What's changed: Initial version
5.1Risk Assessment in Practice
Learn, through concrete organizational scenarios, how to identify and classify information assets in the field, calculate risk values (threat x vulnerability x asset value), set risk acceptance criteria, and build a response plan (mitigation, retention, avoidance, transfer) for the calculated risk.
An information security manager cannot operate on a vague sense that "something seems risky." The job requires making visible, through numbers and criteria, which information asset carries how much risk against which threat, and then responding with priorities under limited budget and staff. Exam B tests the ability to apply this decision process to real workplace situations.
5.1.1Identifying and classifying information assets
- An information asset is anything an organization holds that must be protected. This must be surveyed broadly--not just information itself, such as customer lists, contracts, and design drawings, but also the servers, PCs, storage media, and software that handle it, and even personnel who hold operational know-how. If the inventory stage scopes the target too narrowly, the risk assessment that follows inherits the gap.
- Asset classification is fundamentally ranked by importance from the viewpoints of confidentiality (C), integrity (I), and availability (A). For example, HR evaluation data weighs especially heavily on confidentiality, while payment logs weigh especially heavily on integrity (not being tampered with)--evaluation must account for the fact that even among assets that are all "important," the property that most needs protecting differs by asset.
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

