Risk management
Pages
Page 11 of 15
Component driven risk management methods

An introduction to using component driven risk management in cyber security.
Introduction
Component driven risk assessments are the most mature and common types of assessment within the cyber security profession. This section describes what component driven techniques have in common, where they add value, and where they don't.
- Once you've understood these basics, you should be able to pick up any component driven standard or framework (as they are based on a similar perspective on risk) and understand how they differ from system driven approaches.
- If you've not already done so, please read the section that introduces component and system driven risk assessments before reading this guidance.
- Our basic risk assessment method provides a very simple and basic component driven approach.
Scope and assets
Unsurprisingly, component driven risk assessments are focused on system components. So what do we mean by 'components'? Typical examples include:
- hardware (computers, servers)
- software (operating systems, applications)
- network components
- data sets
- services
- personally identifiable information (PII)
- business critical information
- people
The focus on components requires you to start by defining the function that you are analysing (for example, a payroll function). This function is known as the 'scope' of your assessment. You then need to state which components you are considering in your risk assessment of the scope, and which you aren't. This is generally referred to as an 'asset list' or 'asset register', but ensure that your description of an asset can be used to cover less tangible things that are still valuable (such as an organisation's reputation or brand). Assets should not just be narrowly applied to describe physical components.
Components which you have no control over (but which your own system depends on) are known as dependencies, and can be included alongside your asset list, provided it is clear how these dependencies affect those components which you can control. A scope is sometimes best presented as a diagram, which clearly shows what is in, what is out, and how the key assets are connected. An example scoping diagram is shown below which describes a corporate user’s access to a cloud-based application as being the focus of some risk analysis, including the connectivity between key actors and components, and those things that we might wish to explicitly scope out.
Elements of risk
Once you have identified your scope, most component driven approaches require the risk analyst to assess three elements of risk. These three elements are typically described by the terms impact, vulnerability, and threat.
Impact is the consequences of a risk being realised. This impact is described in different ways, but one of the more common techniques within the cyber security domain is to assess the impacts to confidentiality, integrity, and availability, of information. For example, an impact might be described in terms of a loss of confidentiality of a customer dataset, or the corruption (loss of integrity) of your company's accounts. A loss of one of these properties can be connected to other types of consequence, such as lost money, loss of life, delays to projects, or any other kind of undesirable outcome.
It is worth noting that this is an information-centric way of thinking about risks and impacts, and organisations may have other priorities or things they care about that might also need to be considered in terms of harmful impacts. For example an organisation that provides online payments service may be concerned about the financial and reputational impacts of fraud, or similarly an organisation that delivers a critical service to the public may be concerned with impacts relating to the safety or reliability of its services. As with all things risk management it is important not to be constrained by any single perspective.
A vulnerability is a weakness in a component that would enable an impact to be realised, either deliberately, or by accident. For instance, a vulnerability could be a piece of software which allows a user to illegitimately increase their user account privileges, or a weakness in a business process (such as not properly checking the identity of someone before issuing them credentials for access to an online system or service). Regardless of the type of vulnerability in question, it is something which can be exploited to cause an impact.
As discussed in the fundamentals and basics of cyber risk threat is considered in the context of four components:
- capability
- intent
- motivation
- opportunity
Threat is the individual, group or circumstance which causes a given impact to occur. For example, this could be:
- a lone malicious hacker, or a state-sponsored group
- a member of staff who has made an honest mistake
- a situation beyond the control of the organisation (such as high-impact weather, which is more accurately described as a 'hazard')
The purpose of assessing threat is to improve the assessment of how likely a given risk is to be realised. Typically, when assessing a human threat actor, analysts consider people who are likely to want to harm the organisation. This then allows them to consider the capability, intent, opportunity and motivation of these groups. Risk analysts use threat information taxonomies, knowledge bases of threat information and categorisation methods to provide a common language of threat capability.
One of the challenges of threat assessment is that a threat's motivation, capability, opportunity, and intent can change rapidly, and reliable information on these changes can be hard to come by. Because of this, don't treat your assessments of threat capability as if they are static, seek out the best source of information available and make sure you recognise uncertainty and variability in your threat assessments. Good sources of threat information could be through information sharing partnerships, sector or industry focussed security groups or national authorities such as the NCSC and the National Protective Security Authority (formerly known as CPNI).
There are numerous techniques, approaches and tools available that might help you build your understanding of threat, vulnerability and impacts. These could include building attack trees conducting threat modelling exercises, and scenario planning. Whilst we propose that these techniques might be useful to you, there may be others that might be equally effective.
Applying and communicating threat, vulnerability, and impact
Once these elements of risk have been assessed, the next step is to combine these to identify which risks are most concerning. These approaches can generate long lists of potential risks, not all of which may happen. Consequently, it is important that you think carefully about a potential threat's opportunity to exploit any identified vulnerabilities to make this list more meaningful. Some techniques do this by combining the assessments of threat, vulnerability and impact into a single measurement of risk for each system component. Where this is the case, care needs to be taken to ensure that you understand each individual element so that you can effectively manage the resultant risk.
This is not as straightforward as some standards claim. The three components of risk are fundamentally different from each other, and care needs to be taken to clearly define the meaning and characteristics of each so that it can be understood by analysts and decision makers. Some approaches recommend the use of risk matrices to combine these elements, and whilst risk matrices are easy and quick to use they can, if not used with care, introduce errors to your risk analysis that can mislead or misinform risk analysis outcomes .
It is useful to note that some component driven approaches combine the analysis of threat and vulnerability in some way to result in a likelihood value. This is then combined with an assessment of the value of the system component (impact) that is the focus of the analysis, to give an assessed value for risk. As previously discussed, where this is the case, it is important that this combined view of risk does not obscure opportunities to manage it by addressing one or more of its components, for example by taking steps to reduce impact, affect a threat actor’s opportunity or a system's vulnerability to attack.
Prioritising your risks
Once the various threats, vulnerabilities and impacts have been assessed and combined to create a list of risks, they can be prioritised according to how concerning they are. This allows you to manage the most concerning risks first. You can communicate this prioritisation of risks in a variety of ways. For example, you could:
- estimate the financial loss of an impact, if it were to be realised
- provide a narrative of the chain of events that would need to occur if an asset were to be compromised
Many standardised component driven risk management techniques use qualitative labels to describe levels of impact, usually with labels like 'high', 'medium' and 'low'. Whilst these are fairly intuitive, research shows that there is a huge difference between how different individuals interpret these labels. When considering this lack of consistency of understanding, these labels (and similar 'traffic light' approaches) should be used very cautiously. The technique you use should be tailored to the risk assessment's audience. Who is it seeking to influence? What decision are you trying to inform? Does the information you are presenting from your assessment aid decision making, or hinder it?
Some approaches have a ready-made list of tasks or objectives that can be used to mitigate the risks you have identified. These are known as 'control sets', from which you can select the most appropriate set of mitigations for each risk.
Commonly used component driven cyber risk management methods and frameworks
This section provides a brief description of commonly used component driven cyber risk management methods and frameworks. Click on the relevant hyperlinks for more detailed information about each method/framework. There are many more component driven risk management techniques which have not been listed here. This list does not include system driven approaches.
Selecting a technique that's right for you
When selecting a risk method or framework, you need to consider:
- the overall cost of using the method (for example, the procurement of tools, licensing, and expertise)
- the scope of the project; is the risk method proportionate to what is being assessed?
- are the required resources proportionate and sustainable; what specialist resources are required, and do you have them?
- how any of your key partners (with whom you must interact regularly to manage shared risks) can work with this method?
Summary of commonly-used component driven methods
| Method / Framework | ISO/IEC 27005:2018 |
| What is it ? | An international standard providing guidelines for information risk management. Although it does outline a generic risk assessment process, it leaves the choice of that risk assessment technique to the business. ISO 27005 is part of the ISO 27000 family of standards. |
| How does it work ? | The standard is not prescriptive about which risk management technique should be used. As such, this could encompass system driven as well as component driven techniques. However, ISO 27005 requires that a risk assessment takes into account threats, vulnerabilities, and impacts, which emphasises a component driven approach. |
| Who is it for ? | The principles of ISO 27005 can be applied to a variety of types and sizes of organisation. |
| Cost and prerequisites | Given the broad nature of the guidance, specialist skilled resources are needed to tailor the implementation to the requirements of the business. The cost of these resources should be considered along with the cost of purchasing the standards. |
| Method / Framework | Information Security Forum (ISF) IRAM 2 |
| What is it ? | The ISF's risk management methodology is intended to help organisations better understand and manage information risks. |
| How does it work ? | This approach uses a number of phases to identify, evaluate and treat risks through the analysis and assessment of risk components (threat, vulnerability and impact). |
| Who is it for ? | IRAM 2 is aimed at organisations. |
| Cost and prerequisites | IRAM 2 is only provided to members of the ISF and organisations will need to have in place information risk management expertise to use it effectively. This should be factored into the cost. |
| Method / Framework | US National Institute of Standards and Technology (NIST) SP 800-30 |
| What is it ? | The US government’s preferred risk assessment methodology, mandated for US government agencies. It features a detailed step-by-step process from the initial stages of preparing for an assessment, through conducting it, communicating the results, and maintaining the assessment. The guidance itself is comprehensive and clear. Unsurprisingly, as a US standard, much of the supporting documentation in the NIST Risk Management Framework is heavily US-focussed, often dwelling on regulatory issues that may have little relevance to non-US users. |
| How does it work ? | The risk assessment process in SP 800-30 takes inputs from a preparatory step that establishes the context, scope, assumptions, and key information sources for the process, and then uses identified threats and vulnerabilities to determine likelihood, impact and risk. The process next requires that the results are communicated, and the assessment maintained, including monitoring effectiveness of controls and verifying compliance. |
| Who is it for ? | The methodology should be usable by organisations of all sizes in both the private and public sectors. It is designed to be consistent with the ISO standards, and flexible enough to be used with other risk management frameworks. |
| Cost and prerequisites | It is freely available directly from the NIST website. |
| Method / Framework | Octave Allegro |
| What is it ? | The Operationally Critical Threat, Asset, and Vulnerability Evaluation (OCTAVE) methodology originates from Carnegie Mellon University in the USA. Older versions are still in use but the most recent version, OCTAVE Allegro, is more streamlined and is actively supported. It is primarily intended as a qualitative assessment, although you may be used for simple quantitative analysis. |
| How does it work ? | Octave Allegro is an asset-focussed method. The first step is establishing consistent, qualitative risk measurement criteria specific to the organisation’s drivers and objectives. After assets have been profiled, threats and impacts are considered in light of real world scenarios to identify risks. These risks are then prioritised according to the risk measurement criteria and planned mitigation. |
| Who is it for ? | OCTAVE is intended to be managed in a ‘workshop’ style, with a small group of participants from the operational and IT areas of the business, not requiring extensive expertise. Therefore, this approach might suit organisations looking for a risk assessment process that can be done without investing heavily in training or consultants. |
| Cost and prerequisites | The resources to perform a risk assessment can be downloaded for free and are integral to the process. |
| Method / Framework | ISACA COBIT 5 for Risk |
| What is it ? | COBIT 5 for Risk is provided by ISACA and provides guidance covering the governance and understanding of enterprise IT risk. |
| How does it work ? | COBIT 5 for Risk provides risk management and governance framework in the form of principles and guidance. |
| Who is it for ? | COBIT 5 for Risk is likely to suit organisations seeking to improve their approach to security risk management and governance. |
| Cost and prerequisites | The COBIT 5 for Risk book is available for purchase on the ISACA website. An organisation looking use COBIT 5 for Risk will also need to take into account any specialist resources necessary to implement its guidance and principles. |
Note
We have deliberately not referenced the CESG Risk Management method using a component driven approach (known as IS1/2). This standard has been formally deprecated by CESG and the NCSC no longer think it's appropriate to use as part of a risk management approach. Organisations should transition from static accreditation and risk management decision making processes, to approaches that support ‘secure by design’ and continuous assurance (such as those listed in the table above, or the basic method provided in this guidance).


