风险分析示例:如何评估风险
Mar 17, 2023
组织在多个方面都面临风险困扰,包括网络安全、责任、投资等。风险分析(或风险评估)是风险管理流程中的第一步。 IT risk analysis 关注内部和外部威胁对 availability, confidentiality, and integrity 的影响风险。通过风险分析,企业会识别风险以及后果的严重程度,例如一旦发生事件,可能给业务带来的潜在损失。
风险分析过程包括:界定处于风险之中的资产(IT 系统和数据)、每项资产面临的威胁、每种威胁的关键程度,以及系统对该威胁的脆弱性。建议采用结构化、以项目为导向的方法来开展风险分析,例如 NIST SP 800-30 或 ISO/IEC 27005:2018 与 31010:2019 中提供的方法。
风险分析之所以重要,有多方面原因。负责在基础设施中降低风险的 IT 专业人员,往往难以判断哪些风险需要尽快解决、哪些风险可以稍后处理;而风险分析有助于他们进行合理的优先级排序。此外,许多监管和合规要求都包含 security risk assessment 作为必备环节。
在本文中,我们将查看一个风险分析示例,并说明 IT 风险分析流程的关键组成部分。
风险分析示例
下面各部分将阐明风险分析文档的关键组成部分。
简介
本部分说明评估流程为何以及如何被处理。内容包括对已审查系统的描述,并明确了为提供和收集信息以及对其进行分析所需的责任分工。
目的
在本节中,您需要定义对 IT 系统进行详细评估的目的。下面是一个示例:
根据年度企业风险评估,< system name > 被识别为潜在的高风险系统。风险评估的目的是识别与 < system name > 相关的威胁和漏洞,并制定减轻这些风险的计划。
范围
在本节中,您需要定义 IT 系统评估的范围。请描述在风险评估中需要考虑的系统组件、用户以及其他系统细节。
本次风险评估的范围是评估资源和控制(已实施或计划实施)的使用情况,以消除和/或管理可被来自 < system name > 内部和外部的威胁所利用的漏洞。
系统描述
列出将被审查的系统、硬件、软件、接口或数据,以及其中哪些不在评估范围内。这是为了进一步分析系统边界、功能、系统与数据的重要性及敏感性。下面是一个示例:
< system name > 由用于处理 < sensitive / critical / regulated > 数据的 < components, interfaces > 组成。< system name > 位于 < details on physical environment >。该系统提供 < core functions >。
参与者
本节包含参与者姓名及其角色的列表。应包括资产所有者、IT 和安全团队,以及风险评估团队。
评估方法
本节将说明用于风险评估的所有方法论和技术。例如:
风险将基于威胁事件、该威胁事件发生的可能性、已知系统漏洞、缓解因素以及对公司使命的影响来确定。 数据收集阶段包括识别并面谈组织中的关键人员,以及开展文档审查。面谈将聚焦于运行环境。文档审查为风险评估团队提供依据,用于评估对政策和程序的合规性。
风险识别与评估
这里开始 信息安全风险评估的核心部分:在此阶段,你需要汇总评估实地工作的结果。
精选相关内容:
数据清单
识别并定义范围内所有有价值的资产:服务器、关键数据、受监管的数据或其他数据(其暴露将对业务运营产生重大影响)。例如:
Type of data | Description | Level of sensitivity (High, Moderate, Low) |
|---|---|---|
|
Personally identifiable information |
|
High |
|
Financial information |
|
High |
系统用户
描述使用系统的人员,并提供用户位置以及访问级别的详细信息。你可以使用下面的示例:
System name | User Category | Access Level (Read, Write, Full) | Number of users | Home Organization | Geographic Location |
|---|---|---|---|---|---|
|
<Name of business application> |
Regular user |
Read/Write |
10 |
ABC Group |
Atlanta |
威胁识别
编制威胁来源的目录。简要描述可能对组织运营产生负面影响的风险,从安全漏洞和技术失误到人为错误以及基础设施故障:
Threat source | Threat action |
|---|---|
|
Cyber criminal |
|
|
Malicious insider |
|
|
Employees |
|
|
Reputation |
|
|
Organizational (planning, schedule, estimation, controlling, communication, logistics, resources and budget) |
|
|
Legal and administrative actions |
|
|
Technical |
|
|
Environmental |
|
漏洞识别
评估哪些漏洞和薄弱环节可能使威胁者突破你的安全防护。以下是一个示例:
Vulnerability | Description |
|---|---|
|
Poor password strength |
Passwords used are weak. Attackers could guess the password of a user to gain access to the system. |
|
Lack of disaster recovery |
There are no procedures to ensure ongoing operation of the system in the event of a significant business interruption or disaster. |
风险确定
在这里,你需要评估威胁与漏洞会造成损害的概率,以及这些后果的影响范围。
风险概率确定
在此步骤中,请重点评估风险概率——也就是风险发生的可能性。
Level | Probability Definition | Example |
|---|---|---|
|
High |
The threat source is highly motivated and sufficiently capable, and controls to prevent the vulnerability from being exercised are ineffective. |
Unauthorized malicious disclosure, modification, or destruction of information |
|
Moderate |
The threat source is motivated or capable, but controls are in place that may impede successful exercise of the vulnerability. |
Unintentional errors and omissions |
|
Low |
The threat source lacks motivation or capability, or controls are in place to prevent, or at least significantly impede, the vulnerability from being exercised. |
IT disruptions due to natural or man-made disasters |
影响分析
进行风险影响分析,以了解一旦发生事件,业务将面临哪些后果。风险分析可以包括定性风险评估,用于识别风险中最危险的部分,例如数据丢失、系统停机以及法律后果。定量风险评估是可选项,用于以财务方式衡量影响。
Incident | Consequence | Impact |
|---|---|---|
|
Unauthorized disclosure of sensitive information |
The loss of confidentiality with major damage to organizational assets. The incident may result in the costly loss of major tangible assets or resources, and may significantly violate, harm or impede the organization’s mission, reputation or interests. |
High |
|
IT disruptions due to unauthorized changes to the system |
The loss of availability with a serious adverse effect on organizational operations. The organization is able to perform its primary functions, but the effectiveness of the functions is significantly reduced. |
Medium |
|
Non-sensitive data is lost by unauthorized changes to the data or system |
The loss of integrity with a limited effect on organizational operations assets, or individuals. The organization is able to perform its primary functions, but the effectiveness of the functions is noticeably reduced. |
Low |
风险等级评估
在此步骤中,将风险分析结果与风险评估标准进行对比。结果用于 确定风险优先级 ,并根据风险等级进行排序。
Level of Impact | Risk Level Definition |
|---|---|
|
High |
There is a strong need for corrective measures. The system may continue to operate, but a corrective action plan must be put in place as soon as possible. |
|
Moderate |
Corrective actions are needed and a plan must be developed to incorporate these actions within a reasonable period of time. |
|
Low |
The system’s owner must determine whether corrective actions are still required or decide to accept the risk. |
风险评估结果
请在“Risk Assessment Results(风险评估结果)”表中列出风险。报告应描述威胁与漏洞、衡量风险,并给出用于实施控制措施的建议。
Threat | Vulnerabilities | Mitigation | Likelihood | Impact | Risk |
|---|---|---|---|---|---|
|
Hurricane |
Power outage |
Install backup generators |
Moderate |
Low |
Low |
|
Lack of disaster recovery plan |
Disaster recovery |
Develop and test a disaster recovery plan |
Moderate |
High |
Moderate |
|
Unauthorized users can access the server and browse sensitive company files |
Open access to sensitive content |
Perform system security monitoring and testing to ensure adequate security is provided for <server name>. |
Moderate |
High |
Moderate |
结论
风险分析可帮助您了解哪些风险是最优先需要处理的。通过持续审查诸如权限、策略、数据和用户等关键领域,您可以确定哪些威胁对您的 IT 生态系统带来最高风险,并相应调整所需的控制措施,以提升安全性和合规性。
分享到
了解更多
关于作者
Ryan Brooks
产品布道者
Netwrix Corporation 的产品布道者,同时也是作者和演讲者。Ryan 专注于宣传网络安全,并强调了解 IT 变更与数据访问的重要性。作为作者,Ryan 关注 IT 安全趋势、调研以及行业洞见。