The Four Elements of a Risk Assessment (2024)

by Cloud Ogre

It’s clear that security threats are on the rise so for companies with concerns, a Risk Assessment is the first step in mitigating threats. Just hours ago I received a phishing attempt to access my Apple ID via a spoofed Apple email address with a link to a server in Georgia, and I don’t mean Atlanta.

Let’s say you haven’t performed a Risk Assessment and one of your fellow employees clicks on that link and puts in their Apple ID and Password. What valuable information can be lost? Say that email doesn’t look like its coming from Apple but rather your Network Admin or a cloud based service you use like Salesforce.com? What proprietary data is at risk? How much will it cost your company? If you want to look at things more personally the ‘what about my job?’ question is fair to ask yourself as well.

In order to answer the questions above thoroughly you’ll need to have a Risk Assessment performed. This way, when it hits the fan you’ll have an idea of what exactly needs cleaning.

There are four parts to any good risk assessment and they are Asset identification, Risk Analysis, Risk likelihood & impact, and Cost of Solutions.

Asset Identification – This is a complete inventory of all of your company’s assets, both physical and non-physical. From there you’ll want to evaluate what the asset is worth. A $5,000 server’s worth is not based on its cost but a range of additional factors like what it would cost to fixit or replace it should it break or be hacked. You may want to start with an telecom audit, starting at $2,500, just to get a hold of what assets you actually have out in the field.

Risk Analysis – This is where you’ll assign both quantitative and qualitative values to risk, analyze the probability of said risk, and strategies to reduce that risk. For example, if your data center is where all your data storage and processing takes place, you’ll want to mitigate that risk by taking a hybrid approach incorporating both AWS and Azure to offload some of that compute and mitigate your risk of failure. Simultaneously, you’ll want to look at exactly what you have in the cloud and what impact you’ll have if one of your cloud providers fails. Click here for more on Cloud Data Services.

Risk Likelihood & Impact – This is the part of your risk assessment where you’ll rate the probability and its impact. Your Annual Loss Expectancy is obtained by multiplying your Single Loss Expectancy (what it will cost) by your Annual Rate of Occurrence (how often it will happen). This is where subjective opinions may clash but your organization should really rely on IT experts to make these decisions and assign these values. One of the most common mistakes that we run across in businesses are in-house data centers. Adding colocation may seem expensive until a storm floods your data center.

Cost of Solutions – Now is your chance to justify your budget with finance. If the cost of the solution far outweighs the likelihood of an event, then there’s no justification. There’s no reason to build Fort Knox for a couple of dollars and there is no reason for a Palo Alto device with all the bells and whistles for a small home office. A SonicWall will probably do just fine. Along that same line of thought, you can’t have an outdated firewall protecting sensitive health or financial information.

The Four Elements of a Risk Assessment (2024)
Top Articles
What's the difference between a Chromebook and a laptop? - Coolblue
List of Symbol Name In English and Hindi
This website is unavailable in your location. – WSB-TV Channel 2 - Atlanta
Skamania Lodge Groupon
Faridpur Govt. Girls' High School, Faridpur Test Examination—2023; English : Paper II
Form V/Legends
Don Wallence Auto Sales Vehicles
Did 9Anime Rebrand
Trade Chart Dave Richard
Jefferson County Ky Pva
Employeeres Ual
Encore Atlanta Cheer Competition
What Is Njvpdi
Gfs Rivergate
Les Schwab Product Code Lookup
Baywatch 2017 123Movies
Wisconsin Women's Volleyball Team Leaked Pictures
Define Percosivism
Craiglist Kpr
NHS England » Winter and H2 priorities
Copart Atlanta South Ga
Persona 4 Golden Taotie Fusion Calculator
[Cheryll Glotfelty, Harold Fromm] The Ecocriticism(z-lib.org)
Hewn New Bedford
Jeff Nippard Push Pull Program Pdf
Dove Cremation Services Topeka Ks
Harbor Freight Tax Exempt Portal
Summoners War Update Notes
Amazing Lash Bay Colony
How Much Is An Alignment At Costco
Unm Hsc Zoom
Rocksteady Steakhouse Menu
Capital Hall 6 Base Layout
Skroch Funeral Home
Upstate Ny Craigslist Pets
2016 Honda Accord Belt Diagram
Help with your flower delivery - Don's Florist & Gift Inc.
Domina Scarlett Ct
Lyca Shop Near Me
The Best Restaurants in Dublin - The MICHELIN Guide
The TBM 930 Is Another Daher Masterpiece
California Craigslist Cars For Sale By Owner
Charli D'amelio Bj
Courses In Touch
Ferhnvi
Enr 2100
Dragon Ball Super Card Game Announces Next Set: Realm Of The Gods
1990 cold case: Who killed Cheryl Henry and Andy Atkinson on Lovers Lane in west Houston?
Wild Fork Foods Login
The Missile Is Eepy Origin
Latest Posts
Article information

Author: Gregorio Kreiger

Last Updated:

Views: 6166

Rating: 4.7 / 5 (57 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Gregorio Kreiger

Birthday: 1994-12-18

Address: 89212 Tracey Ramp, Sunside, MT 08453-0951

Phone: +9014805370218

Job: Customer Designer

Hobby: Mountain biking, Orienteering, Hiking, Sewing, Backpacking, Mushroom hunting, Backpacking

Introduction: My name is Gregorio Kreiger, I am a tender, brainy, enthusiastic, combative, agreeable, gentle, gentle person who loves writing and wants to share my knowledge and understanding with you.