Cybersecurity Risk Management
Context: Information Security and Cryptography Β· the organising philosophy of the whole security half β since perfect security is impossible, manage risk Β· the profession behind it
Quick Revision
- π― Objective: perfect cybersecurity is not achievable β instead manage risk by putting the right security controls in place across many domains.
- β‘ Key Constraint: there is a wide range of control families β no single control suffices; frameworks (NIST RMF) exist precisely because coverage must be systematic, not ad hoc.
π Managing risk
- Core premise β you cannot eliminate risk, only reduce it to an acceptable level with appropriate controls (accept the residual risk).
- Control families (NIST RMF) β 16 families in three groups:
- Technical β Access Control Β· Identification & Authentication Β· System & Communications Protection Β· System & Information Integrity Β· Accountability & Audit.
- Operational / people β Awareness & Training Β· Personnel Security Β· Physical & Environmental Protection Β· Media Protection Β· Configuration Management Β· Contingency Planning Β· Incident Response.
- Management β Risk Assessment Β· Security Planning Β· Certification/Accreditation & Security Assessments Β· System & Services Acquisition.
- Framework β the NIST Risk Management Framework (RMF) structures how controls are selected, implemented, assessed, and monitored.
π₯ Roles in cybersecurity
- Many job types β the breadth of controls implies many professional roles.
- NICE framework β the U.S. NIST National Initiative for Cybersecurity Education identifies 52 distinct roles β from analyst to architect to incident responder.
β οΈ Common Mistakes
- π‘ βSecureβ is never binary β the goal is acceptable residual risk, not perfection; claiming a system is β100% secureβ misunderstands the discipline.
- π‘ Controls are cross-cutting β technical controls (Access Control, firewalls, crypto) sit alongside people/process controls (training, personnel security, incident response) β security is not only technology.
π§ Active Recall
If perfect security is unachievable, what is the actual goal of a security programme?
Answer
- Short answer: to manage risk β select and operate the right mix of controls so that remaining (residual) risk is reduced to a level the organisation can accept, across technical, physical, and human domains.
- Why: Systematic coverage β frameworks like the NIST RMF ensure controls (from access control to incident response to training) are chosen and monitored deliberately, rather than leaving gaps an attacker exploits.