Management of Information Security, Fourth Edition 9-1
Chapter 9
Risk Management: Controlling Risk
At a Glance
Instructor’s Manual Table of Contents
Overview
Objectives
Teaching Tips
Management of Information Security, Fourth Edition 9-2
Lecture Notes
Overview
In this chapter, students are introduced to different risk control strategies and how they can
be utilized within an organization to manage risk. The use basics of cost-benefit analysis
Chapter Objectives
After reading this chapter and completing the exercises, the student will be able to:
Recognize the strategy options used to control risk and be prepared to select from them
when given background information
Teaching Tips
Introduction
1. Explain how corporations have previously used IT systems to gain competitive
Risk Control Strategies
1. Explain to students that once a ranked vulnerability worksheet has been created, one of
the following five basic strategies must be chosen to control risks:
a. Defense
Defense
1. Define the defense risk strategy as a prevention-oriented strategy to avoid exploitation
of vulnerability.
Management of Information Security, Fourth Edition 9-3
Transferal
1. Describe the transferal risk strategy as attempting to shift risk onto other assets,
processes, or organizations. Provide examples of how this might be accomplished, such
as via outsourcing.
Mitigation
1. Introduce the mitigation risk strategy as a control approach that attempts to reduce, by
Acceptance
1. Explain the acceptance risk strategy as a decision to do nothing to protect an asset
against a given risk.
Termination
1. Define the termination risk strategy as an organization’s need or choice not to protect
an asset. Point out that this can occur when the cost of protecting an asset outweighs its
value.
Teaching
Tip
More information about risk control strategies can be found in the following
document from Zurich Insurance Group:
Management of Information Security, Fourth Edition 9-4
Managing Risk
1. Risk appetite, or risk tolerance, should be explained as the quantity and nature of risk
that an organization is willing to accept.
2. Describe residual risk in comparison as the amount of risk that remains after an
organization implements policy, education, and training.
3. Explain the goal of InfoSec as the attempt to bring residual risk in line with an
organization’s risk appetite.
Quick Quiz 1
1. When an organization falls behind its competition, a(n) ____________________ exists
between the two organizations.
2. True or False: An example of using the transferal risk control strategy would be to
outsource the security of an asset to another organization.
3. Which of the following is NOT one of the three types of plans included in a mitigation
risk control strategy?
A. Incident response (IR) plan
B. Disaster recovery (DR) plan
C. Business continuity (BC) plan
D. Risk control plan (RC)
4. When is the acceptance risk control strategy NOT an acceptable approach?
A. The cost of protecting an asset is more than the asset is worth
B. The asset consists of employee and / or customer information
C. The asset is considered expendable
D. The asset has relatively little risk
Management of Information Security, Fourth Edition 9-5
5. Which risk strategy approach can also be referred to as an avoidance strategy?
A. Termination
B. Acceptance
C. Defense
D. Transferal
Feasibility and Cost-Benefit Analysis
1. Students should be aware of the need to explore all readily available information on
Cost-Benefit Analysis
1. Emphasize the importance of economic feasibility when evaluating a strategy to
implement InfoSec controls and safeguards.
2. Describe an economic feasibility study, or cost-benefit analysis (CBA), as analysis
4. Note that benefit is the value to an organization gained by the use of controls to prevent
losses due to a specific vulnerability, and explain how it is determined by the use of
annualized loss expectancy (ALE).
value.
7. List some of the different approaches used by organizations to value information assets,
and explain how each is used:
a. Value retained from the cost of creating the information asset
b. Value retained from past maintenance of the information asset
Management of Information Security, Fourth Edition 9-6
8. Educate students on the calculation of potential loss from exploitation of vulnerability,
and provide students with questions that should be considered when performing loss
estimation.
9. Describe the single loss expectancy (SLE) as a value associated with the most likely
11. Define annualized loss expectancy (ALE) as the overall los potential per risk, which is
calculated using the results from an SLE multiplied by the values from an ARO.
12. Explain that a cost-benefit analysis (CBA) is used to determine whether a benefit from
Other Methods of Establishing Feasibility
1. Introduce students to organizational feasibility analysis, which examines which InfoSec
programs will contribute to efficiency, effectiveness, and overall operation of an
3. Educate students on how to achieve user acceptance and support by means of
communication, education, and involvement.
4. Technical feasibility should be explained as the determination of whether or not an
Alternatives to Feasibility Analysis
1. Provide students with a list of alternatives to the use of cost-benefit analysis, such as
benchmarking, due care and due diligence, use of best business practices, the gold
standard, government recommendations, and baselining.
Teaching
Tip
The following Wikipedia page provides additional information on cost-benefit
analysis:
Management of Information Security, Fourth Edition 9-7
Recommended Risk Control Practices
1. Explain to students how a control or safeguard might protect more than one asset-threat
calculation for a given asset or assets.
Qualitative and Hybrid Measures
1. Describe how to use a qualitative assessment, which uses labels to assess value rather
than numbers.
Delphi Technique
1. Introduce the Delphi technique, which involves the use of groups to rate or rank a set of
The OCTAVE Methods
1. Explain the Operationally Critical Threat, Asset, and Vulnerability Evaluation
(OCTAVE) Method, which allows an organization to balance protection of critical
assets against costs of implementing controls.
2. List the three different variations of the OCTAVE Method:
a. Original OCTAVE Method
Microsoft Risk Management Approach
1. Discuss the Microsoft risk management approach, as noted in its Security Risk
Management Guide, and note that it emphasizes the use of a general governance
Teaching
Information on the OCTAVE approach is available from the ISACA:
Management of Information Security, Fourth Edition 9-8
FAIR
1. Factor Analysis of Information Risk (FAIR) should be introduced as a risk management
framework that can assist with cost-effective risk management.
2. Describe some of the different components that make up the FAIR framework, such as
3. Educate students on the 10 steps of FAIR analysis, and the four stages in which they are
organized:
a. Stage 1Identify Scenario Components
i. Identify the asset at risk
ii. Identify the threat community under consideration
4. Point out that the FAIR framework uses the qualitative assessment of risk components,
and demonstrate how this is done.
ISO 27005 Standard for InfoSec Risk Management
1. Discuss the ISO 27005 standard for performance of risk management, and note the
five-stage risk management methodology:
a. Risk assessment
NIST Risk Management Model
Teaching
Tip
See the following link for a whitepaper on the use of FAIR, from Risk
Management Insight / CXOWARE:
Management of Information Security, Fourth Edition 9-9
1. Introduce the NIST Special Publication 800-39: Managing Information Security Risk:
Other Methods
1. Explain the European network and Information Security Agency (ENISA) as an agency
Quick Quiz 2
1. The ____________________ can be calculated using the values from an ARO
multiplied by the values from an SLE.
2. True or False: Asset valuation is the process of assigning financial value or worth to
each information asset.
3. Operational feasibility, which refers to user acceptance and support, as well as
management acceptance and support, is also known as __________.
4. Which risk management technique relies on a group evaluating, rating, and ranking
assets?
A. Delphi technique
B. OCTAVE methods
C. Microsoft’s technique
D. FAIR
5. What is the easiest way to calculate the cost-benefit analysis (CBA)?
A. CBA = ALE(postcontrol) ALE(precontrol) + ACS
B. CBA = ALE(postcontrol) ALE(precontrol) ACS
C. CBA = ACS(precontrol) ALE(postcontrol) + ALE(precontrol)
D. CBA = ALE(precontrol) ALE(postcontrol) ACS
Class Discussion Topics
Management of Information Security, Fourth Edition 910
1. Start a class discussion on the use of an acceptance risk control strategy. When should
such a strategy be used, and why should it not be used for all risks?
Additional Projects
1. Task students with using the Delphi technique, and provide groups of students with
information that needs to be rated or ranked, depending on the preferences of each
Additional Resources
1. SANS whitepaper on information risks and risk management:
2. Computer Weekly blog article on building information security strategies: