Risk management fundamentals cover the frameworks, models, and lifecycle processes organizations use to identify, assess, and mitigate threats to business assets. Core concepts include Enterprise Risk Management, the People-Processes-Technology model, data states, the CIA triad, and widely adopted frameworks such as NIST, COSO, and ISO 31000.
Risk Management Approaches
Just like anything, there's a lot of different ways we could approach risk management. We're just going to talk about certain aspects of risk management and the different approaches we could take towards risk management. This isn't going to be something that's in-depth, but we're just going to hit a few high-level topics.
When it comes to the approach to risk management, there's something called Enterprise risk management, or ER, and we have an Enterprise risk management program. This is just that program that's looking at the overall risk to the company. It's taking into consideration our processes and procedures, and we have checklists and all of our policies that go into that, our different services, and different data that's going into that. There's a lot that plays into a whole program and how the program functions.
When we start taking a deep dive into what are the risks to the business, there are different models that we can use out there, and different approaches and different ways to look at things.
A couple of those that we can take a look at is, first of all, PPT, or people, processes and technology. People, processes and technology is one way that we can start analyzing, okay, what are the risks? Well, we have people that are in place, so what is the risk from a people perspective? And they're carrying out processes, so what is the risk in those processes that we have, and identify weaknesses in those processes and things that need to be improved. And what is the technology that those people are using to carry out their job, to carry out their function? And so we take a look at the technology and the weaknesses to the technology. So that's one way that we can look at all of the weaknesses within our business, or what risks we have to our business.
Or we take a look at something like data and what's happening with data. Well, we're moving it around, so it's in transit, and what's happening to the risk when it's in transit, and what are we putting into place to mitigate that risk? Or what happens when data is at rest, being stored on something? So we have data that's being shipped around and sent around to different places, and what does that look like? And then when it's just sitting there stored on somebody's laptop maybe, or maybe it's on the database server, how are we securing that, how is the security at rest? Or it's got to be processed sometimes, so sometimes we print it out and then we're looking at it and using that information, and is those documents being left out? Or it's being processed on the actual processor of those servers. How is it being utilized, and is there risk to that? So that's another model, or different way that we can look at risk.
There's security models such as confidentiality, integrity and availability, and we look at, okay, well, how are we taking a look at the confidential side of things, how are we looking at the integrity side of things, how are we looking from an availability perspective? So once again, just a different way that we can take an approach to making sure that we're covering all of our bases and looking at all of the risks to the company.
Essentially risks have a life cycle to them, and through this life cycle we're going to identify a risk, and from there we have to do an assessment on that risk. And then from there, once we've assessed the risk and fully understand it and know what actions we're going to take, we have to put that action into place, or we call it a control. And a control is something we put into place to mitigate a risk, to lessen a risk, to lessen the probability or lessen the impact that it has. And then what we want to do is we want to review to make sure that in fact what we've done is actually successful. So our risk has a life cycle, and risk management has a life cycle.
During this risk management life cycle, we could put controls into place that would protect some sort of asset, that would guard it from something happening to it. Or to detect, if something does happen to it, that we can actually detect that something has happened to it. And take a response, so we can respond to it if something were to happen to it. Or to restore it, if maybe something was deleted, that we could actually do a restore on that data, or whatever the asset is.
When it comes to risk management and risk management life cycles and our approaches, there are different frameworks. A framework is just something that's set up. I like to think of it as a blueprint, a blueprint of how we could be operating. And there's several risk management frameworks out there that we could go and grab this blueprint and then set up our risk management program based off of that risk management framework.
Here's some examples of risk management frameworks. NIST has their nisk risk management framework, and properly named there. The COO, or COSO, has the ERM framework. And then the ISO 31000 risk management is another framework. So these are different frameworks from different organizations that we could use out there for setting up our risk management program.
Now, depending on which risk management program you're going to use, it could look very different on how you implement those frameworks and what they look like. But I've come up with kind of a generic one, a risk management process here that's just a generic one that takes a few different ones and adds them together.
So one of the things that we need to do is we need to establish our risk tolerance. How much risk are we willing to take on as a company? And from there we go through this risk process and do a risk assessment to identify the different risks that are within our network, within our different infrastructure, risks to the business. And then what we're going to do is we're going to analyze those risks, do an analysis on it to determine what is those risks, how deep do they go, and what would be some mitigation steps that we could take to fix that.
And essentially what we're going to do is we're going to start prioritizing those risks. And I like to think of the analysis and the prioritization kind of happening at the same time. There's kind of some back and forth that happens there to really prioritize which risks that we should fix and which ones we should tackle first. And then from there we're going to create some sort of plan, and then we'll implement that plan for the mitigation, so there's going to be a mitigation part of this. And then from there we're going to go into monitoring and seeing if this has been resolved. And this is a continuous cycle, that whether it's been resolved or not, then we go through the identification process again, and we continually do this on our network.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →