<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>I Told You So, Volume 1 - mn-government</title>
    <subtitle>Archive, Volume 1: conference talks and papers on security and risk, 2010 to 2018.</subtitle>
    <link rel="self" type="application/atom+xml" href="https://blog.itys.net/vol1/tags/mn-government/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2011-12-07T00:00:00+00:00</updated>
    <id>https://blog.itys.net/vol1/tags/mn-government/atom.xml</id>
    <entry xml:lang="en">
        <title>Why Take the Risk? Doing Risk Assessments Right</title>
        <published>2011-12-07T00:00:00+00:00</published>
        <updated>2011-12-07T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/why-take-the-risk-mngts/"/>
        <id>https://blog.itys.net/vol1/posts/why-take-the-risk-mngts/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/why-take-the-risk-mngts/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;The SANS presentation Why Take the Risk? Doing Risk Assessments Right by Matthew
J. Harmon, delivered at the 30th Annual Minnesota Government IT Symposium on
December 7, 2011, lays out a structured approach for organizations to identify,
analyze, and manage IT risks. Harmon draws on industry standards and real-world
examples to show how a disciplined risk assessment process can both prevent loss
and add strategic value.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;risks-and-probability&quot;&gt;Risks and Probability&lt;&#x2F;h2&gt;
&lt;p&gt;First, the talk defines an IT risk assessment as an analysis of system assets
and vulnerabilities to establish an expected loss from certain events based on
estimated probabilities, per the Department of the Navy (OPNAVINST 5239.1A) and
ISO Guide 73:2009. Key terminology such as threat agents, vulnerabilities,
impact, and riskis clarified, with threats described as anything capable of
harming an asset and risk framed as a function of likelihood and impact. Harmon
emphasizes that thorough identification of assets, threat scenarios, and
existing controls is essential to determine whether current safeguards reduce
risk to acceptable levels.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;frameworks&quot;&gt;Frameworks&lt;&#x2F;h2&gt;
&lt;p&gt;Second, Harmon surveys leading frameworks like NIST SP 800-30, ISO 27005, ISO
31010, FAIR, and OCTAVE and maps them onto a Plan-Do-Check-Act lifecycle. The
process begins with planning and establishing context, then moves through asset
and threat identification, vulnerability analysis, and impact assessment. He
details methods for both quantitative (e.g., Annualized Loss Expectancy
calculations) and qualitative (e.g., Low&#x2F;Medium&#x2F;High scales) analyses, and
outlines risk treatment optionsaccept, mitigate, transfer, or avoidguided by
senior-management engagement. The presentation concludes by stressing the
importance of actionable treatment plans, ongoing monitoring, and regular
reviews to maintain and improve organizational resilience.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;55902_2011-12-07_Why_take_the_risk-MNGTS.pdf&quot;&gt;Why take the risk?&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
</feed>
