Sy0 601 19
Sy0 601 19
CompTIA Security+ Lesson 19 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 2
Syllabus Objectives Covered
CompTIA Security+ Lesson 19 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 3
Risk Management Processes
CompTIA Security+ Lesson 19 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 4
Risk Types
• External
• Cyber threat actors and natural or person-made disaster
• Internal
• Risks that arise from assets that are owned/managed
• Multiparty
• Ripple impacts in the supply chain
• Intellectual property (IP) theft
• Software compliance/licensing
• Shadow IT
• Legacy systems
CompTIA Security+ Lesson 19 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 5
Quantitative Risk Assessment
CompTIA Security+ Lesson 19 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 6
Qualitative Risk Assessment
CompTIA Security+ Lesson 19 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 7
Risk Management Strategies
• Inherent risk
• Level of risk before any type of mitigation has been attempted
• Risk posture and prioritization
• Regulatory requirements
• High value asset, regardless of threat likelihood
• Threats with high likelihood
• Procedures, equipment, or software that increase the likelihood of threats
• Return on Security Investment (ROSI)
• Risk mitigation/remediation
• Deploy countermeasure
• Reduce likelihood or impact or both
CompTIA Security+ Lesson 19 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 8
Risk Avoidance and Risk Transference
• Avoidance
• Stop doing the risky activity
• Transference
• Assign risk to a third-party
• Cybersecurity insurance
• Limits to transference
CompTIA Security+ Lesson 19 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 9
Risk Acceptance and Risk Appetite
• Risk acceptance/tolerance
• Risk is assessed and monitored, but no countermeasure is put in place
• Do not ignore risk
• Residual risk
• Likelihood and impact after mitigation
• Risk appetite
• Willingness to tolerate a certain level of risk
• Established at an organization or project level
• Control risk
• Loss of countermeasure effectiveness over time
CompTIA Security+ Lesson 19 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 10
Risk Awareness
CompTIA Security+ Lesson 19 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 11
Topic 19B
Explain Business Impact Analysis Concepts
CompTIA Security+ Lesson 19 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 12
Syllabus Objectives Covered
CompTIA Security+ Lesson 19 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 13
Business Impact Analysis
CompTIA Security+ Lesson 19 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 14
Mission Essential Functions
• Business activities that cannot be deferred
• Contrast primary business functions (PBF)
• Metrics
Images © 123rf.com.
CompTIA Security+ Lesson 19 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 15
Identification of Critical Systems
CompTIA Security+ Lesson 19 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 16
Single Points of Failure
CompTIA Security+ Lesson 19 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 17
Disasters
CompTIA Security+ Lesson 19 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 18
Disaster Recovery Plans
CompTIA Security+ Lesson 19 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 19
Functional Recovery Plans
CompTIA Security+ Lesson 19 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 20
Lesson 19
Summary
CompTIA Security+ Lesson 19 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 21