City University of Hong Kong · FACULTY OF INFORMATION TECHNOLOGY

IS6523 Chap.7 Managing IT Risk and the Economics of Controls

- one subject, every graph, every model, every mark
10 Chapters6-page Bible
Our own words - no uploaded lecturer files
Updated for this semester
Chapter 7 of 10 · IS6523

Managing IT Risk and the Economics of Controls

Two kinds of knowledge before any technique

Risk management is defined as discovering and assessing the risks to an organisation's operations and determining how they can be controlled or mitigated, and the session frames the whole of it around knowing yourself and knowing the enemy.

The first means identifying which information assets are valuable, categorising and classifying them, and understanding how they are currently protected. The second means identifying, examining and understanding the threats those assets face. Neither is a security activity in the narrow sense.

Both are inventory work, and the framework is separated from the process, the first being the strategic design of the effort and the second its implementation.

Identify, analyse, evaluate, treat

Four questions drive the process: where and what is the risk, how severe is the current level of it, is that level acceptable, and what must be done to bring it to an acceptable level.

Identification catalogues the assets, taking in staff and procedures, data and software, hardware and the networking layer, classifies them under a scheme that must be comprehensive and mutually exclusive, and prioritises them by weighted table analysis.

Comparing assets against threats produces the vulnerability list, and each threat, vulnerability and asset combination becomes the row that everything afterwards operates on.

The arithmetic, and what it is honest about

Analysis assigns a rating that the course insists means nothing in absolute terms and exists to support comparison.

It combines asset value, likelihood and the proportion of risk existing controls address, and adds an uncertainty term, because a vulnerability cannot be known in full and the effect of a control is itself an estimate. Evaluation is where the organisation's risk appetite is applied, and treatment offers defence, transference, mitigation, acceptance and termination.

The three loss formulas and the cost benefit comparison built on them are the only arithmetic in the course, and residual risk is the honest output, since the stated goal is to bring it into line with appetite rather than to zero.

In this chapter

What this chapter covers

  • 01

    Knowing the asset and knowing the threat as inventory work

  • 02

    The framework against the process

  • 03

    Identification, classification, categorisation and prioritisation

  • 04

    Six valuation questions, only two of them financial

  • 05

    Threat assessment and the vulnerability list

  • 06

    Likelihood, uncertainty and the relative risk formula

  • 07

    Risk appetite and the evaluation decision

  • 08

    Defence, transference, mitigation, acceptance and termination

  • 09

    Single loss expectancy, annualised loss expectancy and cost benefit analysis

  • 10

    Alternatives when a valuation cannot be made

Worked example · free

Price a control end to end and say what the answer rests on

Q [8 marks]. AskSia-authored practice, with AskSia-authored figures. A distributor values its order platform at two million dollars. A ransomware event would destroy sixty per cent of that value and is expected once in four years. A managed detection contract costs one hundred and forty thousand dollars a year and would cut the frequency to once in ten years without changing severity. Is it worth buying? The marks shown are an AskSia study allocation, not a University marking scheme.
  • 2Compute single loss expectancy.
  • 3Compute annualised loss expectancy before and after.
  • 2Run the comparison and recommend.
  • 1Name the estimated input the result depends on.
Single loss expectancy is asset value times exposure factor: two million at sixty per cent is one million two hundred thousand dollars per event. Annualised loss expectancy is that times the rate of occurrence, so one event in four years gives three hundred thousand dollars a year, and one in ten years gives one hundred and twenty thousand. The comparison is three hundred thousand minus one hundred and twenty thousand minus one hundred and forty thousand, which is forty thousand dollars a year in favour, so buy it. The result rests on an exposure factor and two frequencies that were estimated rather than measured, and the sixty per cent figure matters most because it multiplies through both annualised figures.
Sia tip — Convert every percentage to a decimal in the first line of working, and write the rate of occurrence as events per year rather than as an interval. Once in four years is 0.25; writing 4 there multiplies the annualised loss by sixteen.
Glossary

Key terms

Information Asset
Anything that gathers, holds, works on or moves information, and any body of information the organisation values.
Weighted Table Analysis
A method of ranking assets against criteria the organisation specifies, used because it is more straightforward than a raw estimate on a more ambiguous basis.
Exposure Factor
The percentage of an asset's value lost when a given vulnerability is exploited. It is the second term in the single loss expectancy calculation.
Annualised Rate of Occurrence
How often a specific type of attack is expected to occur within a year. It converts a per-event loss into an annual figure.
Risk Appetite
The quantity and nature of risk an organisation is willing to accept as it trades off perfect security against unlimited accessibility. It must be translated into a number before it can be applied.
Transference
The treatment strategy that shifts risk to another entity through outsourcing, insurance or service contracts, and whose effectiveness depends on the service level agreement behind it.
Termination
The treatment strategy that removes an asset from the environment representing the risk, rather than carrying the exposure as acceptance does.
Cost Avoidance
The money saved by implementing a control and so avoiding the financial consequences of an incident. It is the benefit side of a control decision.
Service Level Agreement
The instrument that makes transference work, built by determining objectives, defining requirements, setting measurements and establishing accountability.
FAQ

Managing IT Risk and the Economics of Controls FAQ

What separates acceptance from termination, and why does it matter to an auditor?

Acceptance keeps the asset and its exposure as a considered decision taken after comparing alternatives; termination removes the asset from the environment that carries the risk. The difference matters because the residues differ.

An accepted risk stays on the register, has to be reported to decision makers and reviewed periodically, while a terminated one leaves the register entirely, but only if the system was genuinely decommissioned rather than merely dropped from a catalogue.

Is a risk management programme a failure if exposure remains at the end of it?

No, and the course states the opposite position explicitly. The goal is not an exposure of zero but to bring it into line with the organisation's risk appetite, and if the people deciding have been told about the uncontrolled exposures and the proper authority groups choose to leave them in place, the programme has accomplished its primary goal. The deliverable is an informed decision rather than an absence of exposure.

Why does the relative risk formula include an uncertainty term at all?

Because the inputs are estimates and the formula would otherwise present them as measurements. A vulnerability cannot be known in full, and the degree to which a control reduces risk is itself subject to estimation error. The term gives back part of the credit taken for existing controls, which is the point: it stops a control estimate being treated as more reliable than the data behind it.

What can you do when an asset cannot be given a financial value?

Use one of the five alternatives to feasibility analysis the session names: benchmarking against comparable organisations, the argument from due care and diligence, the practices the field treats as best, the gold standard set by recognised leaders, and published government recommendations.

These matter here because the assignment and the project both ask about recent developments for which nobody yet has loss figures, and reaching for one of these beats inventing an exposure factor.

Study strategy

Exam move

Work three numeric cases in one sitting with the formulas covered, because this is the only arithmetic the course contains and speed on it is free marks. Write the five treatment strategies down and, for each, a real decision you have seen an organisation take, which will expose whether you can separate acceptance from termination.

Then practise stating, in one sentence after every computation, which input the answer is most sensitive to.

Working through Managing IT Risk and the Economics of Controls in IS6523? Sia is AskSia’s AI Information Technology tutor — ask any IS6523 Managing IT Risk and the Economics of Controls question and get a clear, step-by-step explanation grounded in how IS6523 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.

A+Everything unlocked
Unlocks this Bible + all 6 of your City University of Hong Kong subjects - and 1,000+ Bibles across every Australian university.
Sia - your IS6523 tutor, unlimited, worked the way the exam marks it
The full 6-page Bible + practice bank with worked solutions
Chrome extension - sync your LMS so Sia knows your deadlines
Bilingual EN / Chinese on every Bible and every Sia answer
$0.99 Trial
30-day money-back · cancel in one tap · how it works