SlideShare a Scribd company logo
FSO Consulting Services




Introduction to

RISK MANAGEMENT
FSO Consulting Services


RISK MANAGEMENT

 Risk and Risk Factors
 Risk Assessment

 Ways to Address Risk

 Applying Controls to Reduce Risk

 Managing Risk

 Discussion
FSO Consulting Services


WHAT IS RISK? WHAT IS A THREAT?

Risk is where assets, vulnerabilities,
         and threats intersect.



                       RISK



                       Threats
FSO Consulting Services


WHAT IS RISK? WHAT IS A THREAT?




 A threat is something (or someone)
  that could have a negative impact
        on something of value.
FSO Consulting Services


RISK FACTORS

   Factors are elements that are multiplied to
    determine risk
     Seriousness   – how harmful is the threat?
     Likelihood – what are the chances the threat will
      exploit a vulnerability?

     Vulnerability   – a weakness that could be
      exploited
     Impact – what will the damage be if exploited?
FSO Consulting Services


IDENTIFYING THREATS

Identify from two angles
 Where the threat might come from
     Everhear of China or Iran?
     What about insider threats?

     How about that Internet thing?

   What kinds of problems might arise?
     Shortage of cleared people?
     Scope creep?
FSO Consulting Services


RISK ASSESSMENT: SCORING

   Create a matrix of threats and factors:

         Threat        Seriousness   Likelihood   Vulnerability   Impact   Score

      Cyber attack:        4             4             5            4      320
      hostile nation
FSO Consulting Services


REDUCING RISK

What can you do?
 Eliminate the threat

 Reduce the seriousness of the threat

 Reduce the likelihood of the threat

 Reduce your vulnerability

 Lower the impact
FSO Consulting Services


REDUCING RISK

What can you do?
 Eliminate the threat

 Reduce the seriousness of the threat

 Reduce the likelihood of the threat

 Reduce your vulnerability

 Lower the impact
FSO Consulting Services


RISK ASSESSMENT: SCORING

   Apply controls
     Forexample, install a UTM appliance
     Rescore:

         Threat        Seriousness   Likelihood   Vulnerability   Impact   Score

      Cyber attack:        4             4             2            4      128
      hostile nation



     Harden   servers to reduce the impact of an
      intrusion
     You could cut that score in half
FSO Consulting Services


ADDRESSING RISK

Ways to address risk?
 Risk avoidance
       Also reduces opportunity
   Risk transfer
       Insurance, partnerships,
        coalitions
   Risk acceptance
       Do nothing
FSO Consulting Services


RISK MANAGEMENT

 Identify Risk
 Assess Risk

 Reduce Risk

 Manage Risk
     Re-assess  periodically
     Add new threats when identified

     Address in priority order

     Keep risk at an acceptable level
FSO Consulting Services


DISCUSSION & QUESTIONS

More Related Content

Similar to Risk management

What cybersecurity risk management entails
What cybersecurity risk management entailsWhat cybersecurity risk management entails
What cybersecurity risk management entails
Cyberhunter Cyber Security
 
Riskpro Insurance Services Ver5
Riskpro Insurance Services Ver5Riskpro Insurance Services Ver5
Riskpro Insurance Services Ver5
Rahul Bhan (CA, CIA, MBA)
 
Riskpro Insurance Services Ver5
Riskpro Insurance Services Ver5Riskpro Insurance Services Ver5
Riskpro Insurance Services Ver5
Rahul Bhan (CA, CIA, MBA)
 
Economically driven Cyber Risk Management
Economically driven Cyber Risk ManagementEconomically driven Cyber Risk Management
Economically driven Cyber Risk Management
Osama Salah
 
Fraud risk services 2013
Fraud risk services 2013Fraud risk services 2013
Fraud risk services 2013
Rahul Bhan (CA, CIA, MBA)
 
Fraud risk services 2013
Fraud risk services 2013Fraud risk services 2013
Fraud risk services 2013
Rahul Bhan (CA, CIA, MBA)
 
Fraud risk services 2013
Fraud risk services 2013Fraud risk services 2013
Fraud risk services 2013
Rahul Bhan (CA, CIA, MBA)
 
Fraud risk services 2013
Fraud risk services 2013Fraud risk services 2013
Fraud risk services 2013
Rahul Bhan (CA, CIA, MBA)
 
Risk Management Certification
Risk Management CertificationRisk Management Certification
Risk Management Certification
Rahul Bhan (CA, CIA, MBA)
 
Risk Management Certification
Risk Management CertificationRisk Management Certification
Risk Management Certification
Rahul Bhan (CA, CIA, MBA)
 
How MSPs and MDRs Can Work Together.pdf
How MSPs and MDRs Can Work Together.pdfHow MSPs and MDRs Can Work Together.pdf
How MSPs and MDRs Can Work Together.pdf
Vijilan IT Security solutions
 
Risk Management
Risk ManagementRisk Management
Risk Management
Lifelong Learning
 
People Risk Collateral
People Risk CollateralPeople Risk Collateral
People Risk Collateral
Rahul Bhan (CA, CIA, MBA)
 
People Risk Collateral
People Risk CollateralPeople Risk Collateral
People Risk Collateral
Rahul Bhan (CA, CIA, MBA)
 
People risk collateral 2013
People risk collateral 2013People risk collateral 2013
People risk collateral 2013
Rahul Bhan (CA, CIA, MBA)
 
People risk collateral 2013
People risk collateral 2013People risk collateral 2013
People risk collateral 2013
Rahul Bhan (CA, CIA, MBA)
 
Riskpro iso 31000 services 2013
Riskpro iso 31000 services 2013Riskpro iso 31000 services 2013
Riskpro iso 31000 services 2013
Rahul Bhan (CA, CIA, MBA)
 
Riskpro iso 31000 services 2013
Riskpro iso 31000 services 2013Riskpro iso 31000 services 2013
Riskpro iso 31000 services 2013
Rahul Bhan (CA, CIA, MBA)
 
Crash Course: Managing Cyber Risk Using Quantitative Analysis
Crash Course: Managing Cyber Risk Using Quantitative AnalysisCrash Course: Managing Cyber Risk Using Quantitative Analysis
Crash Course: Managing Cyber Risk Using Quantitative Analysis
"Apolonio \"Apps\"" Garcia
 
Hris Pre Mortem
Hris  Pre MortemHris  Pre Mortem
Hris Pre Mortem
Dimitry Shlyonsky
 

Similar to Risk management (20)

What cybersecurity risk management entails
What cybersecurity risk management entailsWhat cybersecurity risk management entails
What cybersecurity risk management entails
 
Riskpro Insurance Services Ver5
Riskpro Insurance Services Ver5Riskpro Insurance Services Ver5
Riskpro Insurance Services Ver5
 
Riskpro Insurance Services Ver5
Riskpro Insurance Services Ver5Riskpro Insurance Services Ver5
Riskpro Insurance Services Ver5
 
Economically driven Cyber Risk Management
Economically driven Cyber Risk ManagementEconomically driven Cyber Risk Management
Economically driven Cyber Risk Management
 
Fraud risk services 2013
Fraud risk services 2013Fraud risk services 2013
Fraud risk services 2013
 
Fraud risk services 2013
Fraud risk services 2013Fraud risk services 2013
Fraud risk services 2013
 
Fraud risk services 2013
Fraud risk services 2013Fraud risk services 2013
Fraud risk services 2013
 
Fraud risk services 2013
Fraud risk services 2013Fraud risk services 2013
Fraud risk services 2013
 
Risk Management Certification
Risk Management CertificationRisk Management Certification
Risk Management Certification
 
Risk Management Certification
Risk Management CertificationRisk Management Certification
Risk Management Certification
 
How MSPs and MDRs Can Work Together.pdf
How MSPs and MDRs Can Work Together.pdfHow MSPs and MDRs Can Work Together.pdf
How MSPs and MDRs Can Work Together.pdf
 
Risk Management
Risk ManagementRisk Management
Risk Management
 
People Risk Collateral
People Risk CollateralPeople Risk Collateral
People Risk Collateral
 
People Risk Collateral
People Risk CollateralPeople Risk Collateral
People Risk Collateral
 
People risk collateral 2013
People risk collateral 2013People risk collateral 2013
People risk collateral 2013
 
People risk collateral 2013
People risk collateral 2013People risk collateral 2013
People risk collateral 2013
 
Riskpro iso 31000 services 2013
Riskpro iso 31000 services 2013Riskpro iso 31000 services 2013
Riskpro iso 31000 services 2013
 
Riskpro iso 31000 services 2013
Riskpro iso 31000 services 2013Riskpro iso 31000 services 2013
Riskpro iso 31000 services 2013
 
Crash Course: Managing Cyber Risk Using Quantitative Analysis
Crash Course: Managing Cyber Risk Using Quantitative AnalysisCrash Course: Managing Cyber Risk Using Quantitative Analysis
Crash Course: Managing Cyber Risk Using Quantitative Analysis
 
Hris Pre Mortem
Hris  Pre MortemHris  Pre Mortem
Hris Pre Mortem
 

Recently uploaded

3 Simple Steps To Buy Verified Payoneer Account In 2024
3 Simple Steps To Buy Verified Payoneer Account In 20243 Simple Steps To Buy Verified Payoneer Account In 2024
3 Simple Steps To Buy Verified Payoneer Account In 2024
SEOSMMEARTH
 
Part 2 Deep Dive: Navigating the 2024 Slowdown
Part 2 Deep Dive: Navigating the 2024 SlowdownPart 2 Deep Dive: Navigating the 2024 Slowdown
Part 2 Deep Dive: Navigating the 2024 Slowdown
jeffkluth1
 
2022 Vintage Roman Numerals Men Rings
2022 Vintage Roman  Numerals  Men  Rings2022 Vintage Roman  Numerals  Men  Rings
2022 Vintage Roman Numerals Men Rings
aragme
 
list of states and organizations .pdf
list of  states  and  organizations .pdflist of  states  and  organizations .pdf
list of states and organizations .pdf
Rbc Rbcua
 
The Genesis of BriansClub.cm Famous Dark WEb Platform
The Genesis of BriansClub.cm Famous Dark WEb PlatformThe Genesis of BriansClub.cm Famous Dark WEb Platform
The Genesis of BriansClub.cm Famous Dark WEb Platform
SabaaSudozai
 
Anny Serafina Love - Letter of Recommendation by Kellen Harkins, MS.
Anny Serafina Love - Letter of Recommendation by Kellen Harkins, MS.Anny Serafina Love - Letter of Recommendation by Kellen Harkins, MS.
Anny Serafina Love - Letter of Recommendation by Kellen Harkins, MS.
AnnySerafinaLove
 
GKohler - Retail Scavenger Hunt Presentation
GKohler - Retail Scavenger Hunt PresentationGKohler - Retail Scavenger Hunt Presentation
GKohler - Retail Scavenger Hunt Presentation
GraceKohler1
 
Digital Marketing with a Focus on Sustainability
Digital Marketing with a Focus on SustainabilityDigital Marketing with a Focus on Sustainability
Digital Marketing with a Focus on Sustainability
sssourabhsharma
 
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
taqyea
 
Best Competitive Marble Pricing in Dubai - ☎ 9928909666
Best Competitive Marble Pricing in Dubai - ☎ 9928909666Best Competitive Marble Pricing in Dubai - ☎ 9928909666
Best Competitive Marble Pricing in Dubai - ☎ 9928909666
Stone Art Hub
 
2024-6-01-IMPACTSilver-Corp-Presentation.pdf
2024-6-01-IMPACTSilver-Corp-Presentation.pdf2024-6-01-IMPACTSilver-Corp-Presentation.pdf
2024-6-01-IMPACTSilver-Corp-Presentation.pdf
hartfordclub1
 
Industrial Tech SW: Category Renewal and Creation
Industrial Tech SW:  Category Renewal and CreationIndustrial Tech SW:  Category Renewal and Creation
Industrial Tech SW: Category Renewal and Creation
Christian Dahlen
 
How are Lilac French Bulldogs Beauty Charming the World and Capturing Hearts....
How are Lilac French Bulldogs Beauty Charming the World and Capturing Hearts....How are Lilac French Bulldogs Beauty Charming the World and Capturing Hearts....
How are Lilac French Bulldogs Beauty Charming the World and Capturing Hearts....
Lacey Max
 
Chapter 7 Final business management sciences .ppt
Chapter 7 Final business management sciences .pptChapter 7 Final business management sciences .ppt
Chapter 7 Final business management sciences .ppt
ssuser567e2d
 
Zodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
Zodiac Signs and Food Preferences_ What Your Sign Says About Your TasteZodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
Zodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
my Pandit
 
The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...
The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...
The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...
APCO
 
Registered-Establishment-List-in-Uttarakhand-pdf.pdf
Registered-Establishment-List-in-Uttarakhand-pdf.pdfRegistered-Establishment-List-in-Uttarakhand-pdf.pdf
Registered-Establishment-List-in-Uttarakhand-pdf.pdf
dazzjoker
 
Pitch Deck Teardown: Kinnect's $250k Angel deck
Pitch Deck Teardown: Kinnect's $250k Angel deckPitch Deck Teardown: Kinnect's $250k Angel deck
Pitch Deck Teardown: Kinnect's $250k Angel deck
HajeJanKamps
 
How MJ Global Leads the Packaging Industry.pdf
How MJ Global Leads the Packaging Industry.pdfHow MJ Global Leads the Packaging Industry.pdf
How MJ Global Leads the Packaging Industry.pdf
MJ Global
 
DearbornMusic-KatherineJasperFullSailUni
DearbornMusic-KatherineJasperFullSailUniDearbornMusic-KatherineJasperFullSailUni
DearbornMusic-KatherineJasperFullSailUni
katiejasper96
 

Recently uploaded (20)

3 Simple Steps To Buy Verified Payoneer Account In 2024
3 Simple Steps To Buy Verified Payoneer Account In 20243 Simple Steps To Buy Verified Payoneer Account In 2024
3 Simple Steps To Buy Verified Payoneer Account In 2024
 
Part 2 Deep Dive: Navigating the 2024 Slowdown
Part 2 Deep Dive: Navigating the 2024 SlowdownPart 2 Deep Dive: Navigating the 2024 Slowdown
Part 2 Deep Dive: Navigating the 2024 Slowdown
 
2022 Vintage Roman Numerals Men Rings
2022 Vintage Roman  Numerals  Men  Rings2022 Vintage Roman  Numerals  Men  Rings
2022 Vintage Roman Numerals Men Rings
 
list of states and organizations .pdf
list of  states  and  organizations .pdflist of  states  and  organizations .pdf
list of states and organizations .pdf
 
The Genesis of BriansClub.cm Famous Dark WEb Platform
The Genesis of BriansClub.cm Famous Dark WEb PlatformThe Genesis of BriansClub.cm Famous Dark WEb Platform
The Genesis of BriansClub.cm Famous Dark WEb Platform
 
Anny Serafina Love - Letter of Recommendation by Kellen Harkins, MS.
Anny Serafina Love - Letter of Recommendation by Kellen Harkins, MS.Anny Serafina Love - Letter of Recommendation by Kellen Harkins, MS.
Anny Serafina Love - Letter of Recommendation by Kellen Harkins, MS.
 
GKohler - Retail Scavenger Hunt Presentation
GKohler - Retail Scavenger Hunt PresentationGKohler - Retail Scavenger Hunt Presentation
GKohler - Retail Scavenger Hunt Presentation
 
Digital Marketing with a Focus on Sustainability
Digital Marketing with a Focus on SustainabilityDigital Marketing with a Focus on Sustainability
Digital Marketing with a Focus on Sustainability
 
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
 
Best Competitive Marble Pricing in Dubai - ☎ 9928909666
Best Competitive Marble Pricing in Dubai - ☎ 9928909666Best Competitive Marble Pricing in Dubai - ☎ 9928909666
Best Competitive Marble Pricing in Dubai - ☎ 9928909666
 
2024-6-01-IMPACTSilver-Corp-Presentation.pdf
2024-6-01-IMPACTSilver-Corp-Presentation.pdf2024-6-01-IMPACTSilver-Corp-Presentation.pdf
2024-6-01-IMPACTSilver-Corp-Presentation.pdf
 
Industrial Tech SW: Category Renewal and Creation
Industrial Tech SW:  Category Renewal and CreationIndustrial Tech SW:  Category Renewal and Creation
Industrial Tech SW: Category Renewal and Creation
 
How are Lilac French Bulldogs Beauty Charming the World and Capturing Hearts....
How are Lilac French Bulldogs Beauty Charming the World and Capturing Hearts....How are Lilac French Bulldogs Beauty Charming the World and Capturing Hearts....
How are Lilac French Bulldogs Beauty Charming the World and Capturing Hearts....
 
Chapter 7 Final business management sciences .ppt
Chapter 7 Final business management sciences .pptChapter 7 Final business management sciences .ppt
Chapter 7 Final business management sciences .ppt
 
Zodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
Zodiac Signs and Food Preferences_ What Your Sign Says About Your TasteZodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
Zodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
 
The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...
The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...
The APCO Geopolitical Radar - Q3 2024 The Global Operating Environment for Bu...
 
Registered-Establishment-List-in-Uttarakhand-pdf.pdf
Registered-Establishment-List-in-Uttarakhand-pdf.pdfRegistered-Establishment-List-in-Uttarakhand-pdf.pdf
Registered-Establishment-List-in-Uttarakhand-pdf.pdf
 
Pitch Deck Teardown: Kinnect's $250k Angel deck
Pitch Deck Teardown: Kinnect's $250k Angel deckPitch Deck Teardown: Kinnect's $250k Angel deck
Pitch Deck Teardown: Kinnect's $250k Angel deck
 
How MJ Global Leads the Packaging Industry.pdf
How MJ Global Leads the Packaging Industry.pdfHow MJ Global Leads the Packaging Industry.pdf
How MJ Global Leads the Packaging Industry.pdf
 
DearbornMusic-KatherineJasperFullSailUni
DearbornMusic-KatherineJasperFullSailUniDearbornMusic-KatherineJasperFullSailUni
DearbornMusic-KatherineJasperFullSailUni
 

Risk management

  • 2. FSO Consulting Services RISK MANAGEMENT  Risk and Risk Factors  Risk Assessment  Ways to Address Risk  Applying Controls to Reduce Risk  Managing Risk  Discussion
  • 3. FSO Consulting Services WHAT IS RISK? WHAT IS A THREAT? Risk is where assets, vulnerabilities, and threats intersect. RISK Threats
  • 4. FSO Consulting Services WHAT IS RISK? WHAT IS A THREAT? A threat is something (or someone) that could have a negative impact on something of value.
  • 5. FSO Consulting Services RISK FACTORS  Factors are elements that are multiplied to determine risk  Seriousness – how harmful is the threat?  Likelihood – what are the chances the threat will exploit a vulnerability?  Vulnerability – a weakness that could be exploited  Impact – what will the damage be if exploited?
  • 6. FSO Consulting Services IDENTIFYING THREATS Identify from two angles  Where the threat might come from  Everhear of China or Iran?  What about insider threats?  How about that Internet thing?  What kinds of problems might arise?  Shortage of cleared people?  Scope creep?
  • 7. FSO Consulting Services RISK ASSESSMENT: SCORING  Create a matrix of threats and factors: Threat Seriousness Likelihood Vulnerability Impact Score Cyber attack: 4 4 5 4 320 hostile nation
  • 8. FSO Consulting Services REDUCING RISK What can you do?  Eliminate the threat  Reduce the seriousness of the threat  Reduce the likelihood of the threat  Reduce your vulnerability  Lower the impact
  • 9. FSO Consulting Services REDUCING RISK What can you do?  Eliminate the threat  Reduce the seriousness of the threat  Reduce the likelihood of the threat  Reduce your vulnerability  Lower the impact
  • 10. FSO Consulting Services RISK ASSESSMENT: SCORING  Apply controls  Forexample, install a UTM appliance  Rescore: Threat Seriousness Likelihood Vulnerability Impact Score Cyber attack: 4 4 2 4 128 hostile nation  Harden servers to reduce the impact of an intrusion  You could cut that score in half
  • 11. FSO Consulting Services ADDRESSING RISK Ways to address risk?  Risk avoidance  Also reduces opportunity  Risk transfer  Insurance, partnerships, coalitions  Risk acceptance  Do nothing
  • 12. FSO Consulting Services RISK MANAGEMENT  Identify Risk  Assess Risk  Reduce Risk  Manage Risk  Re-assess periodically  Add new threats when identified  Address in priority order  Keep risk at an acceptable level

Editor's Notes

  1. If you have assets of value, and those assets are vulnerable to loss or damage, you have risk.
  2. If you have assets of value, and those assets are vulnerable to loss or damage, you have risk.
  3. Risk factors. Factor means multiply.
  4. Eliminate threat through risk avoidance, but also eliminate opportunity
  5. Unified Threat Management: Firewall, Intrusion Prevention, Anti-virus, etc. The risk score drops from 320 to 128 (over half). What could you do next? Harden servers so that even if they get inside your firewall they won’t be as able to cause damage.