TOPIC
Risk Management & Governance
Putting a number on risk, then deciding what to do about it: quantification, treatment and appetite, control types, and threat modeling. Plus the data governance vocabulary that decides classification questions. CISSP Domains 1 and 2.
Articles
Nothing filed here yet. It's on the list.
Key terms
The expected yearly cost of a risk: Single Loss Expectancy multiplied by Annualized Rate of Occurrence (ALE = SLE x ARO), the figure that justifies control spending in quantitative analysis.
A policy enforcement point between users and cloud services that delivers visibility, compliance, data security, and threat protection, including discovery of shadow IT.
An alternative control adopted when the primary control is impractical or too costly. It must meet the intent and rigour of the original requirement, not merely gesture at it.
The classification of security controls by the function they perform: preventive, detective, corrective, deterrent, recovery, and directive. One control can serve several functions at once.
The process of assigning sensitivity labels to information so that handling, storage, and access requirements follow from the label, and controls are selected to match it.
The technical role that implements data protection on the owner's behalf: backups, access permissions, patching, and secure storage. Responsible for the work, never accountable for the data.
Content-inspection technology that identifies sensitive data and enforces policy to stop it leaving the organisation, deployed at the network edge, on endpoints, or as discovery scans.
The senior business role accountable for a data set: the owner classifies the data, approves access, and sets protection requirements, and that accountability cannot be delegated.
The residual data that remains on storage media after deletion or formatting, recoverable until the media is properly cleared, purged, or destroyed.
The three conditions data occupies (at rest in storage, in transit across networks, in use during processing), each demanding its own distinct protection mechanisms.
The risk that remains after controls are applied. It can never reach zero, so leadership must formally accept whatever remains within the organisation's risk appetite.
The amount and type of risk leadership is willing to accept in pursuit of organisational objectives, set at board level and cascaded down as the boundary for every risk decision.
The decision on how to respond to an identified risk using one of four options: avoid it, transfer it, mitigate it, or accept it. Every identified risk gets exactly one deliberate response.
The top of the governance document hierarchy: a mandatory, high-level statement of management intent, implemented through standards and procedures and advised by guidelines.
The monetary loss from one occurrence of a risk event: asset value multiplied by exposure factor (SLE = AV x EF), the per-incident building block of quantitative risk analysis.
Microsoft's threat categorisation model: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege, each violating one security property.
Identifying and reducing the risks inherited from suppliers, vendors, and service providers: tampered hardware, counterfeit components, malicious implants, and compromised updates.
Systematic identification and rating of the threats a system faces, performed during design so weaknesses are engineered out before deployment rather than discovered in production.