Risk Analysis
Labels: risk
Audit in the area of IT from the lay man perspective, also for beginners. In other word, IT audit for dummies. Contain links to the other IT audit, security and control related websites.
P-to-P Application Causes Police Security Disaster in Japan
A policeman in Japan was fired after a P2P application, Winny, on his PC caused highly confidential information to reach the Internet.
http://security.itworld.com/4337/070724police/page_1.html
Labels: physical security audit, risk, security

Labels: risk
Labels: risk
Previously I mentioned the equation: -
IT Risk – IT Controls = IT Exposure.
First, let’s focus on the IT Risk part. I have expressed the risk equation as follows:
Risk = Impact x Likelihood
Impact can be rated in the scale of 1 to 3, for example: -
High (3)
Could prevent the organisation from achieving all, or a major part, of its objectives for a long time
Medium (2)
Could prevent the organisation from achieving its objectives for a limited period
Low (1)
Could cause minor inconvenience, not affecting the achievement of objectives
Likelihood can be rated in the scale of 1 to 3, for example: -
High (3)
Certain / Has Happened
Medium (2)
Possible / May Happen
Low (1)
Unlikely / Never Happen
Subsequently, the “Impact” and “Likelihood” of the failure in that particular area will be multiplied to give a total “Risk” score.
Labels: risk
Infrastructure
Organization does not have an effective IT infrastructure (e.g. hardware, software, network, people and processes) to effectively support the current and future needs of the business in an efficient, cost-effective and well-controlled fashion.
The risks are generally considered within the following core IT processes:
Access
Failure to adequately restrict access to information (data or programmes, in any form), which may result in, unauthorized knowledge and use of confidential information. Access risk can occur at any, or all of the following 5 levels i.e. network, processing environment, application system, functional access (within an application), field level access (within a function)
Integrity
Inaccuracy and incompleteness of transactions entered into, processed by, or reported by the various application systems deployed. The risk may occur due to improper segregation of duties, inadequate preventive and detective data controls e.g. balancing, reconciliation controls, error processing, interface, change management, data.Labels: risk