Difference between revisions of "Risk Management"

From MgmtWiki
Jump to: navigation, search
(Reference)
(Context)
(4 intermediate revisions by the same user not shown)
Line 1: Line 1:
 
==Full Title==
 
==Full Title==
Most of life is simply [[Risk Management]], It is essential to survival of any organization even though it is not the primary goal, it is the bedrock of continued existence.
+
Much of life is simply [[Risk Management]], It is essential to survival of any organization even though it is not the primary goal, it is the bedrock of continued existence.
 +
 
 
==Context==
 
==Context==
 +
Risk Management consiste of risk evaluation based on assets that need protection. In any transaction there are at least two points of view, that of each party to the transaction, For identity risk management we will be addressing the POV of the user and of the web site, also known (in the GDPR) as the [[Principal]] and the [[PII Controller]].
 
* [[Threat Model]] provides the core data needed for security risk analysis.
 
* [[Threat Model]] provides the core data needed for security risk analysis.
 
* [[Privacy Risk]]
 
* [[Privacy Risk]]
 
* [[Conduct Risk]]
 
* [[Conduct Risk]]
 +
 +
==Cost==
 +
* The Risk is typically measured by the likelihood of a breach times the cost of the breach.
 +
* An alternate measure is to look at similar enterprises and measure the cost of breaches in those simply situations.
 +
* Banking has in many ways the easiest measures as there is a history of losses by a range of categories so a measure of risk is actually fairly easy to gage, at least for old techniques. Even for new techniques the historical data can help to create a risk metric. For example [https://www.cl.cam.ac.uk/~rja14/Papers/cost_of_cybercrime.pdf Ross Anderson and his grad students have created] an extensive inventory of cybercrime costs.
  
 
==Reference==
 
==Reference==

Revision as of 20:37, 30 September 2020

Full Title

Much of life is simply Risk Management, It is essential to survival of any organization even though it is not the primary goal, it is the bedrock of continued existence.

Context

Risk Management consiste of risk evaluation based on assets that need protection. In any transaction there are at least two points of view, that of each party to the transaction, For identity risk management we will be addressing the POV of the user and of the web site, also known (in the GDPR) as the Principal and the PII Controller.

Cost

  • The Risk is typically measured by the likelihood of a breach times the cost of the breach.
  • An alternate measure is to look at similar enterprises and measure the cost of breaches in those simply situations.
  • Banking has in many ways the easiest measures as there is a history of losses by a range of categories so a measure of risk is actually fairly easy to gage, at least for old techniques. Even for new techniques the historical data can help to create a risk metric. For example Ross Anderson and his grad students have created an extensive inventory of cybercrime costs.

Reference