What Is a Cybersecurity Risk Assessment (and HOW TO DO THEM!)

Поділитися
Вставка
  • Опубліковано 18 кві 2021
  • In this video, we're taking you on step by step tutorial on how to conduct a cybersecurity risk assessment and showing you what a cybersecurity risk assessment is and why it is important.
    Risk assessments are a critical piece of an information security program and understanding how to do them and why we do them will enable you to understand a critical piece of the GRC side of the house.
    📒 Show Notes 📒
    ⏰ Markers
    0:10 Preview
    0:32 Why cyber risk assessment?
    2:30 How do you do a Cyber Risk Assessment (case study walkthrough)
    4:00 Getting intel on how your organization is going to use a system
    5:23 Why we call it information security really (over cybersecurity)
    7:02 You got the data, now which risk assessment method to choose
    10:40 Now you have your risks, how to prioritize them
    12:03 What is and how to use a risk register (aka POAM)
    Simply Cyber's mission is to help purpose driven professionals make and and take a cybersecurity career further, faster.
    ---------------------------------------------------------------------------------
    🤝 Social Media 🤝
    LinkedIn: / geraldauger
    Twitter: / gerald_auger
    UA-cam: / geraldauger
    Discord: / discord
    Twitch: / gerald_auger_simplycyber
    ---------------------------------------------------------------------------------
    🔥 My Curated Free Cyber Resources: SimplyCyber.io
    ---------------------------------------------------------------------------------
    ---------------------------------------------------------------------------------
    🙌🏼 Donate 🙌🏼
    Like the channel and got value? Please consider supporting the channel
    www.buymeacoffee.com/SimplyCyber
    ---------------------------------------------------------------------------------
    ---------------------------------------------------------------------------------
    😎 Merch 😎
    👉🏼 SimplyCyber Branded Gear: teespring.com/stores/simplycyber
    ---------------------------------------------------------------------------------
    🎥 My livestreams are produced through StreamYard. Get a $10 credit using my referral link below if you ever upgrade to pro plan.
    STREAMYARD $10 REFERRAL - streamyard.com?pal=6534222448689152
    Disclaimer: All content reflects the thoughts and opinions of Gerald Auger and the speakers themselves, and are not affiliated with the employer of those individuals unless explicitly stated.
  • Наука та технологія

КОМЕНТАРІ • 78

  • @LuisGonzalez-qi6hn
    @LuisGonzalez-qi6hn Рік тому +16

    Summarizing Risk Analysis General Structure:
    1. Get all the intel on the system/solution you are interested in
    2. Figure the use case for this solution to your organization
    3. identify all of the vulnerabilities of the solution
    4. Figure out the likelihood of those vulnerabilities being exploited
    5. Identify the impact to your organization when they are exploited
    6. Group the vulnerabilities by priority
    7. Address the ones that are unacceptable to reduce the risk to lower level
    8. Rinse & repeat

  • @MarcusJGrey
    @MarcusJGrey 2 роки тому +9

    Its super important. Arguably the 3 most important documents you'll find in an organization is 1) the asset inventory 2) the risk analysis/inventory and 3) controls inventory. These tell you exactly what a company has, what they're afraid of and how they're protecting themselves/those assets. Great that you're shining a light on GRC topics as well!

  • @NTG2396
    @NTG2396 2 роки тому +3

    Great video I became an assurance manager and been banging my head against a brick wall trying to figure out the correct way of completing a risk assessment

  • @ArachnaeNonafel
    @ArachnaeNonafel Рік тому +3

    Thanks for these vids! I'm an older person looking to change careers and these are helpful.

  • @Cwhitlock-StudyGRC
    @Cwhitlock-StudyGRC 7 днів тому

    Such a great video, even without all the fancy studio stuff. 🤣I wish everybody watched this getting started!

  • @robertalvarado884
    @robertalvarado884 3 роки тому +4

    Wow this video just summarized my Security & Risk Analysis 311 class that I took about two years ago. Everything you taught us, I literally learned in class. Thank you.

  • @TanujPandey18
    @TanujPandey18 3 роки тому

    One of the most comprehensive video on Risk Assessment Program. I was able to relate maximum of the things. I feel happy that I found this helpful channel which is creating useful content on GRC stuff.

    • @SimplyCyber
      @SimplyCyber  3 роки тому

      You're most welcome. i've lived it a while. The pattern begins to emerge. "Rinse and repeat." lol

  • @Peyo3729
    @Peyo3729 Місяць тому

    Thank you so much! This was really helpful!

  • @realdragonking7779
    @realdragonking7779 Рік тому

    This was a helpful video and well explained! Thank you Gerald.

  • @SAnderson54
    @SAnderson54 3 роки тому +1

    More GRC videos!! Thanks so much Gerald!

    • @SimplyCyber
      @SimplyCyber  3 роки тому

      You got it! Will be sprinkling them in. Thanks AS!

  • @moechaudhry6412
    @moechaudhry6412 3 роки тому +1

    Great video! I recently moved over from Operations into a Cyber Security role that specifically deals with Risk to our organization. Would love more videos on the Risk side and if there any good book recommendations, etc.

    • @SimplyCyber
      @SimplyCyber  3 роки тому +9

      This side of the house gets less love. Best reads(stay w me on this) is NIST special publication 800-37 and 800-30. Both are free and can be downloaded

  • @udohpele1696
    @udohpele1696 2 роки тому +1

    Thanks for this Gerald. This is really awesome and well explained. 😤😤
    Thanks alot.

  • @victorchez9847
    @victorchez9847 Рік тому

    You are simply awesome.

  • @Joshua1_7sc
    @Joshua1_7sc 3 роки тому +3

    This was the most thorough, succinct explanation of risk management I've ever seen.

    • @SimplyCyber
      @SimplyCyber  3 роки тому +1

      Thanks Josh. Do it a few hundred times and you can cut out the excess. :)

  • @mmughal
    @mmughal Рік тому +5

    May be a longer version where you actually do it will be great

    • @SimplyCyber
      @SimplyCyber  4 місяці тому

      I demonstrate the process in a lab in my GRC Analyst Master course fwiw

    • @mmughal
      @mmughal 4 місяці тому

      @@SimplyCyberis that courses here in UA-cam ?

  • @waz1167
    @waz1167 4 місяці тому

    Thank you!

  • @maisaalghamdi8068
    @maisaalghamdi8068 6 місяців тому

    Amazingggggg!

  • @xssoverflow798
    @xssoverflow798 3 роки тому

    Great Summary! Just subscribed!

  • @adeyinkaakinnukawe3048
    @adeyinkaakinnukawe3048 3 місяці тому

    Came across this video while doing research for sort of a (cyber security) risk assessor portfolio for a beginner and i think it's a great resource. Can anyone help with ideas for how to continue practicing as a beginner? Thank you :)

  • @3num3r8r
    @3num3r8r 3 роки тому

    Nice presentation, methodology is spot-on.

  • @rmcgraw7943
    @rmcgraw7943 2 роки тому

    Very good video on Integration Risk assessments.

  • @ArafatAliProfile
    @ArafatAliProfile 3 роки тому

    Very good explanation. Thank you

    • @SimplyCyber
      @SimplyCyber  3 роки тому

      Glad it was helpful!

    • @ArafatAliProfile
      @ArafatAliProfile 3 роки тому

      @@SimplyCyber Just gave an interview, your videos have given me very useful insights. Thank you again ❤️

  • @jashandeep8192
    @jashandeep8192 3 роки тому +4

    • @SimplyCyber
      @SimplyCyber  3 роки тому

      Thanks so much. I've got red vids in here too, but I'm an equal opportunity cyber honk. :D

  • @nicolasmaiques121
    @nicolasmaiques121 9 місяців тому

    Hi Gerald, from all your experience what do you think about EBIOS RM methodology ?

  • @tsuyax6054
    @tsuyax6054 3 роки тому +1

    We have a GRC department on my previous company but they don't focus on IT Security but more on with company operations/financials etc.

    • @SimplyCyber
      @SimplyCyber  3 роки тому

      Yes, Risk manifests in many ways. Many companies are now seeing cyber as their top risk though given all the ransomware.

  • @24reyeser
    @24reyeser 3 роки тому

    Yeahhhhhhh!!!!!!

    • @SimplyCyber
      @SimplyCyber  3 роки тому

      All Things Risk Assessments. Hope you enjoy. As the video goes on I get more frothed up. :)

    • @24reyeser
      @24reyeser 3 роки тому

      @@SimplyCyber get better soon!!

  • @khoapham1821
    @khoapham1821 2 роки тому +1

    Thank you for the awesome video. I feel that you skip 1 big major step, is to identify all vulnerability. How one can identify them all ?

    • @oberlinio
      @oberlinio Рік тому +1

      If you mean for risk assessment on organization's assets, then scope the assessment to particular system(s) and use an appropriate vulnerability scanning tool

  • @SatishSingh-ni8bu
    @SatishSingh-ni8bu Рік тому

    I just watched "Cybersecurity Risk Assessment (A Step by Step Tutorial and WHY!)" ...its awesome! beautifully explained and to the point ....
    May I know how should I get in touch with you to learn more about the Cyber Risk Assessment in details...

    • @SimplyCyber
      @SimplyCyber  Рік тому +1

      Simplycyber.teachable.com is a course I made all about GRC work, including a section and lab on risk assessment

  • @manhalfamazing00
    @manhalfamazing00 2 роки тому +1

    Subscribed. I need more cyber management skills. Any recommendation on reading material?

    • @SimplyCyber
      @SimplyCyber  2 роки тому

      managing what? Tech, people, cyber program? I can advise, but need to know specfic.

  • @frankiebaltimore9851
    @frankiebaltimore9851 5 місяців тому

    Shouldn’t RAs cater beyond technical controls. Aren’t administrative, operational and physical controls a part of the risk analysis/assessment?

  • @Enyalus87
    @Enyalus87 3 роки тому +1

    If you're doing this professionally, like you're a security auditor or compliance manager or that's the career direction you're trying to go, do you need to know/be certified in ISO 27001 or COBIT or anything?

    • @SimplyCyber
      @SimplyCyber  3 роки тому +3

      For the most part no, but there are a few where it’s yes (see below). You could get CISA cert to differentiate yourself but that’s it. I believe PCI auditors need to be certified by PCI to be a QSA. Also with the new us govt CMMC refs you will here to be certified to officially audit.

    • @lyndonmodomo2973
      @lyndonmodomo2973 4 місяці тому

      Yes know ISO27001-ISO27005. I just lost a contract because I started talking about the NIST and the guy was in another country and did not like the USA. If I had known I would have talked about the ISO framework but used the NIST 800-53 behind the scenes as well as the ISO. Since things are going global, know whats in those ISOs I mentioned above. Good luck ALL!!!!

  • @alieconteh7407
    @alieconteh7407 5 місяців тому

    How do you approach institutions for them to provide you with risk assessment information as a start-up cybersecurity company

    • @SimplyCyber
      @SimplyCyber  5 місяців тому

      I’d offer the first few as free assessments in exchange for testimonials and then build on top of that. Especially if ur targeting other small biz that will recognize and appreciate the histle

  • @jarmandog8372
    @jarmandog8372 2 роки тому +1

    Are companies obliged to share or publish their vulnerability assessments or Penetration tests? I know some publish their SOC 2 or ISO 27K compliance papers, but I haven't seen any public pentest/VA done to the services I consume

    • @SimplyCyber
      @SimplyCyber  2 роки тому +2

      Def not. It would show your weaknesses and gaps. It would be a blueprint for bad guys to see where you’re soft

    • @jarmandog8372
      @jarmandog8372 2 роки тому +1

      @@SimplyCyber Agree. I misunderstood you, maybe as an auditor/Compliance external you'd ask for it, but they're absolutely not required to share them to the general public 👍

    • @jarmandog8372
      @jarmandog8372 2 роки тому +1

      @@SimplyCyber Are you planning on making videos about Threat Modeling orgs or specific apps? That'd be amazing! I'm liking the simplicity in which you explain in a short time 👌

    • @SimplyCyber
      @SimplyCyber  2 роки тому +1

      @@jarmandog8372 it’s not on the video schedule but a great concept. Will add it. Thx

  • @Ad000121
    @Ad000121 11 місяців тому

    Does anyone know of some risk assessment case studies

  • @ericlb8769
    @ericlb8769 Рік тому

    is there a place where i can find some TRA template for cyber security ? thanks

    • @SimplyCyber
      @SimplyCyber  Рік тому +2

      Not really but 5 questions to start and ask them.
      What’s their security awareness program look like?
      Where do they use mfa?
      Do they require remote access into your environment and if so how (you prefer vpn and isolated to only systems they need)
      How do they handle your data when in their control? (Encrypted backed up delete when not needed)
      After contract termination how easy is it to get your data out and they not keep it too?
      Bonus questions: do you sell any of our data or meta data?
      Are you (and of the answer isn’t yes run) going to notify us and how quickly if your confirm a incident on systems where our data is.
      That’s just off the cuff w my Friday afternoon happy hour beer but would say the same if you were sitting next to me.
      Cheers friend!

    • @ericlb8769
      @ericlb8769 Рік тому

      @@SimplyCyber thanks a lot that s a grest start :)

  • @AMR-amr1
    @AMR-amr1 2 роки тому +1

    I want to write a master's thesis on risk assessment in drones .can you help me

    • @SimplyCyber
      @SimplyCyber  2 роки тому +1

      That’s substantial. I can speak to the concept but I don’t have the availability to actively participate in the thesis research

    • @AMR-amr1
      @AMR-amr1 2 роки тому +1

      Thanks
      How can I communicate with you better ?

    • @SimplyCyber
      @SimplyCyber  2 роки тому

      @@AMR-amr1 I’m on discord and LinkedIn. And just to be fully transparent I can have a conversation but I don’t have the bandwidth to help you in a material way w your thesis

  • @user-oz9vf1cy7c
    @user-oz9vf1cy7c 10 місяців тому

    Can you please let us have the transcript of the video?

  • @jamesclark9380
    @jamesclark9380 4 місяці тому

    Content actually starts at 2:40

    • @SimplyCyber
      @SimplyCyber  4 місяці тому

      Lil “why” before that but yes the meat of the RA workflow you can jump to at 2:40

  • @amarullohripai3745
    @amarullohripai3745 3 роки тому

    How vulnerabilities assessment?

    • @SimplyCyber
      @SimplyCyber  3 роки тому

      You have to factor in threat intelligence, position of the system with the vulnerability in relation to (network) access, if there is an exploit available, if its being exploited in the wild, if there is a patch out. There are a lot of factors for vuln assessment. Maybe another video idea?

  • @JohnEButton
    @JohnEButton Рік тому +2

    FAIR isnt semi-quantitative....totally false.

    • @bggees
      @bggees Рік тому

      Yep, not semi-quantitative. He probably said that because you can still map your results (e.g., Loss exposure) to the Low, Mid, High (qualitative scale) that most folks are used to.