RISK-ASSESSMENT
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Interactive tool: Pentest Report Builder
OVERVIEW#
Risk assessment is the process of identifying, analyzing, and evaluating information security risks to determine their likelihood and impact. Multiple frameworks and methodologies exist, each with different strengths. Choose based on organizational maturity, available data, and regulatory requirements.
RISK FUNDAMENTALS#
Risk = Threat x Vulnerability x Impact (qualitative) Risk = Probability x Impact (quantitative) Risk = Loss Event Frequency x Loss Magnitude (FAIR) Key Terminology: Threat: potential cause of an unwanted incident Vulnerability: weakness exploitable by a threat Likelihood: probability that a threat exploits a vulnerability Impact: consequence of a risk event occurring Risk Appetite: level of risk an organization is willing to accept Risk Tolerance: acceptable variation from risk appetite Residual Risk: risk remaining after controls are applied Inherent Risk: risk before any controls or mitigations
NIST RISK MANAGEMENT FRAMEWORK (RMF) - SP 800-37#
Step 1: PREPARE - Establish context and priorities - Define risk management roles - Identify organizational risk tolerance - Perform organization-level risk assessment Step 2: CATEGORIZE - Categorize systems based on impact analysis - Use FIPS 199 impact levels (Low, Moderate, High) - Consider confidentiality, integrity, availability Step 3: SELECT - Select security controls from SP 800-53 - Tailor controls to the system's categorization - Document in the System Security Plan (SSP) Step 4: IMPLEMENT - Implement selected controls - Document how controls are deployed - Update the SSP with implementation details Step 5: ASSESS - Assess controls for effectiveness - Determine if controls are implemented correctly - Use SP 800-53A for assessment procedures - Document findings in Security Assessment Report (SAR) Step 6: AUTHORIZE - Authorizing Official reviews risk and makes decision - Accept, reject, or defer (Authority to Operate - ATO) - Document in Plan of Action and Milestones (POA&M) Step 7: MONITOR - Continuously monitor control effectiveness - Assess impact of changes to the system - Report security status to appropriate officials
FAIR (FACTOR ANALYSIS OF INFORMATION RISK)#
Quantitative model for understanding, analyzing, and measuring risk.
Risk Components:
Loss Event Frequency (LEF)
Threat Event Frequency (TEF)
Contact Frequency
Probability of Action
Vulnerability (Vuln)
Threat Capability
Resistance Strength
Loss Magnitude (LM)
Primary Loss
Productivity
Response
Replacement
Secondary Loss
Competitive Advantage
Fines & Judgments
Reputation
FAIR Analysis Steps:
1. Identify the asset at risk and threat community
2. Estimate Threat Event Frequency (how often threats occur)
3. Estimate Vulnerability (probability threat succeeds)
4. Derive Loss Event Frequency = TEF x Vulnerability
5. Estimate Primary Loss Magnitude (direct costs)
6. Estimate Secondary Loss Magnitude (indirect costs)
7. Derive Risk = LEF x LM (expressed in monetary terms)
8. Use Monte Carlo simulations for ranges and confidence
FAIR Advantages:
- Produces dollar-value risk estimates
- Defensible and repeatable methodology
- Recognized standard (Open FAIR)
- Enables cost-benefit analysis of controls
OCTAVE (OPERATIONALLY CRITICAL THREAT, ASSET, AND VULNERABILITY EVALUATION)#
Developed by Carnegie Mellon/SEI. Self-directed, workshop-based approach. OCTAVE Allegro (lightweight version): Phase 1: Establish Drivers - Define risk measurement criteria - Develop information asset profile Phase 2: Profile Assets - Identify information asset containers - Map assets to their locations (technical, physical, people) Phase 3: Identify Threats - Identify threat scenarios for each container - Consider: disclosure, modification, loss, interruption Phase 4: Identify and Mitigate Risks - Analyze risks based on criteria from Phase 1 - Develop mitigation strategies - Prioritize based on organizational impact
RISK MATRICES#
5x5 Qualitative Risk Matrix: Impact: 1-Negligible 2-Minor 3-Moderate 4-Major 5-Critical Likelihood: 5-Almost Certain M H H C C 4-Likely M M H H C 3-Possible L M M H H 2-Unlikely L L M M H 1-Rare L L L M M C = Critical (immediate action required) H = High (senior management attention, urgent mitigation) M = Medium (management responsibility, planned response) L = Low (manage by routine procedures, accept or monitor) Risk Rating Thresholds (example): Critical (20-25): Immediate escalation and remediation High (12-19): Action plan within 30 days Medium (6-11): Action plan within 90 days Low (1-5): Accept, monitor, or address during next cycle
QUANTITATIVE VS QUALITATIVE RISK ASSESSMENT#
Qualitative: + Simpler and faster to perform + Does not require extensive data + Easier to communicate to non-technical stakeholders + Good for initial screening and prioritization - Subjective and inconsistent between assessors - Difficult to justify control investments - Cannot support cost-benefit analysis Quantitative: + Objective, data-driven results + Produces monetary values for risk + Supports ROI calculations for controls + More defensible in regulatory contexts - Requires significant data and expertise - Time-consuming and resource-intensive - Precision can imply false accuracy - Hard to estimate probability for novel threats Recommended: Use qualitative for initial triage, quantitative (FAIR) for high-priority risks requiring investment decisions.
THREAT MODELING: STRIDE#
Microsoft model for identifying threats to software systems.
S - Spoofing Violates: Authentication
Can an attacker pretend to be another user or system?
T - Tampering Violates: Integrity
Can an attacker modify data in transit or at rest?
R - Repudiation Violates: Non-repudiation
Can an attacker deny performing an action?
I - Information Disc. Violates: Confidentiality
Can an attacker access unauthorized information?
D - Denial of Service Violates: Availability
Can an attacker prevent legitimate access?
E - Elev. of Privilege Violates: Authorization
Can an attacker gain unauthorized capabilities?
STRIDE Process:
1. Create a data flow diagram (DFD) of the system
2. Identify trust boundaries
3. For each element, evaluate each STRIDE category
4. Prioritize threats and identify mitigations
THREAT MODELING: PASTA#
Process for Attack Simulation and Threat Analysis (7 stages) Stage 1: Define Objectives - Business objectives, compliance requirements, risk profile Stage 2: Define Technical Scope - Application architecture, infrastructure, dependencies Stage 3: Application Decomposition - Data flows, trust boundaries, entry points, assets Stage 4: Threat Analysis - Threat intelligence, attack patterns, threat actors Stage 5: Vulnerability Analysis - Vulnerability scanning, code review, known weaknesses Stage 6: Attack Modeling - Attack trees, attack patterns (CAPEC), kill chain mapping Stage 7: Risk and Impact Analysis - Business impact, likelihood, residual risk, countermeasures
THREAT MODELING: DREAD#
Scoring model (often used alongside STRIDE). Rate each 1-10: D - Damage Potential: How much damage if exploited? R - Reproducibility: How easy to reproduce the attack? E - Exploitability: How easy to launch the attack? A - Affected Users: How many users are affected? D - Discoverability: How easy to discover the vulnerability? Risk Rating = (D + R + E + A + D) / 5 High: score 8-10 Medium: score 5-7 Low: score 1-4 Note: DREAD is less commonly used today due to subjectivity concerns with Discoverability (some argue it should always be 10).
PRACTICAL RISK ASSESSMENT TEMPLATE#
For each identified risk, document: 1. Risk ID: unique identifier (e.g., RISK-2024-001) 2. Risk Description: clear statement of the risk scenario 3. Threat Source: who or what could cause the event 4. Vulnerability: weakness that could be exploited 5. Affected Assets: systems, data, or processes at risk 6. Existing Controls: current mitigations in place 7. Likelihood: probability rating (1-5 or FAIR estimate) 8. Impact: consequence rating (1-5 or dollar value) 9. Risk Rating: calculated from likelihood x impact 10. Risk Owner: person accountable for the risk 11. Treatment Plan: accept, mitigate, transfer, or avoid 12. Target Date: deadline for implementing treatment 13. Status: open, in progress, closed
RISK TREATMENT OPTIONS#
Accept: Risk is within appetite; document and monitor Mitigate: Implement controls to reduce likelihood or impact Transfer: Shift risk to third party (insurance, outsourcing) Avoid: Eliminate the activity causing the risk
COMMON RISK ASSESSMENT PITFALLS#
- Treating risk assessment as a one-time exercise - Failing to involve business stakeholders - Confusing threats with vulnerabilities - Using overly granular or overly broad scope - Not documenting assumptions and methodology - Anchoring on existing controls instead of actual risk - Ignoring residual risk after control implementation - Not updating assessments after significant changes