How to Assess Security Risk Using Crown Jewels

3.5K views
•
February 16, 2017
by
RSAC Cybersecurity
YouTube video player
How to Assess Security Risk Using Crown Jewels

TL;DR

Assess the most sensitive data and systems first, then evaluate their controls using document review, interviews, observation, and testing. A proper risk assessment defines scope, gathers varied evidence, analyzes likelihood or potential loss, and supports remediation and purchasing decisions by identifying which actions reduce security risk the most.

Transcript

Thank you, and good afternoon. It's, uh, it's great to be at RSA. I, I always, um, really enjoy walking the expo, hearing, hearing in the halls, dropping into sessions, and see where are we. Um, and it doesn't get any easier. It just gets more complex as our systems go to the cloud, as we merge, as our organizational missions become more complex an... Read More

Key Insights

  • A security leader's primary job is to reduce security risk using the money, staff, and other resources provided by the organization. A risk assessment supplies the analysis needed to show leadership whether that responsibility is being fulfilled and to justify security priorities.
  • A risk assessment is an objective review of the security controls protecting organizational assets. It should conclude with a probability, likelihood, or potential cost associated with losing or compromising those assets, rather than stopping after identifying weaknesses or documenting compliance status.
  • Penetration tests, audits, gap assessments, and compliance reviews are not complete risk assessments because they do not necessarily examine all relevant controls or produce a conclusion about probability or likelihood. Their findings can still serve as useful evidence within a broader assessment.
  • The Crown Jewels approach prioritizes a small collection of the organization's most sensitive data and systems. According to the description, assessing the top 2% of data can produce insights about the wider organization while controlling the effort required for enterprise assessment.
  • Assessment scope is defined by documenting which applications, systems, controls, and organizational areas are included or excluded. Valid exclusions may involve a pending spin-off, a recent acquisition, a system examined by another assessment, or a control area intentionally placed outside the current review.
  • Cloud outsourcing does not transfer every security responsibility to the provider. Organizations retain duties connected to their customers and data, including incident response and breach notification, even when a provider operates controls, creates accounts, patches systems, or reports incidents.
  • RIOT is a data-gathering model consisting of reviewing available documents, interviewing responsible people, observing real behavior, and testing controls. Combining these evidence types provides a stronger basis for identifying the actual organizational problem than relying exclusively on vulnerability scanning.
  • A failed vulnerability scan does not prove that personnel simply neglected patching. The underlying cause could be weak configuration management that reversed a patch, insufficient staff time, or another operational problem, so policies, interviews, observations, and tests must be considered together.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is a security risk assessment?

A security risk assessment is an objective review of the controls protecting an organization's assets. It examines whether expected controls are present and effective, then reaches a conclusion about the probability or likelihood of compromise, asset loss, or resulting cost. That analytical conclusion distinguishes a risk assessment from activities that merely collect findings or compare practices against requirements.

Q: Why must senior security leaders perform risk assessments?

Senior security leaders are responsible for reducing security risk with the money, personnel, and other resources assigned to them. They cannot credibly demonstrate that they are fulfilling that responsibility without analyzing and assessing risk. The assessment also creates oversight, revisits threats as the organization changes, and establishes a defensible basis for choosing future security activities and purchases.

Q: Why is a penetration test not a complete risk assessment?

A penetration test gathers useful technical evidence, but it does not necessarily review every relevant security control or conclude with a probability, likelihood, or potential loss. The same limitation applies to audits, compliance reviews, and gap assessments. These activities can contribute data to a risk assessment, but none of them independently supplies the complete analysis described in the presentation.

Q: How does the Crown Jewels risk assessment approach work?

The Crown Jewels approach concentrates assessment effort on a small set of the organization's most sensitive data and associated systems. The description states that examining the top 2% of data can reveal organizational insights. For each selected assessment subject, assessors define its purpose, assets, data, ownership, boundaries, expected controls, and the division of responsibilities with external providers.

Q: How should the scope of a risk assessment be defined?

Assessors should explicitly document what is included and excluded before gathering evidence. Each application or system should be described in terms of its purpose, assets, stored data, ownership, boundaries, and expected controls. Exclusions may cover systems being sold, new acquisitions, controls recently reviewed elsewhere, or areas intentionally placed outside the assessment, provided the reasoning is recorded.

Q: What responsibilities remain after moving systems to the cloud?

Moving a system to a cloud provider does not eliminate the organization's security responsibilities. Control ownership must be considered individually, including account creation, account reviews, incident detection, incident response, and patching. A provider may report an incident, but the affected organization still has customers and data to protect and retains responsibilities such as response and breach notification.

Q: What does RIOT mean in security risk assessment?

RIOT describes four complementary evidence-gathering methods: review available documents, interview responsible people, observe actual conditions and behavior, and test controls. Documents can include service-level agreements, administrator manuals, and previous audits. Interviews and observations add operational context, while tests provide direct evidence. Using all four methods helps assessors move beyond assumptions and identify underlying problems.

Q: Why is a vulnerability scan insufficient for assessing risk?

A vulnerability scan examines only a narrow technical slice of the environment and cannot reliably explain why a weakness exists. An old vulnerability might reflect missed patching, a patched configuration overwritten by a later build, inadequate configuration management, or overloaded personnel without enough time. Policies, procedures, interviews, observations, and tests are needed together to identify the likely cause.

Summary & Key Takeaways

  • A senior security leader's central responsibility is reducing security risk with the available money and staff. Demonstrating progress requires an assessment that objectively reviews controls protecting important assets and reaches a conclusion about likelihood or potential cost. Testing, auditing, compliance checks, and gap assessments can provide evidence, but are not complete risk assessments.

  • The Crown Jewels approach focuses assessment resources on a small set of the organization's most sensitive data and systems. The description states that assessing the top 2% of data can yield broader organizational insights. Each selected subject must be defined by its purpose, assets, data, ownership, boundaries, expected controls, and outsourced responsibilities.

  • Evidence gathering should combine RIOT: reviewing documents, interviewing responsible people, observing actual behavior, and testing controls. A vulnerability scan alone reveals only a narrow technical slice and may not identify the underlying cause of a weakness. Multiple evidence sources and experienced assessors improve data quality before risk analysis and remediation planning begin.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚