Educause Security Discussion mailing list archives
Re: University-Wide Risk Assessment
From: Jim Dillon <Jim.Dillon () CUSYS EDU>
Date: Fri, 18 Aug 2006 11:07:17 -0600
While Brad's Response is more directly applicable potentially (a campus wide IT risk assessment) to your position, our department (Internal Audit) has been asked to do a University Wide risk assessment - that means IT and everything else! A different scope slightly than what you are talking about, but frankly a better scope for risk assessment in my mind - here's why. 1. The basis for any quality risk assessment is a threat or impact analysis that focuses on the BUSINESS OBJECTIVE not particularly on the supply points or supporting infrastructure (such as the IT Risk Assessments most responses have been reflecting - originates with IT, assumptions based on demand, usage, whatever...) Without a thorough, well integrated BIA/Business integrated threat analysis and objective prioritization IT tends to overprotect many things out of pure pride and good heartedness (is that a word?) and not truly prioritize limited resources in pure alignment with business objectives. 2. The general user community is not as involved in examining their dependency on IT or the risks to their day-to-day operations of an interruption in IT, thus you get false information on threat significance. As bad as we sometimes think things are, we've provided solid enough IT support for years (uptimes far greater than 95%) for people to assume commodity like delivery, thus they fail to recognize their dependency and the true nature of their risks. So I guess I'd suggest you look to tie your IT risk assessment efforts to a broader "Enterprise" or in this case "Institutional" risk assessment if you want to get the best direction. As I theorize how to focus people on IT threats/risks I've found two ways to do it, and I'm not sure how to proceed - something we'll work out. 1. Use COBIT as the model to identify the IT Assets, Other IT Resources, the Information Processes/Governance Issues, and add in External Forces. This works really well at capturing, from a business objective point of view, the risk universe. I've taken 3 very long functional risk lists from other people's work and mapped them clearly to the objectives in the COBIT model, and the risks to expected outcomes become fairly clear to me. The problem with this model is that it is not a familiar way of thinking through the problem outside IT - for example "Security" is not an item on the end list. Confidentiality is (an objective), Availability is (another business objective) Integrity is... You see my point? It's all there, just obscured from the "normal speak." I like the result very much but doubt we'll be able to use it as effectively as I'd like. Or 2. Model IT risk more functionally, less objective/process oriented. Then familiar terms such as "Sensitive Information", "Security", "Compliance", "SDLC", DRP, Data Piracy and such come up that bring about more familiar common responses. I like the COBIT model better, it spells out, "Information Effectiveness, Efficient Info Delivery, Confidentiality, Integrity, Availablity, Compliance, Reliability" as they relate to the key asset of information far better than the buzz words, but less familiarly. In the end you may need to use 2, but plan using 1 as a cross check for completeness, I think you'll find it helpful. All the above being said, here's some answers to your specific questions as best as I can imagine our process going forward.
Do you send out surveys, or is the RA done personally?
Both. We will survey over 400 Financial Principals within the 3 campus system, AND we will meet with dozens of strategic positions, as well as constituent groups such as campus IT Councils.
How detailed are the questions?
Not very - we're talking the entire university universe here. There is room for lower level risk assessment, but hopefully based on the overall enterprise/institutional priority schema.
Do you cover both technical and procedural issues?
I think so, but not with a lot of technical specificity, more on a threat/reliance basis.
Do you base the questions on existing policies?
Not really other than organizational responsibilities. We have stopped at the financial principal level rather than involve financial managers, as the audience would simply get too large.
Who answers the questions? Individual techs or heads of departments?
Financial principals! This will include presidents, chancellors, vice-chancellors, key functional managers, deans, Principle Investigators, officers, and some larger group managers.
What method do you use? Electronic? Web based? Written and signed?
We'll probably use our Blackboard system for the survey process, we already have ties to create identity management around the process there. Hope this helps. If you want a more micro/IT focused process, check out Brad's process, I think he's going the right direction, and Texas A&M has a toolset/process that originated in their IT Audit shops they claim has been very successful. They shared it with me, I think they'd likely share it with you. Best regards, Jim ***************************************** Jim Dillon, CISA, CISSP IT Audit Manager, CU Internal Audit jim.dillon () cusys edu 303-492-9734 ***************************************** -----Original Message----- From: Brad Judy [mailto:Brad.Judy () COLORADO EDU] Sent: Friday, August 18, 2006 9:04 AM To: SECURITY () LISTSERV EDUCAUSE EDU Subject: Re: [SECURITY] University-Wide Risk Assessment This is something I have been working on for the past several months and we have begun implementing it. I'll work on getting the docs on our website and send a link to the group when it's up (hopefully within a few days). In the mean time, the source material I used for developing our framework included: NIST 800 series documents OCTAVE Virginia Tech docs U Virginia docs Microsoft Risk Management Guide Burton Group articles on risk management Bits and pieces of some books and things like COSO and GAISP Bits and pieces from conferences/colleagues (including this past Educause security professionals conference) Educause also publishes a risk management framework doc, but it's pretty lightweight (might have been the goal). Pretty much everything listed above is freely available (except the Burton Group materials) - I expect most of you either already know of these items or can quickly find them. If it proves challenging to track them down, I'll dig up a list of links. I'm thinking about proposing a talk on our framework at the next Educause security professionals conference. Brad Judy IT Security Office Information Technology Services University of Colorado at Boulder
-----Original Message----- From: Alex Campoe [mailto:campoe () USF EDU] Sent: Friday, August 18, 2006 5:48 AM To: SECURITY () LISTSERV EDUCAUSE EDU Subject: [SECURITY] University-Wide Risk Assessment One thing that Connie Sadler from Brown University mentioned recently made me curious. We are about to embark on an attempt to perform a University-wide risk assessment program and we're trying to figure out
how to go about doing it. Our environment is pretty large and decentralized. The questions are many, but I would like to know how other Universities approach the issue. Do you send out surveys, or is the RA
done personally? How detailed are the questions? Do you cover both technical and procedural issues? Do you base the questions on existing
policies?
Who answers the questions? Individual techs or heads of departments?
What method do you use? Electronic? Web based? Written and signed?
Thanks
--
-- Alex Campoe, CISSP Information Security
Manager --
-- Associate Director, Systems
--
-- Email: campoe () usf edu Phone: (813) 974-1796
--
-- Academic Computing University of South Florida
--
--------------------------------------------------------------
---------
Current thread:
- University-Wide Risk Assessment Alex Campoe (Aug 18)
- <Possible follow-ups>
- Re: University-Wide Risk Assessment Franklin, Elliott (Aug 18)
- Re: University-Wide Risk Assessment Hunt,Keith A (Aug 18)
- Re: University-Wide Risk Assessment Victoriano Casas, ISO (Aug 18)
- Re: University-Wide Risk Assessment Randy Marchany (Aug 18)
- Re: University-Wide Risk Assessment Franklin, Elliott (Aug 18)
- Re: University-Wide Risk Assessment Brad Judy (Aug 18)
- Re: University-Wide Risk Assessment Jim Dillon (Aug 18)
- Re: University-Wide Risk Assessment Cheek, Leigh (Aug 18)
- Re: University-Wide Risk Assessment Shirley Payne (Aug 18)
- Re: University-Wide Risk Assessment Rodney Petersen (Aug 21)
