Risk Management & Governance

Putting a number on risk, then deciding what to do about it: quantification, treatment and appetite, control types, and threat modeling. Plus the data governance vocabulary that decides classification questions. CISSP Domains 1 and 2.

3 ARTICLES · 87 TERMS

Articles

Key terms

The expected yearly cost of a risk: Single Loss Expectancy multiplied by Annualized Rate of Occurrence (ALE = SLE x ARO), the figure that justifies control spending in quantitative analysis.

Irreversibly processing personal data so that no one can be identified from it by any means reasonably likely to be used, which places the result outside the scope of the GDPR.

Grouping assets such as systems, devices and facilities by value, sensitivity and criticality, so that the controls, monitoring and recovery priority each receives match its importance.

The maintained record of the assets an organisation holds, tangible and intangible, with each one's owner, location, classification and lifecycle state: the starting point for protecting them.

The individual accountable for an asset across its life: confirming its classification, approving its use and making sure suitable controls are in place, even when others operate it.

The senior official accountable for a line of business or a mission, who defines what its supporting systems and data must achieve and weighs their protection against business need.

A signed record that specific media or records were sanitised or destroyed, stating what was processed, by which method, when and by whom, kept as evidence for audit and chain of custody.

A rule requiring staff to lock away sensitive papers and removable media and to lock their screens whenever they leave their workspace, so unattended information is not open to others.

The least intensive NIST SP 800-88 sanitisation method: overwriting or resetting all user-addressable storage so data resists simple recovery tools, while the media stays fit for reuse.

A policy enforcement point between users and cloud services that delivers visibility, compliance, data security, and threat protection, including discovery of shadow IT.

The privacy principle that personal data is collected only as far as needed, by lawful and fair means, and where appropriate with the knowledge or consent of the person it concerns.

An alternative control adopted when the primary control is impractical or too costly. It must meet the intent and rigour of the original requirement, not merely gesture at it.

A repository of configuration items (the components that make up IT services) and the relationships between them, used to support change, incident and asset management.

The classification of security controls by the function they perform: preventive, detective, corrective, deterrent, recovery, and directive. One control can serve several functions at once.

How essential an asset, system, process or data set is to the organisation, judged by how severely and how quickly its loss would cause harm. It mainly drives availability and recovery decisions.

Sanitising encrypted data by destroying every copy of the key that protects it, so the ciphertext left on the media or in a cloud service can no longer be decrypted.

Data held in persistent storage, such as disks, databases, backups, removable media and cloud object stores, as distinct from data moving across a network or being processed in memory.

The process of assigning sensitivity labels to information so that handling, storage, and access requirements follow from the label, and controls are selected to match it.

The person or organisation that decides why and how personal data is processed, alone or jointly with others, and so carries primary accountability for that processing under the GDPR.

The technical role that implements data protection on the owner's behalf: backups, access permissions, patching, and secure storage. Responsible for the work, never accountable for the data.

A picture of a system's components, the data moving between them and its trust boundaries, used as the surface a threat model is walked across element by element.

Data moving between systems, sites or users across a network, also called data in motion, and exposed to interception and tampering along the way unless the channel is protected.

Data being actively processed, held in memory, CPU registers or cache, or shown on a screen, where it normally has to be in plaintext for the application or person to work with it.

The stages information passes through from creation or collection to destruction, with security and privacy requirements attached to each stage according to the data's classification.

Content-inspection technology that identifies sensitive data and enforces policy to stop it leaving the organisation, deployed at the network edge, on endpoints, or as discovery scans.

The ongoing work of keeping stored data accurate, current and consistent across its lifecycle, including correction, review of its classification, and removal of stale copies.

Replacing sensitive values with realistic but fictitious or partly hidden ones, either permanently in a copy (static masking) or as data is queried or displayed (dynamic masking).

The principle that personal data collected and kept should be adequate, relevant and limited to what is necessary for the stated purpose, as set out in GDPR Article 5(1)(c).

The senior business role accountable for a data set: the owner classifies the data, approves access, and sets protection requirements, and that accountability cannot be delegated.

The binding contract that GDPR Article 28 requires between a controller and a processor, limiting processing to the controller's documented instructions and setting security duties.

A person or organisation that processes personal data on behalf of a controller and on its documented instructions, as defined in GDPR Article 4(8), without deciding the purposes.

The degree to which data is fit for its intended use, commonly judged on dimensions such as accuracy, completeness, consistency, validity, timeliness and uniqueness.

The residual data that remains on storage media after deletion or formatting, recoverable until the media is properly cleared, purged, or destroyed.

The physical or geographic location where data is stored and processed, usually chosen by the organisation for legal, contractual, performance or customer reasons.

Keeping data for a defined period set by legal, regulatory and business requirements, then disposing of it securely, as documented in a retention policy and schedule.

The principle that data is subject to the laws and legal processes of the jurisdiction where it is stored, and sometimes of jurisdictions with authority over whoever holds it.

The three conditions data occupies (at rest in storage, in transit across networks, in use during processing), each demanding its own distinct protection mechanisms.

The role responsible for a data set's quality, metadata and business meaning, making sure the data is accurate, well defined and fit for its purpose on behalf of the data owner.

The identified or identifiable natural person whom personal data relates to, as defined in GDPR Article 4(1), holding rights such as access, rectification, erasure and objection.

Anyone who accesses data to perform their job, bound by the acceptable use policy and by the handling requirements that follow from the data's classification.

The authorised removal of a classification once the information's sensitivity has lapsed, so that protection does not stay higher, or last longer, than the information needs.

The controlled retirement of an asset from service: revoking its access and identities, retaining or disposing of its data, sanitising its media, and updating the inventory.

Destroying information routinely under a documented, consistently applied retention schedule, so the organisation can show the destruction was normal business practice, not concealment.

Erasing magnetic media by exposing it to a strong magnetic field matched to the media, a physical purge technique under NIST SP 800-88 that has no effect on flash storage or optical discs.

Protection that travels with content: the file is encrypted and a policy, checked each time it is opened, controls who may view, edit, print, copy or forward it, even after distribution.

Microsoft's threat-scoring model: Damage, Reproducibility, Exploitability, Affected users, Discoverability, rated on an agreed scale to rank threats a framework such as STRIDE has already found.

The vendor milestone after which a product is no longer sold or manufactured; patches and support usually continue until a later End of Support date.

The date a vendor stops issuing security patches, updates and technical help for a product, after which newly found vulnerabilities may stay unfixed while the product keeps running.

The rules, set by an asset's classification, for how information and assets are marked, stored, transmitted, accessed, retained and destroyed across their lifecycle.

The rule that a system, asset or collection takes the highest classification or impact level of any information it holds, so one confidential file makes a laptop confidential.

An asset with no physical form, such as data, software, intellectual property, trade secrets or reputation, valued by what its loss or disclosure would cost rather than by a price tag.

The practice of tracking IT hardware, software and related contracts across their lifecycle, from request and purchase through use and maintenance to retirement and disposal.

The legal ground under GDPR Article 6 that permits processing of personal data: consent, contract, legal obligation, vital interests, public task or legitimate interests.

Removing a file's directory entry or pointer and marking its space as free, while the underlying data stays on the media until something else happens to overwrite it.

Showing an asset's classification: human-readable markings on documents, screens and media, and machine-readable labels that a system uses to enforce access decisions.

Making data on storage media infeasible to recover for a given level of effort, using the Clear, Purge or Destroy methods described in NIST SP 800-88.

NIST's Guidelines for Media Sanitization, which sort sanitisation methods into Clear, Purge and Destroy and help an organisation choose one by media type, sensitivity and destination.

Writing new data, such as a fixed pattern of zeros, over the locations that held old data on storage media, so the original contents can no longer be read back by ordinary means.

Sanitising media by shredding, disintegrating, pulverising, melting or incinerating it, so data cannot be recovered even in a laboratory and the media cannot be used again.

Marking each section, paragraph or item of a document with its own classification, so readers can see which parts are sensitive, while the overall banner shows the highest level.

Replacing direct identifiers in personal data with aliases, while the information needed to re-identify people is kept separately and protected. Under GDPR it is still personal data.

The NIST SP 800-88 sanitisation level that makes data infeasible to recover even with state-of-the-art laboratory techniques, while often leaving the media reusable.

The privacy principle that personal data is collected for specified, explicit and legitimate purposes, and is not later used in ways incompatible with those purposes.

Policy and technical rules for USB drives, external disks, memory cards and tapes: whether they may be used at all, which devices are approved, how they are encrypted and how they are tracked.

The risk that remains after controls are applied. It can never reach zero, so leadership must formally accept whatever remains within the organisation's risk appetite.

The amount and type of risk leadership is willing to accept in pursuit of organisational objectives, set at board level and cascaded down as the boundary for every risk decision.

The decision on how to respond to an identified risk using one of four options: avoid it, transfer it, mitigate it, or accept it. Every identified risk gets exactly one deliberate response.

A defined minimum set of security controls or configuration settings for a class of systems or data, usually adopted from a published source such as the NIST SP 800-53B baselines.

The top of the governance document hierarchy: a mandatory, high-level statement of management intent, implemented through standards and procedures and advised by guidelines.

A drive whose own controller encrypts everything written to it in hardware, with the key held inside the drive, so the data can be sanitised quickly by cryptographic erase.

A measure of the harm that would follow if information were disclosed to people not authorised to see it: the main property that classification labels record.

Hardware, software or cloud services used for organisational work without the knowledge or approval of IT or security, and therefore missing from the inventory and its controls.

The monetary loss from one occurrence of a risk event: asset value multiplied by exposure factor (SLE = AV x EF), the per-incident building block of quantitative risk analysis.

The unused remainder of a cluster allocated to a file, between the end of the file's data and the end of the cluster, which can still hold fragments of earlier data.

Destroying, altering or failing to preserve evidence relevant to litigation that is under way or reasonably expected, including by letting routine deletion continue after a legal hold should apply.

Deciding which external regulations, standards and frameworks set the security requirements for an organisation's data, such as PCI DSS, ISO/IEC 27001 or NIST SP 800-53.

The GDPR principle in Article 5(1)(e): personal data may be kept in a form that identifies people only for as long as the purpose it was processed for requires.

Microsoft's threat categorisation model: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege, each violating one security property.

Identifying and reducing the risks inherited from suppliers, vendors, and service providers: tampered hardware, counterfeit components, malicious implants, and compromised updates.

The role accountable for an IT system or platform that stores or processes data, as distinct from the data owner, who is accountable for the information itself.

An asset with a physical form, such as a server, laptop, network device, storage medium or facility, which can be counted, tagged and valued by its purchase or replacement cost.

Systematic identification and rating of the threats a system faces, performed during design so weaknesses are engineered out before deployment rather than discovered in production.

Replacing a sensitive value, such as a card number, with a meaningless token while the real value is held in a separate secured vault; widely used to reduce PCI DSS scope.

A line on a data flow diagram where the level of trust changes, such as between the public internet and an internal network, and a crossing worth examining first.

Storage the file system records as free, which can still hold the contents of deleted files until new data happens to be written over those blocks.

A flash controller technique that spreads writes across memory cells by remapping them, which can leave old copies of data where host-based overwriting may not reach.

Erasing cryptographic keys and other sensitive security parameters, commonly by overwriting them with zeros, to make them unrecoverable from a device or from memory.