bci-presentation risk management - strategic continuity ......bci-presentation risk management.pptx...

39
Making the Jump to Risk Management Jeff Blackmon, FBCI, CISSP, CBCP, ITIL Strategic Continuity Solutions, LLC.

Upload: others

Post on 02-Jan-2021

5 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

Making the Jump to Risk Management

Jeff Blackmon, FBCI, CISSP, CBCP, ITIL Strategic Continuity Solutions, LLC.

Page 2: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

JeffBlackmon,FBCI,CISSP,CBCP,ITIL– StartedBC/DRplanningworkinthemid1980’s

•  Financial•  Petroleum•  ForeignMilitary•  Pharmaceutical•  Healthcare•  U.S.Government

– ContractConsultantbasedinKansasCityarea,buthavebeenworkingremoteforalmostallprojects.

Page 3: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

Topics:– RiskCategories– Definitions–  InsideRiskManagement(newpartsandpieces)– QualitativeandQuantitativeExposure– BC,SecurityandComplianceinRiskManagement– Discussion?

Page 4: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

WhatRiskManagementisNOT:– NOTtheconsolidationofCompliance,SecurityandBCintoasinglefunction

– NOTchanginganyofthefunctionsofCompliance,SecurityorBC

RiskManagementIS:

– MoreCollaborationbetweenCompliance,SecurityandBC

– MoreCommunicationbetweenCompliance,SecurityandBC

Page 5: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM
Page 6: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

RiskCategories:– Compliance– Credit– Liquidity– Market– Operational– Strategic– Other

Page 7: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

RiskCategories:– Compliance– Credit– Liquidity– Market– Operational(BusinessContinuityandSecurity)– Strategic– Other

Page 8: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

Risk– Ameasureofthepotentialforlossintermsofboththelikelihoodoftheincidentandtheconsequencesoftheincident(ProbabilityandImpact)

RiskAnalysis

– Thedevelopmentofaquantitativeorqualitativeestimateofriskforcombiningestimatesofincidentlikelihoodandconsequences

Page 9: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

RiskAssessment–  Theprocessbywhichtheresultsofariskanalysisareusedtomakedecisionsthroughrelativerankingofriskreductionstrategies

RiskManagement

–  Theplanning,organizing,leadingandcontrollingofanorganization’sassetsandactivitiesinways,whichminimizetheadverseoperationalandfinancialeffectsofaccidentallossesupontheorganization(MitigationandContingency)

Page 10: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

RiskResolution:– Takenoactionandaccepttherisk– Deferactionforshortterm– Developactionplan

•  Avoidtherisk•  Transferrisktothirdparty(suchasinsurance)•  Mitigatetherisk

–  Preventriskevent•  Contingencyifriskeventoccurs

–  LessentheImpact

Page 11: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

ThreatsandVulnerabilitiesareunlimited.Thefundstomitigatethemarenot.OverallGoals:

– ManageexposuretoRisk–  Improveresilience–  Controlcosts

ROIfromRiskprogramsisderivedmorefromkeepingandattractingclientsthanitisfromlossavoidance.

Page 12: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

Keyelement,Knowyourlosspotentials:– Natural,man-made,technologicalorpoliticallyrelated

– Accidentalversusintentional–  Internalversusexternal– Manageablerisksversusthosebeyondthecompany’scontrol

Page 13: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

SingleLossExpectancy(SLE)–  SLE=AssetValue($$)xImpact

AnnualLoseExpectancy(ALE)–  ALE=SLE(fromabove)xyearlyestimates

•  $RiskExposure=AssetValue($$)xImpactxyearlyestimates

Page 14: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

*NEW*EmergingRiskRegister– Event:Whatcouldhappen?(Threat)– Probability:Howlikelyisittohappen?–  Impact:Howbadwillitbeifithappens?– Mitigation:Howcanwereducetheprobability?–  Contingency:Howcanwereducetheimpact?– Reduction=MitigationxContingency– Exposure=Risk–Reduction

Page 15: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

*NEW*EmergingRiskRegister,alsotoinclude– Riskrecordowner– Mitigationstrategy

•  Mitigationcost•  Mitigationexpectedlossreturn

–  Contingencystrategy•  Contingencycost•  Contingencyexpectedlossreturn

–  Status/datesofactions– NewadjustedRiskExposurerating

Page 16: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

RiskImpactRatingAssessment

Low(<20%) Mod(21%-50%) High(51%-80%) Extreme(81%+)

Quality Minordegradation

Obviousdegradation

Majordegradation

EffectivelyUseless

Time <5%timeincrease

5%-10%timeincrease

10%-20%timeincrease

>20%timeincrease

Cost Insignificantcostincrease

<10%costincrease

10%-25%costincrease

>25%costincrease

FindbestassessmentbasedonQuality,TimeandCostImpact

Page 17: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

RiskExposureResults(QualitativeExample)Impact Low(<20%) Mod(21%-50%) High(51%-80%) VeryHigh(81%+)

Probability/year>91%(VeryHigh) Moderate High VeryHigh VeryHigh61%-90%(High) Moderate High High VeryHigh21%-60%(Mod) Low Moderate High High<20%(Low) Low Low Moderate High

ImpactxProbability=RiskExposure

ClassificationsabovebaseduponcompanyRiskAcceptanceprofile

Page 18: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

RiskExposureResults(PartialQuantitative)Impact Low(<20%) Mod(21%-50%) High(51%-80%) VeryHigh(81%+)

Probability/year>81% Moderate High VeryHigh VeryHigh61%-80% Moderate High High VeryHigh41%-60% Low Moderate High VeryHigh21%-40% Low Moderate High High5%-20% Low Low Moderate High<5% VeryLow Low Moderate Moderate

ImpactxProbability=RiskExposure

ClassificationsabovebaseduponcompanyRiskAcceptanceprofile

Page 19: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

RiskExposureResults(Quantitative)ALE Low Moderate High VeryHigh

TotalRiskCosts <$10,000 $10,000-$100,000

$100,000-$500,000

>$500,000

ImpactxProbability=RiskExposurein$$

ClassificationsabovebaseduponcompanyRiskAcceptanceprofile

Page 20: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

Event:CommunicationsLossIf1ofour2fibercablesarecut.Notemajorconstructiontakingplaceonproperty.Effect:Lose50%ofcommunicationbandwidthExpectedLoss:$250,000RiskImpact:HighProbability:10%RiskExposure:RecordOwner:BobSmith,NetworkComms

ExampleforRiskRecord(1)Quantitative

Page 21: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

$Risk=AssetValue($$)xImpactxyearlyestimates250,000x.50x.10=$12,500.00=ALEMitigation:Dophysicaltraceoffibercables,markroutesanddocument.Cost=$2,000NewProbability=5%UpdatedRiskExposure:250,000x.50x.05=$6,250.00NewRiskExposurecategory=

ExampleforRiskRecord(2)Quantitative

Page 22: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

Event:EncryptionFailureIfStandAlonebankingEncryptionKeyserverweretodoahardcrash.Effect:Lose100%ofACHcashtransferExpectedLoss:$1,250,000RiskImpact:VeryHighProbability:20%RiskExposure:RecordOwner:SamSmith,CFO

ExampleforRiskRecord(3)Quantitative

Page 23: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

$Risk=AssetValue($$)xImpactxyearlyestimates1,250,000x1.00x.20=$250,000.00orALEMitigation:ProvideremotelylocatedfailoverserverforEncryption.Cost=$12,000NewProbability=4%UpdatedRiskExposure:1,250,000x1.00x.04=$50,000NewRiskExposurecategory=

ExampleforRiskRecord(4)Quantitative

Page 24: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

QuantitativeprocessesgivemuchmoreaccurateAnnualLossExpectancy(ALE),butremember,thenumbersdeterminedforlossandexpectancymustbeaccurate.Otherwiseacompany’sRiskExposurecalculationscanvarywidely.MorecommonforacompanytostartwithQualitative,andmovetoQuantitatively.

Page 25: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

SohowdoesRiskManagementCHANGEBusinessContinuity,SecurityandCompliance?Actually,littleifany.BCstilldoesBCworkandisnotgoingaway.ThisisthesameforSecurityandCompliance.RiskManagementisaboutcollaborationandcommunicationbetweenthedepartmentsforbetterintegration.OverallGoals:

–  ManageexposuretoRisk–  Improveresilience–  Controlcosts

Page 26: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

RISKMGMT.

COMPLIANCE

BUSINESSCONTINUITY

SECURITY

Page 27: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

FRAME

RESPOND

ASSESS

MONITOR

Page 28: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

WhyisBusinessContinuityImportanttotheRiskManagementprocess?

Page 29: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

MuchoftheinformationusedinRiskManagementcomesdirectlyfromtheBusinessContinuityprocess.Unalteredandunchanged.Justcopiedover.

BusinessContinuity

Page 30: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

EmergingRiskRegister– Event:Whatcouldhappen?(Threat)– Probability:Howlikelyisittohappen?–  Impact:Howbadwillitbeifithappens?

MuchofthisinformationshouldcomefromtheBCRiskAssessment

BusinessContinuity

Page 31: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

EmergingRiskRegister– Mitigation:Howcanwereducetheprobability?–  Contingency:Howcanwereducetheimpact?

BothoftheaboveshouldbepartoftheBusinessContinuityplans.NowjustcarriedintoRiskManagement.

BusinessContinuity

Page 32: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

$Risk=AssetValue($$)xImpactxyearlyestimatesAssetValueshouldcomefromtheBusinessImpactAnalysis(BIA)

BusinessContinuity

Page 33: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

ImportanceofComplianceinRiskManagement– Muchhaschangedindealingwithcomplianceandauditgroupsoverthelast20years

–  CFOsdonotspeakRTOs,RPOs,GigabitEthernet,AIXandsoon

–  TheyareveryawareofPCI,OCC,FFIEC,Sarbane-Oxleyandmanyothercomplianceregulations

–  ConsiderableamountoftheirworkisconsidereddirectRiskManagement

–  CompliancegroupsusuallyhavedirectaccesstoC-Levelexecutivesandcanrelayconcernsandissuestothepeoplethatcanprovidetheprioritytogetthemfixed

Compliance

Page 34: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

ImportanceofSecurityinRiskManagement– Primarygroupwithinacompanyforriskmitigation

•  Firewalls•  Intrusiondetection•  malwarescan•  accesscontrol•  andmanymore

NoneofSecurity’sfunctionswillchange

Security

Page 35: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

ImportanceofBusinessContinuityinRiskManagement

– PrimarygroupwithinacompanyforContingency•  ITRecoveryorderbasedonBIAsandfollow-upstrategies•  Managethepeopleaspectofanevent•  Determineanddocumentthreat•  Determineanddocumentvulnerabilities•  andmuchmore

NoneofBusinessContinuity’sfunctionswillchange

BusinessContinuity

Page 36: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

Compliance Communicationsto management

Security MitigationBusinessContinuity Contingency

RiskManagement

Page 37: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

RiskManagementStandards–  ISO31000:2009– NIST800-30– NIST800-37

Page 38: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

Questions

Page 39: BCI-presentation Risk Management - Strategic Continuity ......BCI-presentation Risk Management.pptx Author Jeff Blackmon Created Date 4/16/2018 7:47:36 PM

001-(913)-971-4081 [email protected] https://www.linkedin.com/in/jeffrey-d-blackmon-

fbci-cissp-cbcp-itil-f-876205

Jeff Blackmon, FBCI, CISSP, CBCP, ITIL