Risk Assessment and Management

Duration: 23 min

This video lesson is available to enrolled students.

Enroll to watch — UP LT Grade Assistant Teacher 2025 Computer Science Course

AI summary & chapters

AI Summary

An AI-generated summary of this video lecture.

The video lecture provides a detailed examination of "Analysis of Threats and Risks" within the context of Information Security. It begins by establishing that system security must be commensurate with the risk involved. The instructor highlights the three pillars of risk assessment: identifying threats, recognizing vulnerabilities, and calculating probable loss. The lecture then transitions to the sources of threats, distinguishing between external and internal origins, and discusses the historical shift from centralized to dispersed computing infrastructures. A significant portion is dedicated to Risk Analysis, where the instructor outlines key questions regarding natural disasters, financial losses, and recovery times. The session further explores Security Policy, detailing components like authentication, authorization, and integrity, and emphasizing the need for written policies. Finally, the lecture contrasts Quantitative Risk Analysis, which uses numerical formulas, with Qualitative Risk Analysis, which assesses risk based on asset nature and system criticality.

Chapters

  1. 0:00 2:00 00:00-02:00

    The lecture opens with section 12.5.1 "Analysis of Threats and Risks". The text states security must be commensurate with risk. The instructor underlines three key components of threat and risk assessment: "identification of applicable threats", "recognition of vulnerability", and "probable loss calculation". She also underlines "centrally located" regarding historical computer systems. The text explains that historically, management of issues was the responsibility of computer center staff. The instructor emphasizes the need to identify the source of threat. The visual focus is on the first paragraph of the document.

  2. 2:00 5:00 02:00-05:00

    The discussion shifts to the source of threats, which can be "external or internal". The instructor underlines this phrase. She highlights that historically, viruses were a major external threat, but now unauthorized intruders hacking vital information are a concern. She underlines the phrase "when an unauthorized intruder may try to hack upon organization's vital information and cause damage". The text notes internal threats are common due to employee access, as they know vulnerabilities. The instructor underlines "focus were to make available" in the context of historical staff responsibilities. The visual focus is on the second paragraph and the start of the third.

  3. 5:00 10:00 05:00-10:00

    The topic moves to "Risk Analysis". The instructor writes "Source" and "Security" next to the heading. She underlines "The common questions asked in evaluating the risks are given below." Specific risks like "fire, earthquakes" are underlined. For loss analysis, she writes "Financial loss, Reputation, legal issue" next to the text about suffering from a halt. She underlines "time permissible for recovery of operation". The text asks if the scope of effects has been made clear. The instructor underlines "scope of their effects on the information system". The visual focus is on the bullet points under Risk Analysis.

  4. 10:00 15:00 10:00-15:00

    The lecture covers "Security policy". The instructor underlines "security policy in writing". She lists four issues: Authentication, Authorization, Information integrity, and Detection. Next to Authorization, she writes "Read + Write". She underlines "Performing the Risk Assessment and Determining Vulnerabilities". She writes "Effective Security" and "Select Tools". She underlines "written information security policy", "sound security policy guidelines", and "well-designed system architecture". She also underlines "physical security", "employee education", and "testing". The visual focus is on the Security Policy section.

  5. 15:00 20:00 15:00-20:00

    The focus is on third-party vendors. The instructor underlines "security-related clauses of a written contract" and "data confidentiality, system security, and notification procedures". She underlines "comprehensive analysis of the provider's security program". The text discusses assessing business sensitivity of information, where the instructor writes "Account -> Sensitive". She underlines "Assessing the risks posed by service provider or business partner". She also underlines "Determining legal implications of security breaks". The visual focus is on the text regarding third-party contracts.

  6. 20:00 22:51 20:00-22:51

    The final section covers "Quantitative Risk Analysis" and "Qualitative Risk Analysis". The instructor writes "Numbers" next to Quantitative. She underlines the formula "Estimated Loss = Potential loss due to the event x Probability" and writes an example "1000 x 0.1 = 100%". For Qualitative, she writes "UPB". She underlines "institution's systems, networks, and information assets" and discusses how transactional banking poses greater risks than information-only websites. She underlines "Performing the Risk Assessment and Determining Vulnerabilities" again. The visual focus is on the final sections of the document.

The lecture systematically builds a framework for understanding information security risks. It starts with the fundamental definition of risk assessment, moving through the identification of threat sources and the historical context of system management. The instructor then guides students through the practical application of risk analysis by asking critical questions about disasters, financial impact, and recovery. The session emphasizes the role of security policy in mitigating these risks, detailing specific controls like authentication and authorization. Finally, the distinction between quantitative and qualitative analysis methods is clarified, providing students with both numerical and descriptive tools for evaluating security posture.

Loading lesson…