IS6523 Chap.7 Managing IT Risk and the Economics of Controls
Managing IT Risk and the Economics of Controls
Two kinds of knowledge before any technique
Risk management is defined as discovering and assessing the risks to an organisation's operations and determining how they can be controlled or mitigated, and the session frames the whole of it around knowing yourself and knowing the enemy.
The first means identifying which information assets are valuable, categorising and classifying them, and understanding how they are currently protected. The second means identifying, examining and understanding the threats those assets face. Neither is a security activity in the narrow sense.
Both are inventory work, and the framework is separated from the process, the first being the strategic design of the effort and the second its implementation.
Identify, analyse, evaluate, treat
Four questions drive the process: where and what is the risk, how severe is the current level of it, is that level acceptable, and what must be done to bring it to an acceptable level.
Identification catalogues the assets, taking in staff and procedures, data and software, hardware and the networking layer, classifies them under a scheme that must be comprehensive and mutually exclusive, and prioritises them by weighted table analysis.
Comparing assets against threats produces the vulnerability list, and each threat, vulnerability and asset combination becomes the row that everything afterwards operates on.
The arithmetic, and what it is honest about
Analysis assigns a rating that the course insists means nothing in absolute terms and exists to support comparison.
It combines asset value, likelihood and the proportion of risk existing controls address, and adds an uncertainty term, because a vulnerability cannot be known in full and the effect of a control is itself an estimate. Evaluation is where the organisation's risk appetite is applied, and treatment offers defence, transference, mitigation, acceptance and termination.
The three loss formulas and the cost benefit comparison built on them are the only arithmetic in the course, and residual risk is the honest output, since the stated goal is to bring it into line with appetite rather than to zero.
What this chapter covers
- 01
Knowing the asset and knowing the threat as inventory work
- 02
The framework against the process
- 03
Identification, classification, categorisation and prioritisation
- 04
Six valuation questions, only two of them financial
- 05
Threat assessment and the vulnerability list
- 06
Likelihood, uncertainty and the relative risk formula
- 07
Risk appetite and the evaluation decision
- 08
Defence, transference, mitigation, acceptance and termination
- 09
Single loss expectancy, annualised loss expectancy and cost benefit analysis
- 10
Alternatives when a valuation cannot be made
Price a control end to end and say what the answer rests on
- 2Compute single loss expectancy.
- 3Compute annualised loss expectancy before and after.
- 2Run the comparison and recommend.
- 1Name the estimated input the result depends on.
Key terms
- Information Asset
- Anything that gathers, holds, works on or moves information, and any body of information the organisation values.
- Weighted Table Analysis
- A method of ranking assets against criteria the organisation specifies, used because it is more straightforward than a raw estimate on a more ambiguous basis.
- Exposure Factor
- The percentage of an asset's value lost when a given vulnerability is exploited. It is the second term in the single loss expectancy calculation.
- Annualised Rate of Occurrence
- How often a specific type of attack is expected to occur within a year. It converts a per-event loss into an annual figure.
- Risk Appetite
- The quantity and nature of risk an organisation is willing to accept as it trades off perfect security against unlimited accessibility. It must be translated into a number before it can be applied.
- Transference
- The treatment strategy that shifts risk to another entity through outsourcing, insurance or service contracts, and whose effectiveness depends on the service level agreement behind it.
- Termination
- The treatment strategy that removes an asset from the environment representing the risk, rather than carrying the exposure as acceptance does.
- Cost Avoidance
- The money saved by implementing a control and so avoiding the financial consequences of an incident. It is the benefit side of a control decision.
- Service Level Agreement
- The instrument that makes transference work, built by determining objectives, defining requirements, setting measurements and establishing accountability.
Managing IT Risk and the Economics of Controls FAQ
What separates acceptance from termination, and why does it matter to an auditor?
Acceptance keeps the asset and its exposure as a considered decision taken after comparing alternatives; termination removes the asset from the environment that carries the risk. The difference matters because the residues differ.
An accepted risk stays on the register, has to be reported to decision makers and reviewed periodically, while a terminated one leaves the register entirely, but only if the system was genuinely decommissioned rather than merely dropped from a catalogue.
Is a risk management programme a failure if exposure remains at the end of it?
No, and the course states the opposite position explicitly. The goal is not an exposure of zero but to bring it into line with the organisation's risk appetite, and if the people deciding have been told about the uncontrolled exposures and the proper authority groups choose to leave them in place, the programme has accomplished its primary goal. The deliverable is an informed decision rather than an absence of exposure.
Why does the relative risk formula include an uncertainty term at all?
Because the inputs are estimates and the formula would otherwise present them as measurements. A vulnerability cannot be known in full, and the degree to which a control reduces risk is itself subject to estimation error. The term gives back part of the credit taken for existing controls, which is the point: it stops a control estimate being treated as more reliable than the data behind it.
What can you do when an asset cannot be given a financial value?
Use one of the five alternatives to feasibility analysis the session names: benchmarking against comparable organisations, the argument from due care and diligence, the practices the field treats as best, the gold standard set by recognised leaders, and published government recommendations.
These matter here because the assignment and the project both ask about recent developments for which nobody yet has loss figures, and reaching for one of these beats inventing an exposure factor.
Exam move
Work three numeric cases in one sitting with the formulas covered, because this is the only arithmetic the course contains and speed on it is free marks. Write the five treatment strategies down and, for each, a real decision you have seen an organisation take, which will expose whether you can separate acceptance from termination.
Then practise stating, in one sentence after every computation, which input the answer is most sensitive to.
Working through Managing IT Risk and the Economics of Controls in IS6523? Sia is AskSia’s AI Information Technology tutor — ask any IS6523 Managing IT Risk and the Economics of Controls question and get a clear, step-by-step explanation grounded in how IS6523 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.