Home > Security Tips > Risk Management Strategies > Failure mode and effects analysis: Process and system risk assessment
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

RISK MANAGEMENT STRATEGIES

Failure mode and effects analysis: Process and system risk assessment


Gideon T. Rasmussen, CISSP, CISA, CISM, CIPP
03.26.2008
Rating: -3.00- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Failure mode and effects analysis (FMEA) is widely used by corporations, manufacturing firms and the U.S. military to evaluate processes or systems (e.g. an incident-response process or a three-tiered application). It prioritizes potential failures by impact severity, probability of occurrence and likelihood of detection. FMEA risk ratings and narrative rationale can be used to quantify exposure to management and facilitate remediation. Most recently, FMEA was incorporated into Six Sigma and the Information Technology Infrastructure Library (ITIL).

FMEA overview
Under FMEA, each process step or system component is evaluated by the criteria using the table below:

[TABLE]

FMEA calculates a risk priority number (RPN) for each process step or system component using this simple technique:

Risk priority number = Severity x Occurrence x Detection

Preparation
Have a current process or system diagram available before beginning the FMEA process. The diagram must document process steps or system components with sufficient detail to support a thorough evaluation. Number each entry for easy reference.

The FMEA team should be comprised of people involved in the day-to-day operations of the process or system (e.g. the team manager and system administrators). Consider using an internal auditor or a peer team manager to act as a facilitator. At a minimum, engage an objective, independent third party. The facilitator is responsible for hosting FMEA meetings and should be actively involved in the evaluation of each process step or system component.

Execution
Begin the first meeting with an FMEA overview. Review the process diagram and enter it into an FMEA worksheet. Consider process flow, inputs, outputs and dependencies.

Conducting a system evaluation is a bit more complex. For example, to review a three-tiered architecture, the diagram should include systems and applica



tions associated with the presentation, application and database layers. For additional scrutiny, review firewall and monitoring configurations and the system development life cycle.

Assign each team member a section of documentation to evaluate before the next meeting. Depending on process or system complexity, it may be necessary to have more than one. Carefully evaluate each process step or system component. Document control deficiencies and associated risk ratings in an FMEA worksheet.

Once the FMEA evaluation is complete, review the RPNs for each process step or system component, It will be apparent which areas pose the greatest risk exposure. The highest numbers correspond to the items with the greatest potential for risk. Corresponding narrative entries provide rationale and detail which can be used to prioritize remediation.

The second half of an FMEA worksheet documents remediation activity. Enter mitigating controls in the first two fields. Complete the Action Results section to determine if the new controls will reduce residual risk to an acceptable level.

[TABLE]

Conduct FMEA reviews at least annually. In additional to evaluation, FMEA helps ensure team members are familiar with critical processes and systems. FMEA also accomplishes process reviews and updates required by common security standards and frameworks.

Simplicity is FMEA's greatest strength. It documents risk posture using qualitative and quantitative approaches. FMEA is a great way to evaluate the risks associated with a process or a system. Consider adding it to your annual security management routines.

About the author:
Gideon T. Rasmussen is a Charlotte-based Information Security Vice President with a background in Fortune 50 and military organizations. His website is http://www.gideonrasmussen.com.

References:
1. Failure Mode and Effects Analysis (Wikipedia)
2. Failure Mode and Effects Analysis (U.S. Department of Defense)


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Risk Management Strategies,   Enterprise Risk Management: Metrics and Assessments,   Information Security Management,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Risk Management Strategies
Cloud computing security: Choosing a VPN type to connect to the cloud
Cloud computing security: Routing and DNS security threats
Cloud computing security model overview: Network infrastructure issues
How to align an information security framework to your business model
When to use open source security tools over commercial products
Vulnerability test methods for application security assessments
Security book chapter: Applied Security Visualization
The 100-day plan: Achieving success as a new security manager
Recovering stolen laptops one step at a time
How to get information security buy-in from the executive team

Enterprise Risk Management: Metrics and Assessments
The basics of enterprise GRC project management
RSA council addresses growing security risks in the cloud
How to write a risk methodology that blends business, security needs
Mature SIMs do more than log aggregation and correlation
Risk management must include physical-logical security convergence
New partnerships, creative thinking help security bust recession
Security budgets take hit in media, tech industry, survey finds
Service-focused security offers best value to organization
Ease the compliance burden with automation
Forensic accounting success depends on information security support
Enterprise Risk Management: Metrics and Assessments Research

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
More Security Resources for Resellers, VARs and OEMs
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts