Security Risk Management
Security risk management is the discipline of identifying what could harm an organization's information systems, judging how likely and how damaging each threat could be, and deciding what to do about it. It turns security spending into justified decisions grounded in threats, vulnerabilities, and business impact.
itCybersecurity fundamentals and governance | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Intro
Security Risk Management
Security risk management is the discipline of deciding how much risk an organization accepts from threats to its information and systems, and what it does about the exposure it will not accept. It connects technical findings, such as a vulnerable service or a vendor with weak access controls, to business decisions about what to protect and how much to spend.
The work follows a loop:
frame the risk → assess the risk → respond to the risk → monitor the risk
↑ │
└────────────────── revise and repeat ─────────────────┘
Framing sets the rules for the assessment. Assessment produces the exposure picture. Response changes the exposure. Monitoring keeps the picture current. Revision feeds change back into the loop.
Risk is made of threat events, vulnerabilities, and impact
Risk is a function of the likelihood of a threat event and the magnitude of its impact. A threat source is the actor or circumstance that could cause harm, such as an external attacker, a negligent insider, or a flood. A threat event is the action or occurrence that exploits a weakness, such as a phishing message that captures credentials. A vulnerability is a weakness that a threat event could exploit, such as an unpatched service or a missing access review. A predisposing condition is a factor that makes a weakness more exploitable or more impactful, such as an exposed management interface.
Continue the course
This section is part of the paid course.
See pricing to subscribe, or log in if you already have access.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://csrc.nist.gov/pubs/sp/800/30/r1/final
Supports
- Risk as a function of likelihood of threat events and magnitude of impact
- Threat sources, threat events, vulnerabilities, and predisposing conditions
- Prepare, conduct, and maintain as the assessment process
- Determining likelihood and impact and determining risk
- Qualitative and quantitative assessment approaches
- Risk response options and residual risk
- Correlated and aggregated risk analysis
- https://csrc.nist.gov/pubs/sp/800/39/final
Supports
- Risk framing with assumptions, constraints, tolerance, and priorities
- Tier 1 organization, Tier 2 mission/business process, and Tier 3 information system levels
- Risk management as an ongoing multi-tier process
- https://csrc.nist.gov/pubs/sp/800/37/r2/final
Supports
- Risk Management Framework system life-cycle process
- Risk acceptance and authorization by senior officials
- Security and privacy integration in risk decisions
- https://www.iso.org/standard/80585.html
Supports
- ISO/IEC 27005:2022 guidance on managing information security risks
- Risk identification, risk analysis, risk evaluation, and risk treatment
- Supporting ISO/IEC 27001 requirements on addressing information security risks
- October 2022 fourth-edition publication
- https://csrc.nist.gov/pubs/ir/8286/r1/final
Supports
- Integrating cybersecurity risk into enterprise risk management
- Cybersecurity risk register as the organizing construct
- Expressing and aggregating cyber risk in business and enterprise risk language
- Risk statements, likelihood, impact, owners, and responses in register entries
- https://csrc.nist.gov/pubs/ir/8286/final
Supports
- October 2020 final publication of the original IR 8286
- Cybersecurity risk as an input to enterprise risk management processes
- https://csrc.nist.gov/pubs/ir/8286/a/r1/final
Supports
- Practical guidance for building and using a cybersecurity risk register
- Getting started with enterprise cybersecurity risk management
- https://csrc.nist.gov/pubs/cswp/29/the-nist-cybersecurity-framework-csf-20/final
Supports
- CSF 2.0 functions including Govern and Identify
- Cybersecurity risk governance, strategy, and assessment outcomes
- February 26, 2024 publication of CSF 2.0
- https://publications.opengroup.org/standards/open-fair-standards
Supports
- Open FAIR Body of Knowledge and its O-RA and O-RT standards
- Loss frequency, loss magnitude, and loss exposure
- Quantitative information security risk analysis
- https://publications.opengroup.org/c13g
Supports
- October 2013 publication of the Risk Analysis (O-RA) Standard version 1.0
- FAIR-based risk analysis scenarios
- https://csrc.nist.gov/nist-cyber-history/risk-management/chapter
Supports
- FIPS 65 in 1979 as early risk analysis guidance
- Original NIST SP 800-30 in 2002
- FISMA enactment through the E-Government Act of 2002
- Original NIST SP 800-37 in 2004
- SP 800-37 Revision 1 introducing the Risk Management Framework in 2010
- SP 800-39 in 2011 and SP 800-30 Revision 1 in 2012
- SP 800-37 Revision 2 in 2018
- https://www.nist.gov/publications/risk-management-guide-information-technology-systems
Supports
- July 2002 publication of the original NIST SP 800-30
- Risk management methodologies for information technology systems
- https://www.iso.org/standard/65694.html
Supports
- ISO 31000:2018 risk management guidelines
- Supersession of the earlier 2009 edition
- https://www.nist.gov/news-events/news/2014/02/nist-releases-cybersecurity-framework-version-10
Supports
- February 12, 2014 release of the Cybersecurity Framework Version 1.0
- Framework Core functions Identify, Protect, Detect, Respond, and Recover
- Voluntary, risk-based framework for managing cyber risk
- https://csrc.nist.gov/projects/risk-management
Supports
- NIST risk management project as the canonical hub for risk guidance
- https://github.com/Arudjreis/awesome-security-GRC
Supports
- Discovery of CISO Assistant, riskquant, minimalist-risk-management, Comply, Mozilla RRA, OCTAVE, FAIR Institute, and COSO as GRC ecosystem resources
- Awesome Links curation decision for security risk management tooling
- https://ciso-assistant.com/
Supports
- Open-source GRC platform combining governance, risk assessment, compliance, and audit reporting
- https://github.com/Netflix-Skunkworks/riskquant
Supports
- Python library for risk quantification with annualized loss and loss exceedance curves
- https://github.com/magoo/minimalist-risk-management
Supports
- Lightweight risk management program documentation
- https://github.com/strongdm/comply
Supports
- SOC 2-focused compliance automation with policy generation and ticketing integration
- https://infosec.mozilla.org/guidelines/risk/rapid_risk_assessment.html
Supports
- Mozilla Rapid Risk Assessment methodology for structured risk decisions in limited time
- https://www.cert.org/octave/
Supports
- OCTAVE risk evaluation method developed by the Software Engineering Institute
- https://www.fairinstitute.org/
Supports
- FAIR community and model for quantitative information risk analysis
- https://www.coso.org
Supports
- COSO ERM framework for enterprise risk management
- https://safe.security/
Supports
- AI-driven cyber risk quantification and management platform built on FAIR
- https://www.kovrr.com/
Supports
- Probabilistic cyber risk modeling and quantification
- https://www.axio.com/
Supports
- Cyber risk quantification and resilience planning
- https://www.bitsight.com/
Supports
- Security ratings from external observation for third-party and enterprise risk
- https://www.securityscorecard.com/
Supports
- Security ratings and third-party risk monitoring
- https://www.upguard.com/
Supports
- Third-party and vendor risk management with breach-risk scoring
- https://www.vanta.com/
Supports
- Automated compliance and security risk management for small and mid-market teams
- https://drata.com/
Supports
- Continuous compliance monitoring and evidence collection
- https://secureframe.com/
Supports
- Automated compliance management and control monitoring
- https://www.tugboatlogic.com/
Supports
- GRC and risk assessment platform for smaller security teams
- https://www.processunity.com/
Supports
- Third-party risk management platform for vendor assessment and monitoring
- https://www.prevalent.net/
Supports
- Third-party risk management with vendor questionnaires and monitoring
- https://eramba.org/
Supports
- Open-source GRC platform with risk register and framework mapping
