Search      


Security Planning Protocol Step 2: Risk Analysis

2-A. Identify Risks

Inventory your technology, data, & expertise*

  • Systems: internal & external extensions
  • Data: accuracy, integrity, security, privacy
  • Physical plant
  • People: staff, users, stakeholders

Measure potential impact of disruptive events
on organization if assets are…

  • Disclosed
  • Corrupted
  • Taken out of service
* Asset-based approach draws on work done by Software Engineering Institute at Carnegie-Mellon University
*

2-B. Assess Vulnerabilities & Threats

  • Systems: weakness may be inherent, created during installation or configuration, caused by maintenance or patterns of ( mis)use, or by attacks
  • Physical plant: exposure to power loss or spikes, floods or burst pipes, overheating or cold, vandalism or fire
  • Organization: inadequate policies, training, or staffing
  • People: accidental and intentional causes

2-C. Security Stress Tests

  • Diagnostic tests: Periphery, Internals, Shared Spaces
  • Operational Reviews
  • User evaluation
  • Architectural evaluation

Prioritize security gaps
Rank on impact, then probability

*
                    
 OUTCOME:
Security Project Description
A project description that includes goals, processes, resources, and decision-making standards.

 CoSN Events

 
     
6/1/2012 9:00 AM Missouri CTO Clinic
6/14/2012 8:30 AM Florida CTO Clinic
6/20/2012 CETL Exam: Austin, TX
6/20/2012 8:30 AM Texas CTO Clinic
6/24/2012 CETL Exam: San Diego, CA
9/27/2012 8:30 AM Georgia CTO Clinic

 News
App Promotes Savvy Web Use Among Kids
A new tool for keeping young teens and pre-teens safe while using social media has been launched using simulated situations the youths might face in their daily school lives. Read Article.

How to practice safe social networking
National Cyber Security Awareness Month Kicks Off Today
10 Security Tips to Prevent a Cloud Migration Disaster
Missouri lawmakers vote to repeal Facebook limits
Consortium for School Networking (CoSN)
1025 Vermont Avenue NW, Suite 1010
Washington, DC 20005-3599
Toll Free 866.267.8747
Telephone 202.861.2676
Fax 202.393.2011
 

 

 
 
Attribution-Noncommercial