<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>BestInternetSecurity.net &#187; Risk Management</title>
	<atom:link href="http://www.bestinternetsecurity.net/category/risk-management/feed" rel="self" type="application/rss+xml" />
	<link>http://www.bestinternetsecurity.net</link>
	<description>Information Security Resources</description>
	<lastBuildDate>Fri, 10 Jul 2009 02:27:12 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Being Humble: The right mind set for Corporate Governance and IT Governance</title>
		<link>http://www.bestinternetsecurity.net/284/being-humble-the-right-mind-set-for-corporate-governance-and-it-governance.html</link>
		<comments>http://www.bestinternetsecurity.net/284/being-humble-the-right-mind-set-for-corporate-governance-and-it-governance.html#comments</comments>
		<pubDate>Fri, 31 Oct 2008 06:25:37 +0000</pubDate>
		<dc:creator>Damen</dc:creator>
				<category><![CDATA[General Information Security]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Corporate Governance]]></category>
		<category><![CDATA[IT Governance]]></category>
		<category><![CDATA[Monty Hall Problem]]></category>
		<category><![CDATA[Risk Analysis]]></category>

		<guid isPermaLink="false">http://www.bestinternetsecurity.net/?p=284</guid>
		<description><![CDATA[For every first lesson I teach about Risk Management and Contingency Planning, I always like to raise an example to begin a discussion about the illusions of human beings.
This illusion is best illustrated by an interesting game called the Monty Hall Problem, which goes like this:
Suppose you are a lucky game show player who is [...]]]></description>
			<content:encoded><![CDATA[<p>For every first lesson I teach about Risk Management and Contingency Planning, I always like to raise an example to begin a discussion about the illusions of human beings.</p>
<p>This illusion is best illustrated by an interesting game called the Monty Hall Problem, which goes like this:</p>
<p>Suppose you are a lucky game show player who is picked to participate in a game. The game requires you to stand in front of the three doors. Behind one door is a car, and behind each of the other two doors is a goat. You are told to choose one of the doors, and if you choose the door to the car, you win the car.</p>
<p>The game requires you to make your choice, and then the host (who knows what is behind each door) will open one of the other two doors that he knows does not open to the car. According to the game rules, you have the chance to change your mind and choose the other remaining door, or remaining with your original choice.</p>
<p>The problem is: Should you pick the other remaining door, or trust your first choice? Would this decision make any difference in the chance of winning the car?</p>
<p>Most people will say that the chance is the same for whichever choice because you have half the chance to win the car out of the two remaining doors. It sounds logical, doesn’t it?</p>
<p>But let’s examine this carefully. Suppose you label these two strategies as:</p>
<p>Strategy A:  Remaining with the present door choice.</p>
<p>Strategy B:  Changing the choice to pick the other remaining door.</p>
<p>Let’s take a look at Strategy A first, where there are two outcomes:</p>
<p><span style="text-decoration: underline;">Strategy A, Outcome 1</span>: Your original door choice was the one if front of the car all along, and you win because you chose to remain with the first door you picked. The chance of you picking the door with the car at the beginning of the game was 1/3 because you had to choose one out of the three doors.<br />
<strong></strong></p>
<p><span style="text-decoration: underline;">Strategy A, Outcome 2</span>: Your original door choice was one of the two doors in front of a goat, and you lose because you chose to remain with this first door you picked.  There is 2/3 of chance for this scenario to take place, since two of the doors had goats behind them.</p>
<p>So for Strategy A, you had only a 1/3 chance to win the car.<br />
What about Strategy B, where you change your original choice?<br />
<strong></strong></p>
<p><span style="text-decoration: underline;">Strategy B, Outcome 1</span>:  You change your door choice, and unfortunately your new door choice is hiding the other goat. You lose. Remember you have 1/3 of chance in this outcome as discussed previously.<br />
<strong></strong></p>
<p><span style="text-decoration: underline;">Strategy B, Outcome 2</span>: You change your door choice, and open the door hiding the car. You win! And you have 2/3 of chance in this outcome. (If you’re interested in a full explanation of how the outcome changes to 2/3, search for the term “Monty Hall Problem” using your favorite search engine and you’ll find plenty of information.)</p>
<p>Looking at the problem this way, it’s quite obvious that Strategy B is a better choice, isn’t it?</p>
<p>Some of you might still feel confused. You might need to re-read the whole discussion above to clarify your thoughts.</p>
<p>Ultimately, this game illustrates one very important weakness of people: We tend to jump to conclusions for many problems too easily without careful analysis. And worst of all, we are usually over confident as to what we have concluded at the beginning.</p>
<p>This problem is closely related to the people issue in Information Security or Corporate Risk Management. People tend to overlook many possible system vulnerabilities when undergoing so-called “risk analysis”. They are not aware that they have been overly naïve when thinking about the possible threats to their system of operations.</p>
<p>It’s quite interesting that this phenomenon is well observed now, as there are so many financial institutions around the world running into their own financial problems because the people who run those organizations were too confident in themselves to manage the risks. And indeed, they seem to be completely blind to the possible exposure of managing and holding all those financial products they have on hand, without even thinking about the possible serious consequence of dragging down their own companies if things go against them. And indeed, it catches up to them in the end.</p>
<p>So in the risk management exercise of information security, the number one beneficial attitude is to be humble. We need to realize that we are not invincible, and be very careful in weighing all possible risks related to the information system we are using. We have to work out the plan in every step of risk management without the tendency to overlook or jump to conclusions too easily. Without the right mind set, we are very likely to fail to manage all possible risks properly.</p>
<p>Tags: Corporate Governance, IT Governance</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bestinternetsecurity.net/284/being-humble-the-right-mind-set-for-corporate-governance-and-it-governance.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is Risk, Vulnerabilities, Threats, and Countermeasures: Risk Management Lesson 101 for Information Security</title>
		<link>http://www.bestinternetsecurity.net/119/what-is-risk-vulnerabilities-threats-and-countermeasures-risk-management-lesson-101-for-information-security.html</link>
		<comments>http://www.bestinternetsecurity.net/119/what-is-risk-vulnerabilities-threats-and-countermeasures-risk-management-lesson-101-for-information-security.html#comments</comments>
		<pubDate>Mon, 11 Aug 2008 08:01:21 +0000</pubDate>
		<dc:creator>Damen</dc:creator>
				<category><![CDATA[General Information Security]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Security Management]]></category>
		<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[Countermeasure]]></category>
		<category><![CDATA[Information Owner]]></category>
		<category><![CDATA[Information Risk Management]]></category>
		<category><![CDATA[Information Security Management]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Risk mitigation]]></category>
		<category><![CDATA[Security Controls]]></category>
		<category><![CDATA[Threat Agents]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://www.bestinternetsecurity.net/?p=119</guid>
		<description><![CDATA[In this article, I will use layman’s terms and descriptions to help you understand the various fundamental concepts of Risk Management in Information Security.
To illustrate those concepts, I like to use a popular diagram1 from Common Criteria, shown below:

In the center of this diagram you’ll find the term vulnerabilities. Vulnerabilities are any weaknesses of a [...]]]></description>
			<content:encoded><![CDATA[<p>In this article, I will use layman’s terms and descriptions to help you understand the various fundamental concepts of Risk Management in Information Security.</p>
<p>To illustrate those concepts, I like to use a popular diagram<sup>1</sup> from <em>Common Criteria</em>, shown below:</p>
<p><a href="http://www.bestinternetsecurity.net/wp-content/uploads/2008/08/risk-threats-vulnerabilities.gif"><img class="aligncenter size-medium wp-image-120" title="risk-threats-vulnerabilities" src="http://www.bestinternetsecurity.net/wp-content/uploads/2008/08/risk-threats-vulnerabilities-300x209.gif" alt="" width="300" height="209" /></a></p>
<p>In the center of this diagram you’ll find the term vulnerabilities. <em><strong>Vulnerabilities</strong></em> are any weaknesses of a system. A system <em>always </em>contains vulnerabilities. You cannot build a 100% perfect system with no vulnerabilities, even if you have unlimited power, money, and time to build such a system. All systems contain imperfect components, and the integration of imperfect components produces an imperfect system that always possesses certain vulnerabilities.</p>
<p><em><strong>Threats</strong></em> are elements from various sources that can exploit vulnerabilities and that increase risk. <em><strong>Risk </strong></em>is the probability that the system’s asset will be damaged/abused by the threats that exploit the vulnerabilities. Assets can be tangible (such as hardware/software) or intangible (such as good will and customers’ confidence).</p>
<p>Threats can be initiated by <em><strong>threat agents</strong></em>. A common threat agent for IT systems is people. They can accidentally or intentionally exploit vulnerabilities of a system to impact an IT system.</p>
<p>In order to manage risk, we deploy <strong><em>countermeasures </em></strong>(controls) to a system to reduce the vulnerabilities. The decision to deploy certain countermeasures to reduce the vulnerabilities and hence reduce risk lies solely on the information owner, who bears all consequences arising from the risk.</p>
<p>In a formal risk management exercise, an organization should undergo an intense brainstorming session to discover all possible threats that can exploit the vulnerabilities of a system. The difficult part of this step is not determining whether a certain threat will cause risk to a system, but the effort required to locate all possible threats to a system. Anything overlooked could lead to possible serious exposure to risks that have not been identified.</p>
<p>It is of the utmost importance for the owner (the “Owners” in the diagram) of an organization to identify all possible threats to its information system to the very best of his/her effort and knowledge, in order to fulfill fiduciary duties to customers and other stakeholders. Without knowing what the risks are, it’s impossible to implement suitable countermeasures to contain and mitigate those risks.</p>
<p>Reference:</p>
<p><sup>1</sup>Picture from <em>Common Criteria</em></p>
<p><span style="text-decoration: underline;">http://www.commoncriteria.org/docs/PDF/CCPART1V21.PDF p.14</span></p>
<p>Tags: Vulnerability, Countermeasure, Security Controls, Risk mitigation, Information Security Management, Information Risk Management</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bestinternetsecurity.net/119/what-is-risk-vulnerabilities-threats-and-countermeasures-risk-management-lesson-101-for-information-security.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Information Risk Management : The Core Concept of Information Security Management</title>
		<link>http://www.bestinternetsecurity.net/22/information-risk-management-the-core-concept-of-information-security-management.html</link>
		<comments>http://www.bestinternetsecurity.net/22/information-risk-management-the-core-concept-of-information-security-management.html#comments</comments>
		<pubDate>Tue, 11 Mar 2008 15:05:52 +0000</pubDate>
		<dc:creator>Damen</dc:creator>
				<category><![CDATA[General Information Security]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Computer Security]]></category>
		<category><![CDATA[Exposure]]></category>
		<category><![CDATA[Information Risk Management]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Information Security Management]]></category>
		<category><![CDATA[Risk mitigation]]></category>
		<category><![CDATA[Threat]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://www.bestinternetsecurity.net/22/information-risk-management-the-core-concept-of-information-security-management/</guid>
		<description><![CDATA[In today’s environment, Risk Management is considered a core management issue in modern corporate governance. We have been discussing this concept in several areas of finance. Now, we are considering the subject as it pertains to the area of Information Security (IS). This is an important consideration since, in the past thirty years, IS systems [...]]]></description>
			<content:encoded><![CDATA[<p>In today’s environment, Risk Management is considered a core management issue in modern corporate governance. We have been discussing this concept in several areas of finance. Now, we are considering the subject as it pertains to the area of Information Security (IS). This is an important consideration since, in the past thirty years, IS systems have grown to be a core component among many other operations within the corporate structure.</p>
<p>In order to understand Risk Management, some basic terms related to risk management should be understood. They are: Vulnerabilities, Threats, and Exposure.</p>
<p><strong><em>Vulnerability</em></strong> refers to the inherent weakness of an IS system. (“Inherent” simply means something that is internal to the system that you can’t easily eliminate completely.) The fact is, there is no system that is totally free from defects. No one-hundred-percent “bullet-proof” system can exist, simply due to the fact that a system is only as strong as its weakest point. There is no system in the world that is without weaknesses. One could not possibly be developed without unlimited resources to build, verify, and test the system.</p>
<p><strong><em>Threats</em></strong> are certain incidents that exploit the vulnerability of a system. Threats can be natural (such as a thunderstorm or earthquake), environmental (such as temperature or humidity), or intentional (such as hacking or virus spreading).</p>
<p><strong><em>Exposure</em></strong> refers to the damage that can be done if and when a threat successfully exploits the vulnerability of a system.</p>
<p>When there is a chance that a threat could exploit a system’s vulnerability, there is <strong><em>risk</em></strong>. In the field of information management, risk refers to the possible attack on an IS system by the threats made possible by its inherent vulnerabilities.</p>
<p>Risk includes the following properties:</p>
<ul>
<li><em>Risk cannot be totally eliminated.</em><br />
<strong>When a system possesses vulnerability, and it always does, there is risk.</strong></li>
<li><em>You can <span style="text-decoration: underline;">reduce</span> the risk, but not completely eliminate it.</em><br />
<strong>However, risk can only be reduced by carefully planned countermeasures.</strong></li>
<li><em>You can deal with residual risk by insuring the system.</em><br />
<strong>We call this process <em>Risk Mitigation</em>.</strong></li>
</ul>
<p><strong><em>Information Security Management</em></strong> is the art of dealing with risk using systematic and consistent management principles. This is not merely a technical issue—it is more likely a management issue. Therefore, Information Security Management is best achieved with the proper deployment of carefully planned corporate strategies to deal with Information Security risk.</p>
<p>Computer Security, Information Risk Management</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bestinternetsecurity.net/22/information-risk-management-the-core-concept-of-information-security-management.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
