
Learn to assess information security risk through a practical scenario-based approach, aligning with NIST SP 830 Rev 1 and producing a comprehensive risk assessment report.
Assess information security risk to identify and prioritize threats, protect sensitive data, satisfy regulatory requirements, prevent financial losses, and support business continuity.
Identify assets, threats, and vulnerabilities; assess likelihood and impact to information security risk across four phases—preparing, conducting, communicating, and maintaining—prioritize risks, implement mitigations, and document and monitor findings.
Learn the NIST SP 800-30r1 risk assessment framework, covering preparation, threat and vulnerability identification, and risk communication. Identify threats, assess likelihood and impact, and monitor risk with ongoing updates.
Learn key risk concepts and how information security risk arises from threats and vulnerabilities. Explore risk assessment processes, methodologies, and models, including quantitative, qualitative, and semi-qualitative approaches, to prioritize risk.
Explore the fundamentals of information security risk assessment, including its purpose and roles, and how risk-based decisions support business, then prepare for building a case study in section two.
start with a blank slate to prep a foundational information security risk assessment, identify the case and objectives, and pose critical questions for each phase.
Explore a Fin Secure, Inc. case to perform an information security risk assessment with Nisp 830, identifying and mitigating risks in a hybrid IT environment for online and mobile banking.
Explore phase one of NIST SP 800-30 by preparing for risk assessment, identifying purpose, scope, assumptions, information sources, and the risk model for a case scenario.
Explore 11 critical questions for defining scope, stakeholders, information gathering, threats, vulnerabilities, likelihood, and impacts across preparation, conducting the risk assessment, communicating, and maintaining the assessment.
Establish a security team structure for the risk assessment and assign tasks with open source tools, defining roles such as risk assessment manager, security analysts, and compliance officer.
Develop a structured risk assessment approach by planning, scoping, and assigning tasks, then monitor and communicate results through a week-by-week project plan for information security risk.
Discover open-source tools for task assignment and project management in information security risk assessments, including collaboration, documentation, version control, security monitoring, and incident management.
Conduct phase two of the information security risk assessment per NIST SP 800-30, identifying threat sources, events, vulnerabilities, and predisposing conditions; assess likelihood, impact, and risk using open source tools.
identify vulnerabilities and risks in the organization using nes sp 830, summarize discovery methods and mitigation actions for categories like data breaches, ransomware, phishing, insider threats, and third-party risks.
Communicate and share risk assessment results with stakeholders using tools like MISP and cis cat, tailoring executive summaries, reports, and presentations for executive leadership and IT and security teams.
Maintain the risk assessment per nist sp 800-30 via real-time continuous monitoring and update it with monitoring results, vulnerability scans, and regulatory changes.
Understand why each ISR assessment phase requires specific tasks, including setting objectives, gathering information, mapping threats to vulnerabilities, assessing likelihood and impact, communicating results, and maintaining continuous monitoring.
Organize project information and document risk activities, mapping questions to assessment phases. Assess vulnerabilities and build a CVSS-based risk matrix to quantify data breaches and other cyber threat costs.
Estimate the financial impact of data breaches and other risk categories, justify mitigations with best practices, and compile the final risk assessment report with costs and ROI.
Present the final risk assessment report to executives. Detail the executive summary, estimated financial impact, annual mitigation costs, cost savings, and prioritized actions like multifactor authentication and encryption.
Download the ECS mind app to access and edit the mind maps, charts, and diagrams used in this course, and use them as templates for your project and organization.
Apply a four-phase information security risk assessment to the Max Finance case, detailing objectives, scope, regulatory compliance, vulnerability discovery, risk sources, a risk matrix, and a final report.
Assessing information security risk ties cyber finance and governance (GRC) to business value, guiding how to communicate with senior management and value data through a four-part cyber finance series.
Access all course resources in section six, including documents, graphs, charts, an editable Excel workbook, and mind maps to support assessing information security risk.
In this course we take a deep dive into the risk assessment element or component of the risk management process as it relates to information security.
This course focuses on a practical approach to the risk assessment component of risk management—providing a step-by-step process for organizations on: (i) how to prepare for risk assessments; (ii) how to conduct the risk assessments; (iii) how to communicate risk assessment results to key organizational personnel; and (iv) how to maintain the risk assessments over time.
Risk assessments are not simply one-time activities that provide permanent and definitive information for decision makers to guide and inform responses to information security risks. Rather, organizations employ risk assessments on an ongoing basis throughout the system development life cycle and across all of the tiers in the risk management hierarchy and that is what we intend to achieve by doing this course.
This course is broken down as follows:
SECTION-1: FOUNDATION
Intro to KEY RISK CONCEPTS
1- What does it mean to assess information security risks?
2a- Why is it necessary and what roles does this process plays in keeping an organization's, businesses, people, processes, technology and data secure?
2b-Risk assessments can support a wide variety of risk-based decisions and activities
SECTION-2: CONDUCTING THE RISK ASSESSMENT
Intro to the case scenario and its requirements
The approach to addressing the case
1-PREPARATION PHASE
2-CONDUCTING THE RISK ASSESSMENT PHASE
3-COMMUNICATING AND SHARING RISK ASSESSMENT INFORMATION PHASE
4-MAINTAINING THE RISK ASSESSMENT PHASE
5-PRODUCTING THE FINAL REPORT: Risk Assessment Report for FinSecure, Inc.
Delve into this course to see the other wonderful resources presented in the following sections.
SECTION-3:
SECTION-4:
SECTION-5: