← All cheat sheets

RISK-ASSESSMENT

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Interactive tool: Pentest Report Builder

OVERVIEW#

Risk assessment is the process of identifying, analyzing, and evaluating
information security risks to determine their likelihood and impact. Multiple
frameworks and methodologies exist, each with different strengths. Choose
based on organizational maturity, available data, and regulatory requirements.

RISK FUNDAMENTALS#

Risk = Threat x Vulnerability x Impact (qualitative)
Risk = Probability x Impact (quantitative)
Risk = Loss Event Frequency x Loss Magnitude (FAIR)

Key Terminology:
  Threat:         potential cause of an unwanted incident
  Vulnerability:  weakness exploitable by a threat
  Likelihood:     probability that a threat exploits a vulnerability
  Impact:         consequence of a risk event occurring
  Risk Appetite:  level of risk an organization is willing to accept
  Risk Tolerance: acceptable variation from risk appetite
  Residual Risk:  risk remaining after controls are applied
  Inherent Risk:  risk before any controls or mitigations

NIST RISK MANAGEMENT FRAMEWORK (RMF) - SP 800-37#

Step 1: PREPARE
  - Establish context and priorities
  - Define risk management roles
  - Identify organizational risk tolerance
  - Perform organization-level risk assessment

Step 2: CATEGORIZE
  - Categorize systems based on impact analysis
  - Use FIPS 199 impact levels (Low, Moderate, High)
  - Consider confidentiality, integrity, availability

Step 3: SELECT
  - Select security controls from SP 800-53
  - Tailor controls to the system's categorization
  - Document in the System Security Plan (SSP)

Step 4: IMPLEMENT
  - Implement selected controls
  - Document how controls are deployed
  - Update the SSP with implementation details

Step 5: ASSESS
  - Assess controls for effectiveness
  - Determine if controls are implemented correctly
  - Use SP 800-53A for assessment procedures
  - Document findings in Security Assessment Report (SAR)

Step 6: AUTHORIZE
  - Authorizing Official reviews risk and makes decision
  - Accept, reject, or defer (Authority to Operate - ATO)
  - Document in Plan of Action and Milestones (POA&M)

Step 7: MONITOR
  - Continuously monitor control effectiveness
  - Assess impact of changes to the system
  - Report security status to appropriate officials

FAIR (FACTOR ANALYSIS OF INFORMATION RISK)#

Quantitative model for understanding, analyzing, and measuring risk.

Risk Components:
  Loss Event Frequency (LEF)
    Threat Event Frequency (TEF)
      Contact Frequency
      Probability of Action
    Vulnerability (Vuln)
      Threat Capability
      Resistance Strength

  Loss Magnitude (LM)
    Primary Loss
      Productivity
      Response
      Replacement
    Secondary Loss
      Competitive Advantage
      Fines & Judgments
      Reputation

FAIR Analysis Steps:
1. Identify the asset at risk and threat community
2. Estimate Threat Event Frequency (how often threats occur)
3. Estimate Vulnerability (probability threat succeeds)
4. Derive Loss Event Frequency = TEF x Vulnerability
5. Estimate Primary Loss Magnitude (direct costs)
6. Estimate Secondary Loss Magnitude (indirect costs)
7. Derive Risk = LEF x LM (expressed in monetary terms)
8. Use Monte Carlo simulations for ranges and confidence

FAIR Advantages:
- Produces dollar-value risk estimates
- Defensible and repeatable methodology
- Recognized standard (Open FAIR)
- Enables cost-benefit analysis of controls

OCTAVE (OPERATIONALLY CRITICAL THREAT, ASSET, AND VULNERABILITY EVALUATION)#

Developed by Carnegie Mellon/SEI. Self-directed, workshop-based approach.

OCTAVE Allegro (lightweight version):
Phase 1: Establish Drivers
  - Define risk measurement criteria
  - Develop information asset profile

Phase 2: Profile Assets
  - Identify information asset containers
  - Map assets to their locations (technical, physical, people)

Phase 3: Identify Threats
  - Identify threat scenarios for each container
  - Consider: disclosure, modification, loss, interruption

Phase 4: Identify and Mitigate Risks
  - Analyze risks based on criteria from Phase 1
  - Develop mitigation strategies
  - Prioritize based on organizational impact

RISK MATRICES#

5x5 Qualitative Risk Matrix:

Impact:         1-Negligible  2-Minor  3-Moderate  4-Major  5-Critical
Likelihood:
5-Almost Certain    M           H        H          C        C
4-Likely            M           M        H          H        C
3-Possible          L           M        M          H        H
2-Unlikely          L           L        M          M        H
1-Rare              L           L        L          M        M

C = Critical (immediate action required)
H = High (senior management attention, urgent mitigation)
M = Medium (management responsibility, planned response)
L = Low (manage by routine procedures, accept or monitor)

Risk Rating Thresholds (example):
  Critical (20-25): Immediate escalation and remediation
  High (12-19):     Action plan within 30 days
  Medium (6-11):    Action plan within 90 days
  Low (1-5):        Accept, monitor, or address during next cycle

QUANTITATIVE VS QUALITATIVE RISK ASSESSMENT#

Qualitative:
  + Simpler and faster to perform
  + Does not require extensive data
  + Easier to communicate to non-technical stakeholders
  + Good for initial screening and prioritization
  - Subjective and inconsistent between assessors
  - Difficult to justify control investments
  - Cannot support cost-benefit analysis

Quantitative:
  + Objective, data-driven results
  + Produces monetary values for risk
  + Supports ROI calculations for controls
  + More defensible in regulatory contexts
  - Requires significant data and expertise
  - Time-consuming and resource-intensive
  - Precision can imply false accuracy
  - Hard to estimate probability for novel threats

Recommended: Use qualitative for initial triage, quantitative (FAIR)
for high-priority risks requiring investment decisions.

THREAT MODELING: STRIDE#

Microsoft model for identifying threats to software systems.

S - Spoofing          Violates: Authentication
    Can an attacker pretend to be another user or system?
T - Tampering         Violates: Integrity
    Can an attacker modify data in transit or at rest?
R - Repudiation       Violates: Non-repudiation
    Can an attacker deny performing an action?
I - Information Disc.  Violates: Confidentiality
    Can an attacker access unauthorized information?
D - Denial of Service  Violates: Availability
    Can an attacker prevent legitimate access?
E - Elev. of Privilege Violates: Authorization
    Can an attacker gain unauthorized capabilities?

STRIDE Process:
1. Create a data flow diagram (DFD) of the system
2. Identify trust boundaries
3. For each element, evaluate each STRIDE category
4. Prioritize threats and identify mitigations

THREAT MODELING: PASTA#

Process for Attack Simulation and Threat Analysis (7 stages)

Stage 1: Define Objectives
  - Business objectives, compliance requirements, risk profile
Stage 2: Define Technical Scope
  - Application architecture, infrastructure, dependencies
Stage 3: Application Decomposition
  - Data flows, trust boundaries, entry points, assets
Stage 4: Threat Analysis
  - Threat intelligence, attack patterns, threat actors
Stage 5: Vulnerability Analysis
  - Vulnerability scanning, code review, known weaknesses
Stage 6: Attack Modeling
  - Attack trees, attack patterns (CAPEC), kill chain mapping
Stage 7: Risk and Impact Analysis
  - Business impact, likelihood, residual risk, countermeasures

THREAT MODELING: DREAD#

Scoring model (often used alongside STRIDE). Rate each 1-10:

D - Damage Potential:      How much damage if exploited?
R - Reproducibility:       How easy to reproduce the attack?
E - Exploitability:        How easy to launch the attack?
A - Affected Users:        How many users are affected?
D - Discoverability:       How easy to discover the vulnerability?

Risk Rating = (D + R + E + A + D) / 5
  High:   score 8-10
  Medium: score 5-7
  Low:    score 1-4

Note: DREAD is less commonly used today due to subjectivity concerns
with Discoverability (some argue it should always be 10).

PRACTICAL RISK ASSESSMENT TEMPLATE#

For each identified risk, document:

1. Risk ID:           unique identifier (e.g., RISK-2024-001)
2. Risk Description:  clear statement of the risk scenario
3. Threat Source:     who or what could cause the event
4. Vulnerability:     weakness that could be exploited
5. Affected Assets:   systems, data, or processes at risk
6. Existing Controls: current mitigations in place
7. Likelihood:        probability rating (1-5 or FAIR estimate)
8. Impact:            consequence rating (1-5 or dollar value)
9. Risk Rating:       calculated from likelihood x impact
10. Risk Owner:       person accountable for the risk
11. Treatment Plan:   accept, mitigate, transfer, or avoid
12. Target Date:      deadline for implementing treatment
13. Status:           open, in progress, closed

RISK TREATMENT OPTIONS#

Accept:    Risk is within appetite; document and monitor
Mitigate:  Implement controls to reduce likelihood or impact
Transfer:  Shift risk to third party (insurance, outsourcing)
Avoid:     Eliminate the activity causing the risk

COMMON RISK ASSESSMENT PITFALLS#

- Treating risk assessment as a one-time exercise
- Failing to involve business stakeholders
- Confusing threats with vulnerabilities
- Using overly granular or overly broad scope
- Not documenting assumptions and methodology
- Anchoring on existing controls instead of actual risk
- Ignoring residual risk after control implementation
- Not updating assessments after significant changes