Managing information resource security is managing the associated risk. But we can’t manage risk unless we know how to measure it effectively. That is the purpose of risk assessments.
In this video, I look at the risk factors we use in a formal process (quantitative, qualitative, and semi-quantitative) to understand the risk associated with an organization, a process, or a system. I then show how those factors are used in an example risk assessment, both with a risk matrix and risk calculator, an Excel-based calculator available for download in the video description.
~ Tom Olzak
==========
Table of Contents:
00:00 - Introduction
01:02 - What is Risk?
01:58 - What is Risk Management
02:23 - NIST Risk Management Framework
05:10 - What are assessments?
05:26 - How we use assessments
06:06 - Risk Factors
09:25 - Business Impact
11:16 - Quantitative Risk Assessment
15:59 - Attack Trees
23:27 - Use of Risk Matrix
24:33 - Semi-quantitative Assessment
27:47 - Managing the risk
==========
Video Script/Study Guide
https://adventuresinsecurity.com/_Sec...
==========
NIST SP 800-53r5 Security and Privacy Controls for Information Systems and Organizations
https://csrc.nist.gov/publications/de...
==========
Vulnerability Management and the CVSS Calculator
• Vulnerability Management and the CVSS Calc...
==========
Asset Classification
• Asset Classification
==========
Threat Modeling
• Threat Modeling
==========
Semi-quantitative Assessment Calculator
https://adventuresinsecurity.com//Too...