L17. Risk Management: Frameworks, Assessment & Treatment
Course outlineLesson 17 of 20
Risk management is the systematic process of identifying, assessing, and responding to threats to an organization's assets. The Security+ exam tests both the conceptual models and the quantitative calculations.
Risk Fundamentals
Risk = Likelihood × ImpactA vulnerability with low likelihood or low impact may not warrant expensive controls. Risk management is about prioritizing finite security resources against the most significant threats. Threat: a potential event that could harm an asset (e.g., ransomware attack) Vulnerability: a weakness that a threat can exploit (e.g., unpatched server) Risk: the combination of threat likelihood and potential impact Residual risk: the risk remaining after controls are applied
Quantitative Risk Analysis
Quantitative analysis uses financial figures to express risk:
- SLE (Single Loss Expectancy): asset value × exposure factor. The financial loss from a single incident.
- ARO (Annual Rate of Occurrence): how many times the incident is expected per year.
- ALE (Annual Loss Expectancy): SLE × ARO. The expected annual financial loss.
Example: Server worth $100,000. Exposure factor 40% (40% of server value lost per incident). SLE = $40,000. Expected 0.5 incidents/year. ALE = $20,000/year. A control costing less than $20,000/year is worth implementing.
Risk Treatment Options
| Option | Description | Example |
|---|---|---|
| Accept | Tolerate the residual risk; document the decision | Accept low-severity vulnerability on isolated system |
| Avoid | Stop the activity that creates the risk | Stop offering a high-risk service |
| Transfer | Shift financial consequences to a third party | Cyber insurance, SLA with vendor |
| Mitigate | Implement controls to reduce likelihood or impact | Patch the vulnerability, add MFA |
NIST Risk Management Framework (RMF)
NIST SP 800-37 defines a 6-step RMF:
- Categorize system based on impact to CIA
- Select baseline security controls (from NIST SP 800-53)
- Implement selected controls
- Assess controls to verify they are implemented correctly and effective
- Authorize the system (ATO: Authority to Operate)
- Monitor controls continuously
- ✓Risk = Likelihood × Impact; residual risk is what remains after controls are applied
- ✓ALE = SLE × ARO: the expected annual financial loss from a specific threat (used in quantitative risk analysis)
- ✓Risk treatment: Accept (tolerate), Avoid (stop the activity), Transfer (insurance), Mitigate (add controls)
- ✓NIST RMF 6 steps: Categorize, Select, Implement, Assess, Authorize (ATO), Monitor
- ✓Risk can be reduced but never fully eliminated; the goal is to reduce it to an acceptable residual level
1. An organization calculates that a data breach would cost $500,000 (SLE) and expects one breach every 5 years (ARO = 0.2). What is the ALE?
2. A company stops offering a high-risk online payment feature because the security controls required to protect it would cost more than the revenue it generates. Which risk treatment strategy is this?
3. Which step of the NIST RMF grants formal approval for a system to operate based on the determined risk posture?
Recommended: Pluralsight
Turn your CompTIA Security+ concepts into passing marks: Pluralsight adds structured study plans, practice exams, and hands-on scenario labs.