Cybersecurity Risk Management

Context: Information Security and Cryptography Β· the organising philosophy of the whole security half β€” since perfect security is impossible, manage risk Β· the profession behind it

Quick Revision

  • 🎯 Objective: perfect cybersecurity is not achievable βž” instead manage risk by putting the right security controls in place across many domains.
  • ⚑ Key Constraint: there is a wide range of control families β€” no single control suffices; frameworks (NIST RMF) exist precisely because coverage must be systematic, not ad hoc.

πŸ“ Managing risk

  • Core premise βž” you cannot eliminate risk, only reduce it to an acceptable level with appropriate controls (accept the residual risk).
  • Control families (NIST RMF) βž” 16 families in three groups:
    • Technical βž” Access Control Β· Identification & Authentication Β· System & Communications Protection Β· System & Information Integrity Β· Accountability & Audit.
    • Operational / people βž” Awareness & Training Β· Personnel Security Β· Physical & Environmental Protection Β· Media Protection Β· Configuration Management Β· Contingency Planning Β· Incident Response.
    • Management βž” Risk Assessment Β· Security Planning Β· Certification/Accreditation & Security Assessments Β· System & Services Acquisition.
  • Framework βž” the NIST Risk Management Framework (RMF) structures how controls are selected, implemented, assessed, and monitored.

πŸ‘₯ Roles in cybersecurity

  • Many job types βž” the breadth of controls implies many professional roles.
  • NICE framework βž” the U.S. NIST National Initiative for Cybersecurity Education identifies 52 distinct roles β€” from analyst to architect to incident responder.

⚠️ Common Mistakes

  • πŸ’‘ β€œSecure” is never binary βž” the goal is acceptable residual risk, not perfection; claiming a system is β€œ100% secure” misunderstands the discipline.
  • πŸ’‘ Controls are cross-cutting βž” technical controls (Access Control, firewalls, crypto) sit alongside people/process controls (training, personnel security, incident response) β€” security is not only technology.

🧠 Active Recall