120 likes | 250 Views
Risk Management. An unexpected Journey. Table of Content. The Threats (Outside) The Vulnerabilities (Inside) The Risk Management Process ISO 27001. Do you know this place?. Threat Landscape. Advanced Persistent Threats (APT) State Sponsored: Mandiant Report
E N D
Risk Management An unexpected Journey
Table of Content • The Threats (Outside) • The Vulnerabilities (Inside) • The Risk Management Process • ISO 27001
Threat Landscape • Advanced Persistent Threats (APT) • State Sponsored: • Mandiant Report • Stuxnet, Duku and Flame network worms • Hacktivism: Anonymous, LulzSec • Organised crime • Lack of care, negligence
Too Little, Too Late? "We need to concentrate less on building castles and assuming they will be impervious, and more on building better dungeons so that when people get in they can't get anything else.“ Rik Ferguson, Global VP of Security Research, Trend Micro
The client factor • Set expectations • Agree on acceptable risk levels • Be open and upfront • Be prepared to answer difficult questions
Business Impact Analysis and Risk Assessment and Treatment Plan • BIA and RATP • Test your assets for the impact of a loss of: • Confidentiality • Integrity • Availability
What to do with Risks • Mitigate • Accept • Avoid • Transfer