It seems to me that self-assessment of risk is a difficult process to understand and execute, primarily because the employees who are asked to assess the risk in their business process, a) don’t really understand the notion of risk and b) don’t really care. Let’s face it – risk is difficult to understand, since it is a function of many different, often-interdependent variables.
So the question I am going to pose today is: What is the best way to do a risk assessment?
and the answer is: Start by asking the right questions.
Let’s say that you have the job to collect data for a risk assessment in your business unit. You sit down with the security and compliance manager and schedule meetings with people in the unit. You figure you’re going to be less than thrilled with the quality of information you receive and the employees may not be excited by your standard checklist questions. However, you know that whistleblowing is innate in all of us and it’s worth trying to get to first base.
Drop the compliance checklist and use an attack modeling approach instead.
Explain the notion of valuable company assets, vulnerabilities, threats that exploit vulnerabilities and security countermeasures. It will take a few minutes and every employee I’ve ever met will grok the concept immediately. For starters – ask 7 questions (you notice how all the process improvement methodologies always have 7 steps…)
- What is the single most important asset in your job?
- What do you think is the single biggest threat to that asset?
- How do you think attackers cause damage to the asset?
- Can you give me one example of a security exploit (on conditions of non-disclosure)?
- If you could give the risk and compliance manager one suggestion, what would it be?
- If you had to give the CEO one suggestion, what would it be?
- If you had to give President Obama one suggestion on how to reduce the threat of global terror, what would it be?

[...] 6th, 2010 admin Leave a comment Go to comments In my last post – “The right way to assess risk”, I talked about using attack modeling to elicit information instead of self-assessment check lists. [...]
[...] to collect data December 6th, 2010 admin Leave a comment Go to comments In my article – “How to assess risk – Part I: Asking the right questions”, I talked about using attack modeling as a tool to collect data instead of using self-assessment [...]
[...] How to assess risk – Part I: Asking the right questions [...]
Following my own investigation, billions of people on our planet receive the loan from different creditors. Therefore, there’s a good possibility to get a short term loan in any country.