What's changed: Initial version
2.1Information Asset Management and Risk Assessment
Learn how to identify and classify information assets, the risk assessment procedure (risk identification, risk analysis, risk evaluation), how to choose among the risk treatment options (risk reduction, risk avoidance, risk transfer, risk acceptance), the difference between quantitative and qualitative risk analysis, and the residual risk that remains after treatment.
The starting point of information security management is clarifying "what to protect." The overall flow of identifying, analyzing, and evaluating the risks facing each information asset that must be protected is called risk assessment. Because an organization can never reduce risk to zero, it must judge, based on the assessment results, whether to reduce, avoid, transfer, or accept each risk, and manage the residual risk that remains after treatment down to an acceptable level--this is the core of practical understanding for SG.
2.1.1Identifying and classifying information assets
- Information assets are information and the mechanisms that handle it that hold value for the organization (customer databases, design documents, business systems, laptops, paper contracts, and so on). Building an asset inventory that leaves nothing out is the precondition for everything else in risk assessment--if the inventory is incomplete, the risks facing that asset are excluded from evaluation from the start.
- The criterion for classification is the impact on business if confidentiality, integrity, or availability (CIA) is compromised. Even within "customer data," a list containing only names and payment information containing credit card numbers require different levels of protection, and weighting controls by importance (applying stricter controls to more important assets) leads to a rational allocation of resources.
2.1.2The risk assessment procedure
- Risk identification is the stage of surfacing what threats could exploit what vulnerabilities against an information asset to cause what loss. Concrete risk scenarios are enumerated as combinations of "asset x threat x vulnerability."
- Risk analysis is the stage of estimating, for each identified risk, its likelihood (frequency) and its impact if it occurs (magnitude of loss). Risk evaluation is the stage of comparing the analysis results against predetermined acceptance criteria (risk criteria) to judge whether treatment is needed and in what priority order. The distinction is that analysis "measures the size," while evaluation "judges it against a standard."
- Quantitative risk analysis estimates probability of occurrence and expected loss in monetary or numerical terms. It is easy to use when explaining to management or making budget decisions, but has the drawback that gathering accurate data takes cost and time. Qualitative risk analysis evaluates the magnitude of risk on a relative scale such as "high/medium/low." It can be performed quickly, but has the drawback of being easily swayed by the evaluator's subjectivity.
The staples: risk assessment proceeds as risk identification -> risk analysis -> risk evaluation; risk treatment has four categories: reduction, avoidance, transfer, acceptance; quantitative analysis converts to money but data collection is costly; qualitative analysis is fast but subjective; residual risk is what remains after treatment, and it must be checked against the acceptance criteria. A classic wrong-answer pattern is confusing the four risk treatment categories (for example, mistaking outsourcing for "reduction" when it is actually "transfer").
2.1.3The four risk treatment categories and residual risk
- Risk reduction is treatment that lowers the likelihood or impact itself by introducing controls (technical, physical, or human) (for example, deploying antivirus software or strengthening access control). Risk avoidance is treatment that discontinues the activity that causes the risk itself (for example, forgoing a new service that would handle highly confidential data).
- Risk transfer is treatment that shifts the risk outside the organization (for example, taking out cyber insurance, or outsourcing work so that contractual responsibility is shared with the vendor). Risk acceptance is treatment that judges a risk to be within the acceptance criteria and tolerates it as-is without additional treatment (used for small risks where the cost of treatment would not be worth the size of the risk).
- Residual risk is the risk that remains even after risk treatment has been carried out. Because controls usually cannot reduce risk to zero, a step is needed to re-evaluate the residual risk after treatment and confirm whether it falls within the organization's acceptance criteria; if it does not, further treatment is considered.
Take the information systems department of a mid-sized company as an example of the flow from risk assessment to treatment. First, after building an asset inventory, a "sales support system holding customers' names and addresses" was surfaced as an important information asset. In the next stage, risk identification, the risk scenario of "customer data being stolen via unauthorized external access" is identified. In risk analysis, drawing on past incidents at similar companies and the results of the company's own vulnerability assessment, the likelihood was estimated as "medium" and the impact if it occurred as "large" (loss of trust, damages, business disruption). Comparing this analysis against the risk criteria in risk evaluation, it is judged to be a risk that must be treated with priority. In considering treatment, several options are compared. Introducing multi-factor authentication and strengthening access log monitoring to lower the likelihood of unauthorized access itself is a realistic first candidate: risk reduction. If the business could instead shift policy to "not hold any sensitive information beyond names and addresses in the first place," that would be risk avoidance. Taking out cyber insurance to cover potential damages is risk transfer, and outsourcing the operation of the information system itself to a specialized cloud provider, sharing contractual responsibility with the vendor, can likewise be organized as a form of transfer. Meanwhile, for a minor risk judged to have very small impact (for example, minor confusion from a typo in an internal document), the cost of treatment would not be worth it, so a judgment of risk acceptance--deliberately taking no further action--is also possible. In this case, after introducing multi-factor authentication as a reduction measure, the likelihood dropped but did not reach zero, and some unauthorized-access risk still remains. Only once this residual risk remaining after treatment is analyzed again and evaluated against the risk criteria as having "dropped to an acceptable level" does the risk assessment cycle complete.
| Risk treatment | Approach | Example |
|---|---|---|
| Risk reduction | Lower likelihood/impact | Introducing MFA |
| Risk avoidance | Discontinue the causing activity | Forgoing a business handling sensitive data |
| Risk transfer | Shift the risk outside the org | Cyber insurance, outsourcing |
| Risk acceptance | Tolerate as within criteria | Leaving a minor risk as-is |
Trap: "outsourcing work eliminates risk completely" is wrong. Outsourcing shifts risk outside the organization (transfer); risk from the vendor's own control deficiencies does not disappear--only the contractual allocation of responsibility changes. Also, "carrying out risk treatment brings risk to zero" is wrong--residual risk remains after most treatments, and it must be checked against the acceptance criteria. Furthermore, "qualitative risk analysis is best suited to management decisions because it evaluates in monetary terms" is wrong--converting to monetary terms is quantitative risk analysis; qualitative analysis is characterized by rapid evaluation on a relative scale such as high/medium/low.
2.1.4Section summary
- Risk assessment proceeds as risk identification -> risk analysis (likelihood x impact) -> risk evaluation (compare against criteria)
- Risk treatment falls into four categories: reduction (lower likelihood/impact), avoidance (discontinue the activity), transfer (shift outside the org), acceptance (tolerate as within criteria)
- Quantitative analysis converts to money but data collection is costly; qualitative analysis is fast but subjective. Residual risk remains after treatment and must be re-checked against the acceptance criteria
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. When an information systems department carries out a risk assessment, it first surfaces the risk scenario "customer data held in the sales support system could be stolen via unauthorized access." Which stage of risk assessment does this correspond to?
Q2. A company judges that the risk of offering a new service handling highly confidential customer data is too large, and decides to discontinue offering the service itself. Which risk treatment category does this correspond to?
Q3. Multi-factor authentication was introduced to lower the likelihood of unauthorized access, but some unauthorized-access risk still remains after the treatment. Which term most appropriately refers to the risk that remains after this treatment?

