<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ISO27k - RiskInsight</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/tag/iso27k-en/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/en/tag/iso27k-en/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Mon, 30 Nov 2020 17:43:10 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>ISO27k - RiskInsight</title>
	<link>https://www.riskinsight-wavestone.com/en/tag/iso27k-en/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Quantified Risk Assessment (1/2): A Quantification Odyssey</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/11/quantified-risk-assessment-1-2-a-quantification-odyssey/</link>
		
		<dc:creator><![CDATA[Charles Dubos]]></dc:creator>
		<pubDate>Mon, 30 Nov 2020 17:42:47 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[FAIR]]></category>
		<category><![CDATA[FAIR methodology]]></category>
		<category><![CDATA[ISO27k]]></category>
		<category><![CDATA[OpenFAIR]]></category>
		<category><![CDATA[risk]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=14448</guid>

					<description><![CDATA[<p>A few months ago, François LUCQUET and Anaïs ETIENNE told us of the growing interest in quantifying cyber risks[1], but also warned us against going to the path of quantification without prior reflection. Their analysis, which is still relevant, emphasized...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/11/quantified-risk-assessment-1-2-a-quantification-odyssey/">Quantified Risk Assessment (1/2): A Quantification Odyssey</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>A few months ago, François LUCQUET and Anaïs ETIENNE told us of the growing interest in quantifying cyber risks<a href="#_ftn1" name="_ftnref1">[1]</a>, but also warned us against going to the path of quantification without prior reflection. Their analysis, which is still relevant, emphasized in particular the level of maturity required to engage in a method of quantitative estimation. This latter point of maturity level drastically reduces the scope of organizations which are likely try it out. However, some methods of quantification are the source of solutions that give hope in the ability of quantifying its risks in financial terms, and by the same logic of being capable to estimate a return on investment.</p>
<p>It is therefore useful at this point to take a look at the existing methods and the theories that could lead us to concrete results. In the big bang of cyber risk quantification, what are the theoretical foundation for the development of a method? Which ones have succeeded, which ones seem mature? Can we expect in the short or medium term, alternatives to the current quantitative assessment methods?</p>
<p>&nbsp;</p>
<h2>Roadmap: Risk analysis and quantification:  what can we expect of it?</h2>
<p>To locate the quantification in the field of risk management, let&#8217;s start by clarifying what we are looking for. Within the risk management process, the primary objective is to define an efficient numerical value, illustrating a level of risk (usually a financial cost).</p>
<p>It is therefore, according to the ISO27k standard, only a new risk assessment. Indeed, preceding phases of risk contextualization and identification have no reason to be affected by quantification. The phases of risk treatment, acceptance, supervision or communication, while they will benefit from the results of the quantitative analysis, are unchanged in their workflow. Simply put, it is only question of changing the way each risk is estimated and computed.</p>
<p>&nbsp;</p>
<figure id="post-14762 media-14762" class="align-none"><img fetchpriority="high" decoding="async" class="wp-image-14762 size-full aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/10/Image4.png" alt="" width="761" height="553" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/10/Image4.png 761w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/10/Image4-263x191.png 263w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/10/Image4-54x39.png 54w" sizes="(max-width: 761px) 100vw, 761px" /></figure>
<p>&nbsp;</p>
<p>This point, rather trivial but crucial, allows us to ensure that, even if they are fundamentally different from the qualitative methods in their results, the quantitative ones will in any case support pre-existing methods. So, we can be reassured that, although it is necessary to use them to have a mature risk management process, it will also be the basis for the quantification (that will thus exploit the pre-existing risk identification phase).</p>
<p>Now that we have framed the contribution of quantification in an organization&#8217;s overall risk analysis, let us specify what we would expect (regardless of the possibility of achieving these assertions):</p>
<ul>
<li>On the one hand, it is imperative for this method to be more precise in its result, compared to the qualitative method that it has to replace. This means above all that, from the first occurrence and without having previous results records, it must give a precise numerical estimation (which may as far as possible contain several values: maximum risk or probable risk in particular).</li>
<li>We may also want it to be faster to achieve (or at least to be carried out in an acceptable time), in order to be able to completely replace the qualitative estimate in the long-term. We are here talking about the time it would take to implement the analysis, without worrying a lot about the time it would take for computations (which can now be efficiently delegated, especially via the cloud). In the end, correlating this with the previous point, it is only question of having a better efficiency than the qualitative evaluation.</li>
<li>Furthermore, we wish the quantitative assessment to be based on concrete data, in order to gain credibility in the results that will be produced. Indeed, since the workflow of a quantitative method is based on mathematical theories, only an incorrect implementation could introduce subjectivity into the values obtained. This last point would justify that in a time equivalent to qualitative analysis, we have finer results.</li>
<li>Finally, and this stems from the previous point, we need to have a precise taxonomy, for the collected data to be clearly defined (regardless of the kind of risk). Indeed, if the quantitative estimate is based on proven mathematical theories, the quality of the data produced will then depend only on the quality of the data used as input, and in particular on the relevance and the consistency of the data, depending largely on its definition..</li>
</ul>
<p>&nbsp;</p>
<h2>At the core of the galaxy: moving from theory to practice</h2>
<p>Having specified what are the characteristics of quantification, let us now see what mathematical theories would take into account the hazard associated with a risk.</p>
<p>Consider, for example, the fuzzy sets theory. This mathematical theory is based on the principle that an element, instead of classically belonging or not to a mathematical ensemble, may only partially belong to it, according to a stated degree. This could be useful to highlight the occurrence or the impact of a risk with the degree of belonging of that risk to ensembles. This theory, while interesting, has not led to concrete applications.</p>
<p>Another approach, which could be called correlative, would be based on the use of self-learning neural networks, to determine from CTI data what the level of risk of a company would be, according to its characteristics. This theory has benefited from the current popularity for artificial intelligence. This led to academics’ studies comparing different modes of machine learning (notably BP<a href="#_ftn2" name="_ftnref2">[2]</a> or RBF)<a href="#_ftn3" name="_ftnref3">[3]</a>, in order to be used in cyber risk analysis. However, to date, it does not appear mature enough to lead to a realistic method.</p>
<p>Finally, the only mathematical solution that has paid off has been the statistical analysis (and game theory, which offers the means to combine statistical distributions, see the &#8220;Risk Quantification and Data: Advice and Tools&#8221;<a href="#_ftn4" name="_ftnref4">[4]</a> article about this subject). The principle of statistical analysis is to rely on statistical observations to estimate the level of a risk. The hazard of risk is then, in large part, taken into account by the distribution of the statistics.</p>
<p>Based on these statistics, two approaches are practicable:</p>
<ul>
<li>The first is illustrated by a method proposed by the IMF<a href="#_ftn5" name="_ftnref5">[5]</a>. It proposes to assess a cyber risk by a detailed statistical analysis. However, it is highly computational and inaccessible for regular use or as a part of a quantified risk estimate. However, it retains an undoubted interest in an analysis of a level of cyber risk on several entities that would have similar data, which may be useful for an insurer or in the banking community. However, it remains confined to this use. Reduced to the already limited scope of entities with acceptable cyber maturity, this method does not seem to be able to offer in the short or medium term an exploitable solution for the IS level of an organization.</li>
<li>The second is to break down any cyber risk based on common characteristics. This is in particular the approach of the FAIR methodology: it proposes in its taxonomy (see &#8216;how to apply the FAIR method’1) a dissociation of risk according to its occurrence and the estimated impact, from a financial point of view. FAIR then proposes a declination of these two parameters which, because of their universal nature, may therefore be applied to any cyber risk. This type of method has the advantage of proposing an identical process for the analysis of any cyber risk, facilitating its use in an organizational context (that can then compare cyber risks of distinct natures).</li>
</ul>
<p>&nbsp;</p>
<figure id="post-14758 media-14758" class="align-none">
<figure id="post-14760 media-14760" class="align-none"><img decoding="async" class="aligncenter wp-image-14760 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/10/Image3-1.png" alt="" width="1865" height="593" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/10/Image3-1.png 1865w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/10/Image3-1-437x139.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/10/Image3-1-71x23.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/10/Image3-1-768x244.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/10/Image3-1-1536x488.png 1536w" sizes="(max-width: 1865px) 100vw, 1865px" /></figure>
</figure>
<p style="text-align: center;">The galaxy of quantification</p>
<p>&nbsp;</p>
<h2>The FAIR method: a supermassive black hole</h2>
<p>Currently, only the FAIR method has risen to applicated quantification solutions for a company. Its monopoly in the field is such that it has become an inescapable reference for a solution or methodology to remain credible. Like a black hole, it attracts to it all the current solutions of quantification. We can, for example, illustrate this with the Risquant Library, developed by Netflix&#8217;s R&amp;D department<a href="#_ftn6" name="_ftnref6">[6]</a>. This one clearly announces that it relies on the FAIR methodology. Nevertheless, he takes great freedom in the interpretation of taxonomy and analysis, but the fact of quoting it allows him to be more easily accepted and recognized.</p>
<p>This hegemony of FAIR can be explained quite easily:</p>
<ul>
<li>To begin with, it&#8217;s a pragmatic method by design. Its inventor, Jack Jones, set it up when he was an RSSI of a large American group, and was asked to justify cyber ROI. It was therefore initiated for operational purposes, then refined and gained credibility by relying on mathematical tools and theories. This concept of development  (i.e.  the fact that the method was born out of a need, and then mathematically justified) makes of FAIR a method particularly appreciated by the first concerned, that are the CISO and the other cyber-risk managers.</li>
<li>Then, it was particularly visionary, as she preceded all other methods. Appeared in 2001, the first book about the method was published in 2006, detailing its operation and taxonomy. As time went on, a community was made up around Jack Jones and his method: the FAIR Institute. This community continued the maturation and thz diffusion of the method. More precisely, it helped developing the efficiency of the method by placing facilitators to make it ever usable.</li>
<li>The FAIR method also has a particularly solid basis: in addition to the publication mentioned above and which was the subject of an enriched reissue in 2016, it is based on two  standardization documents, published by the OpenGroup (the consortium behind the architecture standard of SI TOGAF). The OpenGroup also offers certification to the method, based on its two standards, and which add to the interest laying on the method.</li>
<li>Finally, FAIR is strongly supported (particularly across the Atlantic): the community that drives it is particularly active, and contributes as much to its evolution as to its promotion: the links between the OpenFAIR and the FAIR Institute, both mentioned above, are substantially close. The strength of his ties is ensured by the fact that Jack Jones, father of the method, plays a central role in both organizations.</li>
</ul>
<p>Thus, in the world of cyber-risk quantification, the only operational solutions to date all rely on the FAIR methodology, with a more or less large but still displayed parentage.</p>
<p>If the maturity of this method seems now acquired, its monopoly in the field of quantification allows with little doubt to envisage, at least for next years, that it will remain the only method of quantification. In order for another method to be equal, and in addition to the fact that it will have to establish its conceptual credibility, it will above all have to make a place for itself  alongside the hegemony of FAIR, while proving that it is more efficient.</p>
<p>&nbsp;</p>
<p><a href="#_ftnref1" name="_ftn1">[1]</a> <a href="https://www.riskinsight-wavestone.com/en/2020/06/la-quantification-du-risque-cybersecurite/">https://www.riskinsight-wavestone.com/2020/06/la-quantification-du-risque-cybersecurite/</a></p>
<p><a href="#_ftnref2" name="_ftn2">[2]</a> Back-propagation</p>
<p><a href="#_ftnref3" name="_ftn3">[3]</a> Radial basis functions</p>
<p><a href="#_ftnref4" name="_ftn4">[4]</a> See the 2nd article on Risk Insight</p>
<p><a href="#_ftnref5" name="_ftn5">[5]</a> <a href="https://www.imf.org/en/Publications/WP/Issues/2018/06/22/Cyber-Risk-for-the-Financial-Sector-A-Framework-for-Quantitative-Assessment-45924">https://www.imf.org/en/Publications/WP/Issues/2018/06/22/Cyber-Risk-for-the-Financial-Sector-A-Framework-for-Quantitative-Assessment-45924</a></p>
<p><a href="#_ftnref6" name="_ftn6">[6]</a> <a href="https://netflixtechblog.com/open-sourcing-riskquant-a-library-for-quantifying-risk-6720cc1e4968">https://netflixtechblog.com/open-sourcing-riskquant-a-library-for-quantifying-risk-6720cc1e4968</a></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/11/quantified-risk-assessment-1-2-a-quantification-odyssey/">Quantified Risk Assessment (1/2): A Quantification Odyssey</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>How to effectively evaluate your cybersecurity</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/06/how-to-effectively-evaluate-your-cybersecurity/</link>
		
		<dc:creator><![CDATA[Anthony GUIEU]]></dc:creator>
		<pubDate>Tue, 30 Jun 2020 13:00:04 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Analyze]]></category>
		<category><![CDATA[How-to]]></category>
		<category><![CDATA[ISO27k]]></category>
		<category><![CDATA[Level]]></category>
		<category><![CDATA[Maturity]]></category>
		<category><![CDATA[REX]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[Roadmap]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=13312</guid>

					<description><![CDATA[<p>Security managers often bring us in to evaluate their cybersecurity maturity level. We help firms analyze the return on investment for cybersecurity, properly allocating the budget, comparing level of security to that of others in similar sectors or common standards,...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/06/how-to-effectively-evaluate-your-cybersecurity/">How to effectively evaluate your cybersecurity</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Security managers often bring us in to <strong>evaluate their cybersecurity maturity level</strong>. We help firms analyze the return on investment for cybersecurity, properly allocating the budget, comparing level of security to that of others in similar sectors or common standards, and measure exposure to recent attacks.</p>
<p>But these projects are not only the work of systems security managers. These projects also come from executive committees who seek a<strong> 360 view of the security of their institution</strong> to better evaluate potential risk. So, what are key success factors that we have seen in the field?</p>
<p>&nbsp;</p>
<h2>Step 1: Know the purpose and expectations of your evaluation</h2>
<p>Evaluations can be entirely different <strong>levels of depth</strong>. From a high-level interview with the Chief Security officer to an in-depth assessment of the security mechanisms and processes of all the subsidiaries of a multinational group, everyone can choose their areas of focus and advance step-by-step.</p>
<p>Our first advice is to <strong>keep in mind the objectives of your evaluation</strong>. This will allow you to orient yourself toward the right security benchmarks and ultimately define the depth of the evaluation. Do you only want to measure the security maturity of your subsidiary’s information systems or also its efficiency? Perfectly documented security processes and an ISO 27001 certification can unfortunately hide problems on the ground that can expose you to vulnerabilities. It can be judicious to combine a technical test (pentest, red team, etc.) to the evaluation in order to <strong>avoid situations that seem fine on the surface but hide underlying issues</strong>.</p>
<p>&nbsp;</p>
<h2>Step 2: Find and mobilize the right people at the right level, easy to say but harder to do…</h2>
<p>The next difficulty that you can encounter in your assessment is to succeed at meeting the right people. From experience, we advise you to confirm your list of the necessary collaborators as soon as possible.</p>
<p>Logically, this list will certainly depend on the granularity of the analysis but also on the organization of the business. For example, the necessary people will differ if the security staff are at the group level and function as a service center or if they are merged into each entity and service. Consequently, if you want to have a high-level estimate first, it could suffice to only have a half day exchange with the Chief Security Officer, who generally has a sufficient and global vision of the subject.</p>
<p>The second stage of analysis can be performed in gathering information from all actors involved in cybersecurity at the group level. In this group, it can be interesting to meet a large group of people involved in information systems and the cloud.</p>
<p>Finally, when the assessment must be thorough and exhaustive, it becomes necessary to widen the list of collaborators to all of the concerned entities. Obviously, you should expect a larger workload, so do not skimp on preparation and tools to help you in your work. It can also be the right moment to think about your presentation format: face-to-face, distance, strategic, operational, etc.</p>
<p>&nbsp;</p>
<h2>Step 3: Equipment, finding the right balance between too much and not enough</h2>
<p>Choosing the right tools is one of the main assessment challenges that you will face. The more complete the assessment, the more it will require tools that ensure simplification and understanding of the whole project. Indeed, for large evaluations, the <strong>consolidation and restitution of results are two of the great challenges that you will encounter</strong>. In particular, commonly used tools don’t take into account the organizational complexity of large groups or the effectiveness of allocated resources. It is for these reasons that, from our side, we have chosen to develop a specific tool.</p>
<p>A good tool also allows you to position yourself against your competitors and understand your exposure to current attack trends and points where your COMEX is particularly sensitive, ensuring you can legitimize the assessment.</p>
<p>So it begins! It’s time to get your hands dirty and start the work of collecting information! There is a classic phrase that applies to these situations: entirely feasible from a distance. Be aware and transparent about the limits of the exercise: those questioned will sometimes have the impression that the assessment is too theoretical and this is normal, according to their objectives. During this phase, it will also be necessary to be able to juggle between the various unknowns because it is not uncommon to have people who are ultimately absent for long periods of time, added parameters, changes in methodology. Make it a point of honor to remain agile.</p>
<p>&nbsp;</p>
<h2>Step 4: Reforming at the right level to act, everything is a question of the point of view</h2>
<p>A good habit to keep is to honestly adapt each reform to each person. From the managerial summaries where we talk about trends without much detail to presentations for technical teams that are highly detailed, adapting the discourse to the necessary format is important to convey the right messages to the right people.</p>
<p>Usually, we start the reforms in terms of the organization’s budget and workforce dedicated to cybersecurity. These very concrete points allow you to attract attention and be able to then analyze the situation from four different angles:<br />
· Compliance with different global benchmarks (ISO/NIST)<br />
· Assessment of the level of maturity of different entities compared to others in the same sector or market<br />
· Quantification of the effort reach the market level and/or the required level according to cybersecurity benchmarks<br />
· Evaluation of the level of robustness of the organization against the last known cyberattacks</p>
<p>With senior management, the restitution is often going to focus on organizational and governance matters. However, there can always be surprises. In cases where businesses have already been hit by serious cyber attacks, we have had surprisingly precise and technical questions from executive committees. For example, we have been asked for details on encryption algorithms and “How secure is my active directory?”</p>
<p>&nbsp;</p>
<h2>Get started</h2>
<p>As mentioned earlier, the maturity assessment is an effective means for <strong>measuring the effectiveness and progress of your cybersecurity roadmap</strong>. Consequently, even if you don’t want to immediately begin an assessment involving all security systems and dozens of teams at your business, <strong>we advise you to familiarize yourself with the approach</strong> and its usefulness in starting out with more modest goals.</p>
<p>At Wavestone, with years of experience and expertise, we have developed the <strong>W-Cyber-Benchmark</strong>, a multi-use tool that has been implemented by dozens of clients. We know that just writing about it isn’t enough, <a href="https://www.wavestone.com/en/contact/">so don’t hesitate to contact us to discuss further</a>!</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/06/how-to-effectively-evaluate-your-cybersecurity/">How to effectively evaluate your cybersecurity</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
