Build a risk register somebody can actually act on
Task
Run the whole risk cycle against your lab estate: list the assets and who owns their risk, turn vague concerns into risk statements, score them honestly, record the mitigations actually running, and choose a treatment for each with the acceptance signed by somebody entitled to sign it. 'Ransomware' is not a risk statement, and a register in which every row says 'mitigate' records intentions rather than decisions.
Steps
- List the assets in your lab estate (systems, data sets, the backup store, the identity service) and, for each, the business role that would own its risk. The owner is a business person, never the analyst who found the problem.
- Start from six one-word concerns: ransomware, insider, vendor, cloud, leaver, flood. Rewrite each as a cause-and-consequence sentence: what happens, to which asset, with what result for the business. A statement with no consequence cannot be assessed.
- Write
/tmp/register.csvwith the headerid,asset,category,risk_statement,owner,inherent_likelihood,inherent_impact,existing_controls,residual_likelihood,residual_impact,ale,strategy,accepted_by,actions,review_date. Put double quotes round any field that contains a comma, or every column after it shifts. - Score likelihood and impact on a 1 to 5 scale, before controls (inherent) and after them (residual). List in
existing_controlsonly controls that are running today: a planned control listed as current makes the residual risk look lower than it is. - Fill
aleonly where you have real figures to support it, and writen/awhere you do not. Quantitative where you have data, qualitative where you do not, and never the other way round. - Choose a strategy for each from mitigate, transfer, avoid and accept, using at least three different ones. For the risk you accept, record the business owner who accepted it in
accepted_byand the date it is revisited inreview_date. Give every row a review date. - Write
/tmp/register-notes.mdcovering what does NOT move when you transfer a risk, which categories the register shows risk concentrating in, and two events (other than the date) that should trigger an early review.
Verify
python3 - <<'PY'
import csv,re
from collections import Counter
rows=list(csv.DictReader(open('/tmp/register.csv')))
assert len(rows)>=6, 'fewer than six entries'
for r in rows:
s=r['risk_statement']
assert len(s.split())>=12, 'risk statement too short to contain a consequence: '+s[:40]
o=r['owner'].strip().lower()
assert o and not re.search(r'analyst|security team', o), 'owner for %s must be a business role' % r['id']
assert re.match(r'\d{4}-\d{2}-\d{2}$', r['review_date'].strip()), 'no review date for '+r['id']
for a,b in (('residual_likelihood','inherent_likelihood'),('residual_impact','inherent_impact')):
assert 1<=int(r[a])<=5 and 1<=int(r[b])<=5, 'scores must be 1 to 5 for '+r['id']
assert int(r[a])<=int(r[b]), '%s is higher than %s for %s' % (a,b,r['id'])
strats=Counter(r['strategy'].strip().lower() for r in rows)
print('strategies used:',dict(strats))
assert set(strats)<= {'mitigate','transfer','avoid','accept'}, 'unknown strategy name'
assert len(strats)>=3, 'fewer than three distinct strategies - nothing was decided'
acc=[r for r in rows if r['strategy'].strip().lower()=='accept']
assert acc and all(r['accepted_by'].strip() for r in acc), 'an accepted risk with nobody named as accepting it'
q=[r for r in rows if r['ale'].strip().lower()!='n/a']
print('%d quantified, %d qualitative only' % (len(q),len(rows)-len(q)))
assert len(q)<len(rows), 'every row has an ALE - were the figures real, or invented?'
print('categories:',dict(Counter(r['category'].strip().lower() for r in rows)))
PY
grep -ciE "does not transfer|obligation|reputation" /tmp/register-notes.md
grep -ciE "incident|new system|supplier|change" /tmp/register-notes.md
The assertions enforce what makes a register usable: statements long enough to carry a consequence, a business owner rather than the analyst, residual scores no higher than inherent ones, a review date on every row, and an acceptance that names who made it. The ALE assertion is the honesty check: if every row has a currency figure, some of them were invented.
Notes
What does not transfer is worth writing in your own words. Insurance moves the money; the regulator still holds you responsible and your customers still blame you. That is the most commonly tested nuance in this objective, and the register is where it stops being an exam point and becomes a decision with a name against it.
This is an independent study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.