risk assessment on information security

18
risk assessment on information security Angelo Sala - November 2010 http://www.flickr.com/photos/borghetti/43058749/

Post on 21-Oct-2014

973 views

Category:

Education


4 download

DESCRIPTION

 

TRANSCRIPT

Page 1: Risk assessment on information security

risk assessment on information securityAngelo Sala - November 2010

http://www.flickr.com/photos/borghetti/43058749/

Page 2: Risk assessment on information security

goal: to reduce risks related to

information security

http://www.flickr.com/photos/keylosa/184606430/

Page 3: Risk assessment on information security

you have to identify risk activities among

sensitive processes

http://www.flickr.com/photos/emiliano-iko/4045654001/

Page 4: Risk assessment on information security

1. IT (information technologies)

http://www.flickr.com/photos/johnseb/3425464/

identify risk factors …

Page 5: Risk assessment on information security

2. organization

http://www.flickr.com/photos/thomasguest/3581215442/

Page 6: Risk assessment on information security

3. human resources

http://www.flickr.com/photos/pietel/3468574846/

Page 7: Risk assessment on information security

4. environment

http://www.flickr.com/photos/theplanetdotcom/4878805271/

Page 8: Risk assessment on information security

identify and classify risks by

factors and …

http://www.flickr.com/photos/stephenpoff/3032885683/

Page 9: Risk assessment on information security

by information values

http://www.flickr.com/photos/sidelong/305305214/

1. data integrity

Page 10: Risk assessment on information security

2. confidentiality

http://www.flickr.com/photos/giltron/315026788/

Page 11: Risk assessment on information security

3. availability

http://www.flickr.com/photos/davidjwbailey/3676408544/

Page 12: Risk assessment on information security

you have to estimate bad

event probability

http://www.flickr.com/photos/jackpix/146384867/

Page 13: Risk assessment on information security

evaluate damages ($)

http://www.flickr.com/photos/dawn_perry/237343945/

Page 14: Risk assessment on information security

if the company reputation is involved

http://www.flickr.com/photos/striatic/2191404675/

so you get risk levels that could increase …

Page 15: Risk assessment on information security

.. and finally you have to establish mitigation actions

in order to reduce risk level

Page 16: Risk assessment on information security

Number of risks identified * (Middle & High level)

human resources

organization

IT

environment

45

5

11

27

* fake data

Page 17: Risk assessment on information security

Measured vs. Expected * risk index

31,5

9,5

15,5

20

22,5

12,25

6,25

16,5

human resources

organization

IT

environment

* fake data

Page 18: Risk assessment on information security

and then …

you’ll have to roll up your sleeves and start mitigation actions

http://www.flickr.com/photos/pennstatelive/5059771553/