introduction to the language of risk

23
The Language of Risk Translating between Business and Security

Upload: brandon-dunlap

Post on 25-Dec-2014

461 views

Category:

Business


1 download

DESCRIPTION

This is the opening introduction slides from the (ISC)2 2010 Security Leadership Series on Competitive Compliance as well as the Language of Risk.

TRANSCRIPT

Page 1: Introduction To The Language Of Risk

The Language of Risk

Translating between Business and

Security

Page 2: Introduction To The Language Of Risk
Page 3: Introduction To The Language Of Risk

The potential harm that may arise from a future event.

Page 4: Introduction To The Language Of Risk

The Value of Risk Management

“More than any other development, the quantification

of risk defines the boundary between modern times and the

rest of history.”

Peter L. Bernstein, Harvard Business Review, Mar.-Apr. 1996, p. 57-51.

Page 5: Introduction To The Language Of Risk

Risk Management is Bigger Than Fire

Page 6: Introduction To The Language Of Risk

Basic Games of Chance

Renaissance Studies on Probability

The Birth of Insurance

Evolution of Risk Management

Early dice made from sheep bones

Galileo publishes "Sopra le Scoperte“ in 1630

Lloyd’s of London circa 1774

Page 7: Introduction To The Language Of Risk

Measuring Risk is Hard

We’ve reduced this…

…to this. (ARO)(SLE)=ALE

Page 8: Introduction To The Language Of Risk

You Cannot Predict Misfortune• You do not know what

the Average Rate of Occurrence is.

• Your best hope is to pull a plausible average out of the air

Page 9: Introduction To The Language Of Risk

Guessing Doesn’t Count

•You do not know the Single Loss Expectancy•You can only estimate the impact

Page 10: Introduction To The Language Of Risk

Communicating Risk Is Harder

Page 11: Introduction To The Language Of Risk

Education Is The Missing Piece

Finding a Common Language is Key

Page 12: Introduction To The Language Of Risk

risks you faceeverydaywhat are the

Page 13: Introduction To The Language Of Risk
Page 14: Introduction To The Language Of Risk

malicious outsiders?

Page 15: Introduction To The Language Of Risk

malicious insiders?

Page 16: Introduction To The Language Of Risk
Page 17: Introduction To The Language Of Risk

Whatdo youworryabout

Page 18: Introduction To The Language Of Risk

Moreimportantly…

Page 19: Introduction To The Language Of Risk

businessWhat does your

worry about

Page 20: Introduction To The Language Of Risk
Page 21: Introduction To The Language Of Risk

businessHow does a

doing wellknow it is

Page 22: Introduction To The Language Of Risk
Page 23: Introduction To The Language Of Risk

Brandon DunlapManaging Director of Research

[email protected]: bsdunlap

Brightfly, Inc.www.brightfly.com

Twitter: brightfly

Questions?