:26,970 --> 00:07:29,790
that are near or at end of life,

159
00:07:29,790 --> 00:07:31,830
percentage of systems or devices

160
00:07:31,830 --> 00:07:33,788
that are near or end of life,

161
00:07:33,788 --> 00:07:36,660
or percentage of systems in use

162
00:07:36,660 --> 00:07:38,110
that are no longer supported.

163
00:07:39,450 --> 00:07:41,370
Vendor management KRIs might be things

164
00:07:41,370 --> 00:07:45,060
like a trend of outstanding vendor issues,

165
00:07:45,060 --> 00:07:47,910
outsourced projects that
are experiencing delays,

166
00:07:47,910 --> 00:07:49,830
or disputes with vendors.

167
00:07:49,830 --> 00:07:52,170
Again, these would be
measures of all of these.

168
00:07:52,170 --> 00:07:54,030
And project management KRIs

169
00:07:54,030 --> 00:07:57,540
might include a percentage
of projects delayed,

170
00:07:57,540 --> 00:08:00,000
a percentage of projects exceeding budget,

171
00:08:00,000 --> 00:08:03,480
and a percentage of projects
that are not fully staffed.

172
00:08:03,480 --> 00:08:07,383
All of these things being
indicative of an emerging risk.

173
00:08:09,240 --> 00:08:12,060
And that my friends, brings us
to a three-second challenge.

174
00:08:12,060 --> 00:08:15,000
Five challenge questions,
three seconds each.

175
00:08:15,000 --> 00:08:16,530
Let's do it.

176
00:08:16,530 --> 00:08:19,770
An indicator that is a
predictor of unfavorable events

177
00:08:19,770 --> 00:08:22,743
that can adversely impact an organization.

178
00:08:23,610 --> 00:08:25,593
One, two, three.

179
00:08:26,490 --> 00:08:28,983
That's gonna be a KRI,
a key risk indicator.

180
00:08:30,660 --> 00:08:32,460
A dynamic central repository

181
00:08:32,460 --> 00:08:34,743
for all risk-related documentation.

182
00:08:35,880 --> 00:08:37,830
One, two, three.

183
00:08:37,830 --> 00:08:39,003
The risk register.

184
00:08:40,110 --> 00:08:42,900
Number three, selecting
one or more options

185
00:08:42,900 --> 00:08:45,423
for addressing and identified risk.

186
00:08:46,440 --> 00:08:48,033
One, two, three.

187
00:08:48,990 --> 00:08:50,440
That would be risk treatment.

188
00:08:51,990 --> 00:08:56,460
Number four, reducing risk
to an acceptable level.

189
00:08:56,460 --> 00:08:57,963
One, two, three.

190
00:08:58,890 --> 00:09:01,893
And that's risk mitigation
or mitigating risk.

191
00:09:02,760 --> 00:09:05,280
And five, the formal acknowledgement

192
00:09:05,280 --> 00:09:07,020
that a risk has been identified

193
00:09:07,020 --> 00:09:10,233
but it's not practical or
feasible to address it.

194
00:09:11,220 --> 00:09:12,693
One, two, three.

195
00:09:13,740 --> 00:09:17,700
That is a risk exception, right?

196
00:09:17,700 --> 00:09:19,950
And that brings us to
a security in action.

197
00:09:19,950 --> 00:09:22,350
This one's about risk response.

198
00:09:22,350 --> 00:09:23,940
Your organization has been working

199
00:09:23,940 --> 00:09:26,940
with an external consulting
firm for many years.

200
00:09:26,940 --> 00:09:28,770
The firm recently conducted

201
00:09:28,770 --> 00:09:31,590
its annual risk analysis of a core system,

202
00:09:31,590 --> 00:09:35,310
and they identified
several systemic issues

203
00:09:35,310 --> 00:09:38,640
and they determined the level
of operational, strategic,

204
00:09:38,640 --> 00:09:42,450
and reputational risk to be very high.

205
00:09:42,450 --> 00:09:45,900
Now since the CISO is
new to the organization,

206
00:09:45,900 --> 00:09:48,570
the business process owner insists

207
00:09:48,570 --> 00:09:52,260
that she should be the one
to respond to the analysis.

208
00:09:52,260 --> 00:09:55,533
What course of action would
you recommend to the CISO?

209
00:09:56,520 --> 00:09:58,320
Isn't an interesting situation, right?

210
00:09:58,320 --> 00:10:01,020
You've been working with
this external consulting firm

211
00:10:01,020 --> 00:10:04,860
for many, many years and they
recently did their annual,

212
00:10:04,860 --> 00:10:08,190
so they do it every year, risk
analysis of a core system.

213
00:10:08,190 --> 00:10:11,490
And they identified
several systemic issues.

214
00:10:11,490 --> 00:10:13,350
So issues that you know are ingrained

215
00:10:13,350 --> 00:10:14,730
and going on for a while.

216
00:10:14,730 --> 00:10:17,610
And they say, "Oh geez,
the operational strategic

217
00:10:17,610 --> 00:10:19,860
and reputational risk

218
00:10:19,860 --> 00:10:22,890
of whatever's happening
here is very high."

219
00:10:22,890 --> 00:10:24,900
We have this brand new CISO.

220
00:10:24,900 --> 00:10:26,827
And so our business process owner says,

221
00:10:26,827 --> 00:10:29,801
"Well, look, the CISO is brand
new to this organization.

222
00:10:29,801 --> 00:10:33,270
So you know, he or she shouldn't
be the one that responds.

223
00:10:33,270 --> 00:10:35,910
I should be the one that
responds to the analysis."

224
00:10:35,910 --> 00:10:38,940
And the CISO is kinda
like, "Oh, what do I do?"

225
00:10:38,940 --> 00:10:40,803
So what would you advise them?

226
00:10:41,700 --> 00:10:44,379
Go ahead and put me on
pause to jot down some notes

227
00:10:44,379 --> 00:10:46,329
and come back with your recommendation.

228
00:10:49,890 --> 00:10:53,430
Well, the identified risks
impact the entire enterprise.

229
00:10:53,430 --> 00:10:55,860
So the risk response should not be siloed

230
00:10:55,860 --> 00:10:58,488
within a specific business
unit where they came back

231
00:10:58,488 --> 00:11:03,120
and said, operational,
strategic, and reputational risk.

232
00:11:03,120 --> 00:11:05,584
That doesn't belong at the business unit.

233
00:11:05,584 --> 00:11:07,050
That's pretty significant.

234
00:11:07,050 --> 00:11:09,540
And they said not only
in those categories,

235
00:11:09,540 --> 00:11:11,103
but it was very high.

236
00:11:12,360 --> 00:11:14,880
Now the CISO should first consult policy

237
00:11:14,880 --> 00:11:18,780
to see if there's a defined
risk response workflow.

238
00:11:18,780 --> 00:11:21,450
And if not, well this level of risk

239
00:11:21,450 --> 00:11:24,223
really warrants immediate
executive management

240
00:11:24,223 --> 00:11:28,440
and perhaps even board
of director attention.

241
00:11:28,440 --> 00:11:30,930
Risk treatment options to be evaluated,

242
00:11:30,930 --> 00:11:33,630
taking into consideration,
certainly, the risk appetite,

243
00:11:33,630 --> 00:11:37,833
include termination,
mitigation, or acceptance.

244
00:11:39,090 --> 00:11:41,700
Now acceptance, if we went down that path,

245
00:11:41,700 --> 00:11:43,380
would require stakeholders

246
00:11:43,380 --> 00:11:47,190
to acknowledge any risk exceptions.

247
00:11:47,190 --> 00:11:49,440
But here's what else I'd wanna know.

248
00:11:49,440 --> 00:11:51,540
If we've got these systemic issues

249
00:11:51,540 --> 00:11:53,626
and this consulting firm has been doing

250
00:11:53,626 --> 00:11:57,960
these annual risk assessments
year over year over year,

251
00:11:57,960 --> 00:12:00,450
how come we're only
hearing about them now?

252
00:12:00,450 --> 00:12:02,730
So I'd probably wanna
look a little bit closer

253
00:12:02,730 --> 00:12:04,890
at that consulting firm as well.

254
00:12:04,890 --> 00:12:07,650
Doing all that, security in action.

255
00:12:07,650 --> 00:12:08,640
There's your word cloud.

256
00:12:08,640 --> 00:12:09,600
You know what to do.

257
00:12:09,600 --> 00:12:11,049
There's a lot here

258
00:12:11,049 --> 00:12:12,510
and these are all really important topics.

259
00:12:12,510 --> 00:12:14,790
So make sure you're
comfortable and confident.

260
00:12:14,790 --> 00:12:16,860
And when you are, head on
over to the next lesson

261
00:12:16,860 --> 00:12:18,560
and I'll be waiting for you there.
