Home > Ask the Security Experts > Security Management Questions & Answers > What are ways to measure security risks, threats and vulnerabilities?
Ask The Security Expert: Questions & Answers
EMAIL THIS

What are ways to measure security risks, threats and vulnerabilities?

Mike Rothman EXPERT RESPONSE FROM: Mike Rothman

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 23 April 2007
What are some good examples of effective risk metrics?

>
EXPERT RESPONSE
In general, risk tends to be hard to quantify. Before I jump into the million or so things you could quantify, it's important to understand a bit about risk, especially within the context of security. Back in my TruSecure (now CyberTrust) days, CTO Peter Tippett defined risk via a simple equation:

Risk = Threat x Vulnerability x Cost

Threat is the frequency of adverse events. Vulnerability is the likelihood that a particular attack will be successful, and cost is the total economic impact of a successful attack. A lot of folks have different ways to quantify risk -- investors, actuaries and security professionals all have different opinions -- but this definition is sufficiently simple for a rock head like me, so let's go with it.

You need to quantify your security environment (which is threats and vulnerabilities) and then calculate the cost to derive your risk exposure. In reality, you can spend a lifetime trying to build a sophisticated, PhD-level model and still be wrong. Basically, you are making assumptions on top of assumptions on top of assumptions.

I'm a fan of simplicity, and I suggest folks take a more qualitative approach to quantifying anything related to security. Much of this is laid out in my book, The Pragmatic CSO, but here is the abridged version.

To start, figure out what's important, focusing on cost. What business systems are most critical to your organization? Who uses them? What is their time worth? Once you have an idea of the most critical systems, then figure out the most likely threats to those systems. Are they vulnerable to cross-site scripting attacks? Or a brute force DDoS assault? Use these findings to develop a realistic estimate of how likely it is that such attacks, if successful, could take down those critical systems.

Ultimately, try to establish if it makes sense to implement a new process or install a new product, and figure out which knobs that specific product will affect. Will installing a Web application firewall reduce the likelihood of a XSS attack on your critical application? If yes, to what degree? Take a guess. Will that affect the frequency of the attack? (Nope. The only way to do that is to take the system offline, so that number stays the same in this case.) This approach will allow you to get an "apples-to-apples" comparison of different options and figure out what will yield the greatest reduction in risk.

I am not a big fan of simply counting things. The taxonomy I described will allow you to weigh certain decisions against others by using the only metric that's important: the risk to your critical business systems.

For more information:

  • In this SearchSecurity.com Q&A, security management expert Mike Rothman discusses the differences between business continuity planning and operational risk management.
  • This list of disaster recovery basics can help security practitioners improve their recovery plans.


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Security Management
    What is the GISP certification and how does it compare to the CISSP certification?
    Would QSAs normally write up a PCI DSS report on compliance (ROC) and submit it to all issuing card brands?
    How can gap analysis be applied to the security system development life cycle?
    When should an enterprise consider low-cost security appliances vs. a bigger do-everything appliance?
    What are some tips on protecting my security budget in a tight economy?
    What value do research firms provide to enterprises that subscribe to their services?
    What certificate offers the best ROI for an IT project manager?
    Which is the biggest threat to data: Insider activity or outsider activity?
    What role does information security play in enterprise fraud-prevention activities?
    What is the difference between an SAS 70 data center and a Tier III data center?

    Risk Management Metrics and Measuring Risk
    Security beyond compliance: A proactive and customized security framework
    Death of a risk assessor
    Security spending driven by mergers, Web 2.0 and compliance
    IRS faulted for lax security controls, dangerous data risks
    Consensus Controls project aims to set benchmarks for compliance
    Bruce Schenier, Marcus Ranum debate risk management
    CIS takes the measure of information security
    Security of customer data, IP sustains security budgets
    Security visualization helps make log files work
    Security data lapses hamper researchers

    Risk Assessment and Analysis
    Death of a risk assessor
    Security spending driven by mergers, Web 2.0 and compliance
    IT security pros focus on internal threats during tough economy
    IRS faulted for lax security controls, dangerous data risks
    Security policy being bypassed by employees, survey finds
    How can gap analysis be applied to the security system development life cycle?
    IT security pros face challenge during economic crisis
    Data risks take shine off Google Chrome
    Bruce Schenier, Marcus Ranum debate risk management
    PCI is about eliminating data, not securing it, former QSA says

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    risk analysis  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    Targeted Security Channel Tips for Resellers, Integrators and Consultants
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts