Google

Wednesday, June 04, 2008

Risk Analysis

Labels:

technorati tags:

Sunday, January 13, 2008

Cyber Crime Toolkits

CBC News Today host Nancy Wilson speaks with Jesse Hirsh about the emergence of Cyber Crime Toolkits and the related genre of online crime and computer security.

Labels: ,

technorati tags:

Monday, November 05, 2007

Server room - flood risk

A Server room is flooded after heavy rain

Labels: ,

technorati tags:

Wednesday, October 03, 2007

Identity Theft : Data Breach, Hacking, Hackers

Labels:

technorati tags:

P2P Computer Security Risk

Risk of using P2P(peer to peer) application e.g. Bit Torrent, Kazaa, Lime Wire.

P-to-P Application Causes Police Security Disaster in Japan
A policeman in Japan was fired after a P2P application, Winny, on his PC caused highly confidential information to reach the Internet.
http://security.itworld.com/4337/070724police/page_1.html


Labels: ,

technorati tags:

Tuesday, October 02, 2007

Smokers as an IT security risk?

A U.K. firm is claiming smokers pose a risk to IT security by leaving doors open when they take a puff break. Network World investigates


Labels: , ,

technorati tags:

Thursday, August 16, 2007

IT Risk Assessment model












Modeling Information Risk Elements



Risk is combination of :-
  • Financial impact
  • Vulnerability
    • Accessibility (Physical and Network Access)
    • No of users
  • Complexity
    • System Design Complexity
    • Organisational Complexity
    • Technology Risk
For details visit:-
http://www.theiia.org/itaudit/index.cfm?act=ITAudit.archive&fid=482


Also visit:
Using Risk Models to Determine Information Risk Levels
Taking the Helicopter View of Information Risks

Labels:

technorati tags:

Monday, November 20, 2006

Illustration of an IT Risk Assessment

Area : IT Planning and Strategy

Source : IT Plan

Risk : Failure to plan for effective use of the IT resources

Outcomes:
Use of IT not alligned with the business objectives
Missed IT opportunities resulting to loss of competitive advantage

Control:
IT Long term and short term plan

Control effectiveness:
Medium effective(ME)
- IT Plan not reassessed periodically and feedback from users not captured and reported to the Steering Committee

Risk Mitigation Strategies (Recommendation):-
Review the IT plan on periodical basis via gathering feedback from the various users and report the status to the IT Steering Committee.

Labels:

technorati tags:

Tuesday, September 12, 2006

IT Risks Assessment

Previously I mentioned the equation: -
IT Risk – IT Controls = IT Exposure.

First, let’s focus on the IT Risk part. I have expressed the risk equation as follows:
Risk = Impact x Likelihood

Impact can be rated in the scale of 1 to 3, for example: -
High (3)
Could prevent the organisation from achieving all, or a major part, of its objectives for a long time
Medium (2)
Could prevent the organisation from achieving its objectives for a limited period
Low (1)
Could cause minor inconvenience, not affecting the achievement of objectives

Likelihood can be rated in the scale of 1 to 3, for example: -
High (3)
Certain / Has Happened
Medium (2)
Possible / May Happen
Low (1)
Unlikely / Never Happen


Subsequently, the “Impact” and “Likelihood” of the failure in that particular area will be multiplied to give a total “Risk” score.

Labels:

technorati tags:

Sunday, September 10, 2006

IT Risks

IT risks and circumstances or conditions giving rise to each risk :-


Infrastructure
Organization does not have an effective IT infrastructure (e.g. hardware, software, network, people and processes) to effectively support the current and future needs of the business in an efficient, cost-effective and well-controlled fashion.

The risks are generally considered within the following core IT processes:

  • Organizational planning
  • Application system definition and deployment
  • Logical security and security administration
  • Computer and network operations
  • Data and database management
  • Business/data center recovery

Access

Failure to adequately restrict access to information (data or programmes, in any form), which may result in, unauthorized knowledge and use of confidential information. Access risk can occur at any, or all of the following 5 levels i.e. network, processing environment, application system, functional access (within an application), field level access (within a function)

Integrity

Inaccuracy and incompleteness of transactions entered into, processed by, or reported by the various application systems deployed. The risk may occur due to improper segregation of duties, inadequate preventive and detective data controls e.g. balancing, reconciliation controls, error processing, interface, change management, data.

Relevance

Irrelevant information created or summarized by an application system, which may adversely affect decisions of the users. The risks relates to the usability and timeliness of information collected, maintained or distributed.

Availability
  • Unavailability of important information when needed threatens the continuity of the organization’s critical operations and processes.
  • Availability risk focuses on 3 different levels of risk:
  • Risks that can be avoided by monitoring performance and proactively addressing system issues before a problem occurs
  • Risks associated with short-term disruptions to systems where restore/recovery techniques can be used to minimize the extent of a disruption
  • Risks associated with disaster that cause longer term disruptions in information processing and which focus on controls such as backups and contingency planning

Labels:

technorati tags: