A Risk Analysis Essay

Improved Essays
Gibson says, “A risk assessment (RA), also referred to as “Risk Analysis”, is a process used to identify and evaluate risk” (2015). It differs from Risk Management Plan (RMP) as RA is about classifying the risks quantitatively and qualitatively, but RMP is about avoiding and mitigating risks, threats and vulnerabilities.
Risk assessment is a subset of RMP. RA helps an organization to prioritize the risks based on their likelihood and degree of impact. RA is a very important instrument when an organization is trying to evaluate their risks, plan the control/solution and monitor their effectiveness. RA helps the management take well informed decision to neutralize the risks based on the quantitative numbers and qualitative factors. Once a control
…show more content…
SL.no Risks, Threats, ad Vulnerabilities Primary domain impacted Risk Impact/factor
1 Unauthorized access from public Internet WAN 2
2 User destroys data in application and deletes all files LAN 1
3 Hacker penetrates your IT infrastructure and gains access to your internal network System/Application 3
4 Intraoffice employee romance gone bad Workstation 3
5 Fire destroys primary data center System/Application 1
6 Service provider service level agreement (SLA) is not achieved User 2
7 Workstation operating system (OS) has a known software vulnerability Workstation 3
8 Unauthorized access to organization-owned workstations Workstation 2
9 Loss of production data server System/Application 1
10 Denial of service attack on organization Demilitarized zone (DMZ) and e-mail server System/Application 2
11 Remote communications from a home office WAN 3
12 LAN server OS has a known software vulnerability LAN 3
13 User downloads an unknown e-mail attachment Workstation 3
14 Workstation browser has software vulnerability Workstation 3
15 Mobile emplyoee needs secure browser access to sales-order entry system LAN-to-WAN 2
16 Service provider has a major network outage User 1
17 Weak ingress/egress traffic-filtering degrades performance User
…show more content…
Breaking them down further, there are 2 RF for System/Application domain, 2 for User domain, and 1 each for Remote access and LAN domain. These are critical as they impact the compliance and may cause a big financial loss to the stakeholders and shareholders. These critical issues need to be addressed as soon as possible. There are 8 major issues, 2 RF impacting each of WAN, LAN-to-WAN, and User domains. 1 RF impacting each of System/Application and Work station domains. These major issues are to be addressed once the critical issues are mitigated first. Las but not the least, there are 8 minor issues as listed in the above table, which should not be completely ignored, in fact, they should be handled

Related Documents

  • Decent Essays

    Upon determining what should be in the intranet, what risk is the organization willing to tolerate should be tackled. An assessment of the privacy controls and security controls can be determined by using NIST Special Publication 800-53A: Assessing Security and Privacy Controls in Federal Information Systems and Organizations, Building Effective Assessment Plans as a guide along with NIST Special Publication 800-30, Rev-1, Guide for Conducting Risk Assessments (NIST SP 30-1, 800-53A). To truly understand this publication is prohibitive to fully explain; however, this step is critical and will impact your intranet dramatically. To simplify: you cannot always have the risk metric you desired because by doing so would make your system so slow and unusable you could not accomplish much.…

    • 428 Words
    • 2 Pages
    Decent Essays
  • Improved Essays

    Xacc/280 Week 4

    • 629 Words
    • 3 Pages

    Decisions for Year 3 were more challenging, I think this is so because I now have a total understanding of the simulation. I found that it is difficult to make all the ideal choices because my budget may not allow it. The organizational stakeholders decision I selected initiate a full audit of the supply chain of all K-Tai, Inc.’s consumer electronic products. I feel that the issue presented was worthy of investigation and that the best place to begin would be an audit to confirm if the company was currently using any of the conflict materials.…

    • 629 Words
    • 3 Pages
    Improved Essays
  • Improved Essays

    Risk assessment refers to determining the potential threat that an individual as upon their release from custody because of mental illness and/or criminal activity. There are two methods of risk assessments they are actuarial and clinical judgment (Brown & Singh, 2014). Actuarial risk assessment refers to a method of assessment that is based on statistics that estimates the risk level of a particular event to occur for example, how likely is this offender to commit a violent crime. There are requirements of actuarial instruments they include there being scientific integrity and practical utility (Baumann, Law, Sheets, Reid, & Graham, 2005). Practical utility involves being efficient, being accessible, and producing actual results that are desired…

    • 897 Words
    • 4 Pages
    Improved Essays
  • Superior Essays

    Case Study: Kroger Company

    • 1178 Words
    • 5 Pages

    FACTORS: Statement “The Risk Assessment Standards establish standards and provide guidance concerning the auditor’s assessment of the risks of material misstatement in a financial statement audit and the design and performance of audit procedures whose nature, timing, and extent are responsive to the assessed risks.” (Risk Assessment, 2017). An auditor doing a risk assessment would look at materiality, results from previous audits both internal and externa, data sources, among others and the auditor must look at the level of risk as well. Reviewing the income statement for Kroger Company there was an increase in Sales/Revenue for the year 2017 over 2016:…

    • 1178 Words
    • 5 Pages
    Superior Essays
  • Improved Essays

    Triton Multi-INT

    • 505 Words
    • 3 Pages

    I am a little concern about the bidding or proposal against RMF effort. There is tremendous work need to be done for the RMF compliance that leading to an ATO. Without the ATO, even your system is built with the state-of-the-art technology, you are not allow to operate in the field. I do not see that importance reflect on the proposal. I am not sure whether Triton Multi-INT (or the Triton baseline) is a program of record that needs an ATO or it only needs to be RMF compliance.…

    • 505 Words
    • 3 Pages
    Improved Essays
  • Improved Essays

    Nursing research is a research that provides evidenced used to support nursing practices. HISTORICAL BACKGROUND • 1940 The Nazi Medical Experiment used of prisoners of war and other race to conduct human experiment without their consent that exposed them to severe harm and death • 1932 The Tuskegee Syphilis Study sponsored by US Public Service where participants without syphilis were also inoculated and medical treatment where deliberately withheld for these participants. The same US doctor who worked in the Tuskegee Study inoculated the prisoners in Guatemala in the 1940’s • 1960’s…

    • 864 Words
    • 4 Pages
    Improved Essays
  • Great Essays

    Unit 4222-320 Support individuals to live at home Outcome 1 Understand the principles of supporting individuals to live at home 1. describe how being supported to live at home can benefit an individual…

    • 2495 Words
    • 10 Pages
    Great Essays
  • Improved Essays

    Rq1

    • 1478 Words
    • 6 Pages

    ARRANGEMENTS The Health and Safety at Work (NI) Order 1978 legally enforces responsibilities to employers with the organisation to look after the health and safety of all their employees. This legislation also requires the employees to comply with the guidelines put in place for their own health and safety. There are many regulations that have been developed under this order concerning the Health and Safety at work. These regulations require that employers perform risk assessments and provide employees with information and training if necessary (health-ni.gov.uk, n.d).…

    • 1478 Words
    • 6 Pages
    Improved Essays
  • Improved Essays

    Johns Hopkins Health System employs more than 20,000 people annually. It is a diverse organization that is dedicated to its employees, patients, their families, and the community it serves. John Hopkins has spent substantial amount of time, energy, and resources to address and improve patient safety understanding that, like any other area of medicine, science must guide the way to improvement. With a need to train physicians, nurses, medical students and administrators in this evolving area of the science of safety, it found that the best approach is to have that training led by employees that are in the trenches. John Hopkins developed a program that helped better understand how to identify and learn from mistakes.…

    • 1081 Words
    • 5 Pages
    Improved Essays
  • Improved Essays

    Good Morning, Chapter 7 Risk assessment for marijuana dependence or abuse is not a problem for me. I can not lie when I was younger I did smoke marijuana and you might have said I had a little bit of dependence for it. It was a huge part of my life in my teenage years. My friends smoked it some of my family smoked it. But for 25 years now I have not touched it and chose to teach my children to not touch it either.…

    • 786 Words
    • 4 Pages
    Improved Essays
  • Improved Essays

    Identifying and managing risks is a critical responsibility of project managers. Risk is defined as the probability of a specified threat and the subsequent impact that the event produces (Vaidyanathan, 2013). Risks can also bring about either positive or negative outcomes for a project or organization. A project manager must identify potential risks and evaluate each one to determine the severity and likelihood of each event. Only by completing the risk management process, a project manager can determine what approach would work best to avoid, mitigate, and/or transfer the risk.…

    • 730 Words
    • 3 Pages
    Improved Essays
  • Improved Essays

    Cenartech Case

    • 884 Words
    • 4 Pages

    Its overall company network is well separated with three networks (Whitman & Mattord, 2011). The first is a wireless guest network, the second is a financial network ,without any wireless access and the third is a production network (for employees and other functions) with wireless access (Whitman & Mattord, 2011). All networks are…

    • 884 Words
    • 4 Pages
    Improved Essays
  • Improved Essays

    Furthermore, risk management is the act of forecasting and evaluating a certain situation and finding different ways to avoid and minimize the risks involved in getting the particular tasks done (Ryan, 2013). Leaders take risks, but they must first consider associated costs in order to determine if they can assume risks in a certain area and if taking those risks is advantageous. Risk management often requires careful consideration for personnel, equipment, and other resources because the goal is for individuals to achieve the most positive outcomes possible for the organization (Ryan,…

    • 970 Words
    • 4 Pages
    Improved Essays
  • Great Essays

    When dealing with the term risk we think about uncertainty, the unknown and probability, how likely it is that such an event will occur. Risk management can be about other elements rather than just associated with firms and industries. Every day people are managing risks and trying to deal with risk, which portrays…

    • 1358 Words
    • 6 Pages
    Great Essays
  • Improved Essays

    Quantitative Risk Analysis

    • 1299 Words
    • 5 Pages

    Quantitative risk analysis is the one which follows the Qualitative analysis, and gives a numerical priority rating to project risks (PMI, 2009). Based on the PMBOK (PMI, 2013) quantitative risk analysis “… is the process of numerically analyzing the effect of identified risks on overall project objectives (p. 333).” This is also a process for the PM and project team to get risk data to support making decisions, which can help to reduce project uncertainties (PMI, 2013, p. 333). Based on the prior researchers’ statement, the Quantitative Risk Analysis is more complicate and even the most difficult part within risk management since it requires statistical and mathematical methods to be operated (Purnus & Bodea, 2013, p. 145). Inputs of this…

    • 1299 Words
    • 5 Pages
    Improved Essays

Related Topics