Educause Security Discussion mailing list archives

Re: University-Wide Risk Assessment


From: Jim Dillon <Jim.Dillon () CUSYS EDU>
Date: Fri, 18 Aug 2006 11:07:17 -0600

While Brad's Response is more directly applicable potentially (a campus
wide IT risk assessment) to your position, our department (Internal
Audit) has been asked to do a University Wide risk assessment - that
means IT and everything else!  A different scope slightly than what you
are talking about, but frankly a better scope for risk assessment in my
mind - here's why.

1. The basis for any quality risk assessment is a threat or impact
analysis that focuses on the BUSINESS OBJECTIVE not particularly on the
supply points or supporting infrastructure (such as the IT Risk
Assessments most responses have been reflecting - originates with IT,
assumptions based on demand, usage, whatever...)

Without a thorough, well integrated BIA/Business integrated threat
analysis and objective prioritization IT tends to overprotect many
things out of pure pride and good heartedness (is that a word?) and not
truly prioritize limited resources in pure alignment with business
objectives.  

2. The general user community is not as involved in examining their
dependency on IT or the risks to their day-to-day operations of an
interruption in IT, thus you get false information on threat
significance.  As bad as we sometimes think things are, we've provided
solid enough IT support for years (uptimes far greater than 95%)  for
people to assume commodity like delivery, thus they fail to recognize
their dependency and the true nature of their risks.

So I guess I'd suggest you look to tie your IT risk assessment efforts
to a broader "Enterprise" or in this case "Institutional" risk
assessment if you want to get the best direction.

As I theorize how to focus people on IT threats/risks I've found two
ways to do it, and I'm not sure how to proceed - something we'll work
out.

1. Use COBIT as the model to identify the IT Assets, Other IT Resources,
the Information Processes/Governance Issues, and add in External Forces.
This works really well at capturing, from a business objective point of
view, the risk universe.  I've taken 3 very long functional risk lists
from other people's work and mapped them clearly to the objectives in
the COBIT model, and the risks to expected outcomes become fairly clear
to me.  The problem with this model is that it is not a familiar way of
thinking through the problem outside IT - for example "Security" is not
an item on the end list.  Confidentiality is (an objective),
Availability is (another business objective) Integrity is... You see my
point?  It's all there, just obscured from the "normal speak."  I like
the result very much but doubt we'll be able to use it as effectively as
I'd like.

 Or

2. Model IT risk more functionally, less objective/process oriented.
Then familiar terms such as "Sensitive Information", "Security",
"Compliance", "SDLC", DRP, Data Piracy and such come up that bring about
more familiar common responses.  I like the COBIT model better, it
spells out, "Information Effectiveness, Efficient Info Delivery,
Confidentiality, Integrity, Availablity, Compliance, Reliability" as
they relate to the key asset of information far better than the buzz
words, but less familiarly.  

In the end you may need to use 2, but plan using 1 as a cross check for
completeness, I think you'll find it helpful.

All the above being said, here's some answers to your specific questions
as best as I can imagine our process going forward.

Do you send out surveys, or is the RA 
done personally? 

Both.  We will survey over 400 Financial Principals within the 3 campus
system, AND we will meet with dozens of strategic positions, as well as
constituent groups such as campus IT 
Councils.

How detailed are the questions? 

Not very - we're talking the entire university universe here.  There is
room for lower level risk assessment, but hopefully based on the overall
enterprise/institutional priority schema.

Do you cover both 
technical and procedural issues? 

I think so, but not with a lot of technical specificity, more on a
threat/reliance basis.

Do you base the questions on existing 
policies?

Not really other than organizational responsibilities.  We have stopped
at the financial principal level rather than involve financial managers,
as the audience would simply get too large.

Who answers the questions? Individual techs or heads of departments? 

Financial principals! This will include presidents, chancellors,
vice-chancellors, key functional managers, deans, Principle
Investigators, officers, and some larger group managers.

What method do you use? Electronic? Web based? Written and signed?

We'll probably use our Blackboard system for the survey process, we
already have ties to create identity management around the process
there.

Hope this helps.  If you want a more micro/IT focused process, check out
Brad's process, I think he's going the right direction, and Texas A&M
has a toolset/process that originated in their IT Audit shops they claim
has been very successful.  They shared it with me, I think they'd likely
share it with you.

Best regards,

Jim

*****************************************
Jim Dillon, CISA, CISSP
IT Audit Manager, CU Internal Audit
jim.dillon () cusys edu
303-492-9734
*****************************************
 
 -----Original Message-----
From: Brad Judy [mailto:Brad.Judy () COLORADO EDU] 
Sent: Friday, August 18, 2006 9:04 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] University-Wide Risk Assessment

This is something I have been working on for the past several months and
we have begun implementing it.  I'll work on getting the docs on our
website and send a link to the group when it's up (hopefully within a
few days).

In the mean time, the source material I used for developing our
framework included:

NIST 800 series documents
OCTAVE
Virginia Tech docs
U Virginia docs
Microsoft Risk Management Guide
Burton Group articles on risk management Bits and pieces of some books
and things like COSO and GAISP Bits and pieces from
conferences/colleagues (including this past Educause security
professionals conference) Educause also publishes a risk management
framework doc, but it's pretty lightweight (might have been the goal).

Pretty much everything listed above is freely available (except the
Burton Group materials) - I expect most of you either already know of
these items or can quickly find them.  If it proves challenging to track
them down, I'll dig up a list of links.

I'm thinking about proposing a talk on our framework at the next
Educause security professionals conference.  

Brad Judy

IT Security Office
Information Technology Services
University of Colorado at Boulder

-----Original Message-----
From: Alex Campoe [mailto:campoe () USF EDU]
Sent: Friday, August 18, 2006 5:48 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] University-Wide Risk Assessment

One thing that Connie Sadler from Brown University mentioned recently 
made me curious. We are about to embark on an attempt to perform a 
University-wide risk assessment program and we're trying to figure out

how to go about doing it. Our environment is pretty large and 
decentralized.

The questions are many, but I would like to know how other 
Universities approach the issue. Do you send out surveys, or is the RA

done personally? How detailed are the questions? Do you cover both 
technical and procedural issues? Do you base the questions on existing

policies?
Who answers the questions? Individual techs or heads of departments? 
What method do you use? Electronic? Web based? Written and signed?

Thanks


-- 
--  Alex Campoe, CISSP            Information Security 
Manager       --
--                                Associate Director, Systems 
       --
--  Email: campoe () usf edu         Phone: (813) 974-1796       
       --
--  Academic Computing            University of South Florida 
       --
--------------------------------------------------------------
---------


Current thread: