SlideShare a Scribd company logo
1 of 34
Download to read offline
@jkuemerle
Risk
Measurement
and
Management
Using Open
Source Tooling
Joe Kuemerle / joe@kuemerle.com / @jkuemerle
https://www.flickr.com/photos/carlbob/3983465822
@jkuemerle
Building CTFs To Teach Non-Security Folks
Everyone
Can
Play!
Joe Kuemerle / joe@kuemerle.com / @jkuemerle
https://upload.wikimedia.org/wikipedia/commons/5/5a/Muggle_Quidditch_Game_in_Vancouver_2.jpg
https://www.bsidesbos.org/
@jkuemerle
Agenda
★ Why
★ What
★ How
@jkuemerle
https://www.laughtard.com/16-funny-care-bear-memes/
@jkuemerle
https://www.flickr.com/photos/61547555@N00/5638292
7
@jkuemerle
https://www.flickr.com/photos/9140419@N07/628940027
@jkuemerle
https://www.flickr.com/photos/67953162@N00/3979679536
@jkuemerle
https://www.flickr.com/photos/68785404@N00/10506366393
@jkuemerle
https://www.flickr.com/photos/43056779@N00/276045711
9
@jkuemerle
https://www.flickr.com/photos/53586511@N00/172375525
@jkuemerle
https://wiki.owasp.org/index.php/OWASP_Risk_Rating_Methodology
https://www.flickr.com/photos/61547555@N00/3292559799
@jkuemerle
https://www.flickr.com/photos/67115587@N00/8102218300
@jkuemerle
Likelihood
★ Who has access to the system?
○ Restricted Internal Only
○ Internal only
○ Partner users
○ Authenticated customers
○ Anonymous Internet users
★ How exposed is the knowledge of the
system?
○ Confidential
○ Internal
○ Partner
○ Public knowledge (public
documentation, open source,
etc.)
Impact
★ What types of information could be
disclosed?
○ Public data
○ User/partner data or metadata
○ Administrative data or metadata
○ Authentication secrets
○ Compliance Data
★ What is the use case of the system?
○ Internal use only
○ Internal and Partner use only
○ Deprecated customer use
○ Deprecated public use
○ Standard customer use
○ Standard public use
○ Strategic customer use
○ Strategic public use
@jkuemerle
https://www.flickr.com/photos/51035555243@N01/5764768187
@jkuemerle
Likelihood Score = SUM(Likelihood) / COUNT(Likelihood)
Impact Score = SUM(Impact) / COUNT(Impact)
https://www.flickr.com/photos/83346641@N00/5002736203
@jkuemerle
Likelihood
★ Who has access to the system?
○ Restricted Internal Only
○ Internal only
○ Partner users
○ Authenticated customers
○ Anonymous Internet users
★ How exposed is the knowledge of the system?
○ Confidential
○ Internal
○ Partner
○ Public knowledge (public documentation, open source, etc.)
@jkuemerle
Likelihood Score = [SUM(Likelihood) / COUNT(Likelihood)] || Override
Impact Score = [SUM(Impact) / COUNT(Impact)] || Override
@jkuemerle
https://www.flickr.com/photos/58411470@N00/5279315937
@jkuemerle
Mitigating Factors
★ Technical debt
○ Very Low
○ Low
○ Moderate
○ High
○ Very High
★ Security Coverage
○ None
○ Some
○ Full
@jkuemerle
https://www.flickr.com/photos/17461430@N00/6069632056
@jkuemerle
Mitigation = (Value * Weightage) / Scale Factor
https://www.flickr.com/photos/83346641@N00/5016097457
@jkuemerle
★ Technical debt
○ Very Low
○ Low
○ Moderate
○ High
○ Very High
@jkuemerle
Residual Risk = Inherent Risk - Mitigation
Very Low - 1
Low - 2
Moderate - 3
High - 4
Very High - 5
@jkuemerle
https://www.flickr.com/photos/94796820@N00/1332626933
https://github.com/salesforce/salesforce-risk
@jkuemerle
https://www.flickr.com/photos/14934133@N00/14608937672
@jkuemerle
https://www.flickr.com/photos/51764518@N02/10787767575
@jkuemerle
https://www.flickr.com/photos/68613185@N00/141793036
@jkuemerle
https://www.flickr.com/photos/68894626@N00/2568228939
@jkuemerle
https://www.laughtard.com/16-funny-care-bear-memes/
@jkuemerle
https://www.flickr.com/photos/110200667@N08/11161124526
@jkuemerle
https://www.flickr.com/photos/74418647@N00/45763884161
@jkuemerle
Recap
★ Why
★ What
★ How
@jkuemerle
Next Steps
★ Take it with you
★ Feedback and suggestions
http://bit.ly/jkuemerle-feedback
★ Discuss & contribute
@jkuemerle
Resources
★ https://wiki.owasp.org/index.php/OWASP_Risk_Rating_Methodology
★ https://github.com/salesforce/salesforce-risk
★ Application Security Risk: Assessment and Modeling:
https://www.isaca.org/resources/isaca-journal/issues/2016/volume-2/a
pplication-security-risk-assessment-and-modeling
★ https://help.veracode.com/reader/kJC1iOtXp8N~rCtV8P9jhw/29ydXhnfF
nCOc5Rue0~3uA
★ OWASP SAMM Application Risk Profile:
https://owaspsamm.org/model/design/threat-assessment/stream-a/

More Related Content

What's hot

Clown around play laugh and smile
Clown around play laugh and smileClown around play laugh and smile
Clown around play laugh and smile
davidlashun
 
Disease terminology
Disease terminologyDisease terminology
Disease terminology
16joes
 
Velocity EU 2013 What is the velocity of an unladen swallow?
Velocity EU 2013 What is the velocity of an unladen swallow?Velocity EU 2013 What is the velocity of an unladen swallow?
Velocity EU 2013 What is the velocity of an unladen swallow?
pdyball
 
09 dc-diseases vocab-16 jaemins
09 dc-diseases vocab-16 jaemins09 dc-diseases vocab-16 jaemins
09 dc-diseases vocab-16 jaemins
Jae-Min Shin
 
Humrich shane ignite_slideshow
Humrich shane ignite_slideshowHumrich shane ignite_slideshow
Humrich shane ignite_slideshow
Shane Humrich
 
Mc collum meghan-slideshow
Mc collum meghan-slideshowMc collum meghan-slideshow
Mc collum meghan-slideshow
meghanmccollum47
 

What's hot (19)

Presentation Delivery and Design
Presentation Delivery and DesignPresentation Delivery and Design
Presentation Delivery and Design
 
Clown around play laugh and smile
Clown around play laugh and smileClown around play laugh and smile
Clown around play laugh and smile
 
Tots Too Hot : The Good, The Bad and the Ugly of Pediatric Fever
Tots Too Hot : The Good, The Bad and the Ugly of Pediatric FeverTots Too Hot : The Good, The Bad and the Ugly of Pediatric Fever
Tots Too Hot : The Good, The Bad and the Ugly of Pediatric Fever
 
Disease terminology
Disease terminologyDisease terminology
Disease terminology
 
Living with Laptops: Digital Citizenship for Parents
Living with Laptops: Digital Citizenship for ParentsLiving with Laptops: Digital Citizenship for Parents
Living with Laptops: Digital Citizenship for Parents
 
Velocity EU 2013 What is the velocity of an unladen swallow?
Velocity EU 2013 What is the velocity of an unladen swallow?Velocity EU 2013 What is the velocity of an unladen swallow?
Velocity EU 2013 What is the velocity of an unladen swallow?
 
#StoryTips
#StoryTips#StoryTips
#StoryTips
 
Internet Awareness 2011
Internet Awareness 2011Internet Awareness 2011
Internet Awareness 2011
 
09 dc-diseases vocab-16 jaemins
09 dc-diseases vocab-16 jaemins09 dc-diseases vocab-16 jaemins
09 dc-diseases vocab-16 jaemins
 
Humrich shane ignite_slideshow
Humrich shane ignite_slideshowHumrich shane ignite_slideshow
Humrich shane ignite_slideshow
 
If We Could Talk To The Animals
If We Could Talk To The AnimalsIf We Could Talk To The Animals
If We Could Talk To The Animals
 
Mc collum meghan-slideshow
Mc collum meghan-slideshowMc collum meghan-slideshow
Mc collum meghan-slideshow
 
Social Business: Be Social, Don't Use Social
Social Business: Be Social, Don't Use SocialSocial Business: Be Social, Don't Use Social
Social Business: Be Social, Don't Use Social
 
Destruir para Construir
Destruir para ConstruirDestruir para Construir
Destruir para Construir
 
Mystory
MystoryMystory
Mystory
 
Making A Lasting Impression (Version 2)
Making A Lasting Impression (Version 2)Making A Lasting Impression (Version 2)
Making A Lasting Impression (Version 2)
 
Words In Images
Words In ImagesWords In Images
Words In Images
 
Connected Learning Community Orientation
Connected Learning Community OrientationConnected Learning Community Orientation
Connected Learning Community Orientation
 
3 Steps To Success With Social Selling.
3 Steps To Success With Social Selling.3 Steps To Success With Social Selling.
3 Steps To Success With Social Selling.
 

Similar to Risk Measurement and Management Using Open Source Tooling

My Life as A Sponge #altc2013 Invited Speaker session
My Life as A Sponge  #altc2013 Invited Speaker session My Life as A Sponge  #altc2013 Invited Speaker session
My Life as A Sponge #altc2013 Invited Speaker session
Sheila MacNeill
 
Video Games are not the Enemy
Video Games are not the EnemyVideo Games are not the Enemy
Video Games are not the Enemy
FSimpson24
 
Raising Awareness in Regards to Food Depravation
Raising Awareness in Regards to Food DepravationRaising Awareness in Regards to Food Depravation
Raising Awareness in Regards to Food Depravation
Joel M
 
Scrum in the Wild at #dpc10
Scrum in the Wild at #dpc10Scrum in the Wild at #dpc10
Scrum in the Wild at #dpc10
Mike van Riel
 
もし永和の新入社員がケントベックの『テスト駆動開発入門』を読んだら
もし永和の新入社員がケントベックの『テスト駆動開発入門』を読んだらもし永和の新入社員がケントベックの『テスト駆動開発入門』を読んだら
もし永和の新入社員がケントベックの『テスト駆動開発入門』を読んだら
Kenichi Takahashi
 

Similar to Risk Measurement and Management Using Open Source Tooling (20)

Playful IAs @ Euro IA Summit 2007
Playful IAs @ Euro IA Summit 2007Playful IAs @ Euro IA Summit 2007
Playful IAs @ Euro IA Summit 2007
 
The Ecology of Information: A Future in a Library Without Walls
The Ecology of Information:  A Future in a Library Without WallsThe Ecology of Information:  A Future in a Library Without Walls
The Ecology of Information: A Future in a Library Without Walls
 
Functional Interaction Design
Functional Interaction DesignFunctional Interaction Design
Functional Interaction Design
 
My Life as A Sponge #altc2013 Invited Speaker session
My Life as A Sponge  #altc2013 Invited Speaker session My Life as A Sponge  #altc2013 Invited Speaker session
My Life as A Sponge #altc2013 Invited Speaker session
 
Computer Gaming Vs Console Gaming
Computer Gaming Vs Console GamingComputer Gaming Vs Console Gaming
Computer Gaming Vs Console Gaming
 
Presentation design and delivery
Presentation design and deliveryPresentation design and delivery
Presentation design and delivery
 
Video Games are not the Enemy
Video Games are not the EnemyVideo Games are not the Enemy
Video Games are not the Enemy
 
Raising Awareness in Regards to Food Depravation
Raising Awareness in Regards to Food DepravationRaising Awareness in Regards to Food Depravation
Raising Awareness in Regards to Food Depravation
 
What do we keep and what do we throw away?
What do we keep and what do we throw away?What do we keep and what do we throw away?
What do we keep and what do we throw away?
 
Presentation Design and Delivery Tips
Presentation Design and Delivery TipsPresentation Design and Delivery Tips
Presentation Design and Delivery Tips
 
Bitrzr - Ignite Portugal Tecnológico
Bitrzr  - Ignite Portugal TecnológicoBitrzr  - Ignite Portugal Tecnológico
Bitrzr - Ignite Portugal Tecnológico
 
Usability testing and Silverback (in Japanese)
Usability testing and Silverback (in Japanese)Usability testing and Silverback (in Japanese)
Usability testing and Silverback (in Japanese)
 
Scrum in the Wild at #dpc10
Scrum in the Wild at #dpc10Scrum in the Wild at #dpc10
Scrum in the Wild at #dpc10
 
もし永和の新入社員がケントベックの『テスト駆動開発入門』を読んだら
もし永和の新入社員がケントベックの『テスト駆動開発入門』を読んだらもし永和の新入社員がケントベックの『テスト駆動開発入門』を読んだら
もし永和の新入社員がケントベックの『テスト駆動開発入門』を読んだら
 
The Shape of Alpha
The Shape of AlphaThe Shape of Alpha
The Shape of Alpha
 
Branch_Derrick_4.4
Branch_Derrick_4.4Branch_Derrick_4.4
Branch_Derrick_4.4
 
TEDx Seattle 2013
TEDx Seattle 2013TEDx Seattle 2013
TEDx Seattle 2013
 
TEDx Seattle 2013
TEDx Seattle 2013TEDx Seattle 2013
TEDx Seattle 2013
 
PCP-O Storyboard
PCP-O StoryboardPCP-O Storyboard
PCP-O Storyboard
 
Re:build 2011: Passion -> Startup
Re:build 2011: Passion -> StartupRe:build 2011: Passion -> Startup
Re:build 2011: Passion -> Startup
 

Recently uploaded

TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Victor Rentea
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 

Recently uploaded (20)

DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Six Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal OntologySix Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal Ontology
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
How to Check CNIC Information Online with Pakdata cf
How to Check CNIC Information Online with Pakdata cfHow to Check CNIC Information Online with Pakdata cf
How to Check CNIC Information Online with Pakdata cf
 
API Governance and Monetization - The evolution of API governance
API Governance and Monetization -  The evolution of API governanceAPI Governance and Monetization -  The evolution of API governance
API Governance and Monetization - The evolution of API governance
 
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
 
ChatGPT and Beyond - Elevating DevOps Productivity
ChatGPT and Beyond - Elevating DevOps ProductivityChatGPT and Beyond - Elevating DevOps Productivity
ChatGPT and Beyond - Elevating DevOps Productivity
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Introduction to use of FHIR Documents in ABDM
Introduction to use of FHIR Documents in ABDMIntroduction to use of FHIR Documents in ABDM
Introduction to use of FHIR Documents in ABDM
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 
Platformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityPlatformless Horizons for Digital Adaptability
Platformless Horizons for Digital Adaptability
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
AI in Action: Real World Use Cases by Anitaraj
AI in Action: Real World Use Cases by AnitarajAI in Action: Real World Use Cases by Anitaraj
AI in Action: Real World Use Cases by Anitaraj
 

Risk Measurement and Management Using Open Source Tooling