Introduction to Risk Assessment

Sdílet
Vložit
  • čas přidán 12. 12. 2010
  • Info
    Level: Beginner
    Presenter: Eli the Computer Guy
    Date Created: October 12, 2010
    Length of Class: 57 Minutes
    Tracks
    Computer Security /Integrity
    Prerequisites
    None
    Purpose of Class
    This class teaches students the basic concepts behind Risk Assessments.
    Topics Covered
    Defining Risk, Threat and Vulnerability
    Types of Protections
    Mitigation Concepts
    Business Rational for Risk Assessment and Management
    Class Notes
    Introduction
    The better you know technology the better you will do with Risk Assessment/ Management.
    Risk
    Risk = Treat x Vulnerability
    Overview of Risk
    Risk is defined as the likelihood of financial loss.
    Risk is a business concepts not a technological one.
    Down Time
    Fraud
    Legal data loss issues
    Hacking -- Attacks from your network
    Data Theft (Trade Secrets)
    Overview of Threat
    i. Natural Disatser
    ii. Malicious Human
    iii. Accidental Human
    iv. System Failure
    Impersonation
    Interception
    Interference
    Overview of Vulnerability
    Flooding
    Theft of Systems
    Hacking
    Viruses
    Overview of Protections Technoloigical Safe Guards
    Physical/ Operational Security
    Disaster Plan
    Documentation
    Technological Safeguards (Firewalls, Antivirus)
    Concepts of Mitigation
    Incident - Response - Debrief - Mitigation
    Making Bad not so bad
    You will never be safe
    Security Buy In and Quantifying Risk
    The business leaders will make the final decision on Risk Management
    The better your BUSINESS argument the more likely you are to get the go ahead.
    What is the cost of downtime
    What is the legal cost
    Cost of Security vs. Benefit
    Final Thoughts
    Risk is a BUSINESS concept! The more you understand about business and can talk about financial ramifications the more likely you are to get you fancy new security equipment.
    Resources
    US Computer Emergency Readiness Team
  • Věda a technologie

Komentáře • 107

  • @rulk9129
    @rulk9129 Před 7 lety +39

    Is there some risk associated with right side audio?

  • @MegaSam05
    @MegaSam05 Před 12 lety +1

    Beacuse of Some Intelligent Guys Like you we pepole are able to get trained. I thanks a lot for this excellent explanatory presentation.

  • @wyattculberson1943
    @wyattculberson1943 Před 8 lety +1

    Good introductory presentation. The key concept is being able to present the risk with a $$ estimate so the business can make a business decision.

  • @InstTaxSolutionsLLC
    @InstTaxSolutionsLLC Před 11 lety +1

    Great presentation on risk assessment. When risk assessment is done properly it allows businesses and individuals to plan ahead and develop contingency plans that are ready to be implemented should certain events occur. This not only makes the process more efficient, it also reduces some of the stress that can occur when something unexpected happens.

  • @Limitless1717
    @Limitless1717 Před 11 lety

    Thank you very much for sharing Eli. A customer has asked me to do a risk assessment, and I know (at least) have a starting point. Great job!

  • @subhodhambali
    @subhodhambali Před 12 lety +4

    Extremely good presentation & information. Thank you :)

  • @jayzeraquino8667
    @jayzeraquino8667 Před 3 lety

    You are a blessing.... thank you for your practical way of presenting the Risk Assessment for Infosec matters...

  • @bigweirdo9947
    @bigweirdo9947 Před 9 lety +3

    "...to...to...to... the ghetoooooo"
    LOL I love nerds.

  • @MktNinja
    @MktNinja Před 9 lety +2

    Hey Eli, Thx for vid. Do you know if there's a software or a tool for Risk Assessment?

  • @lakhanialhijab
    @lakhanialhijab Před 12 lety +1

    well explained, i got a CCA (chartered accountacy) advanced audit and assurance exam in 2 weeks time, this did help me get a wider understanding of the underlying concepts of risk and i can relate these to the syllabus area of business risk.
    Regards & Thank You.

  • @hiphoponeworld
    @hiphoponeworld Před 12 lety

    @Svinqvai You know CZcams has this feature where you can fast forward in videos?

  • @TheBoudiay
    @TheBoudiay Před 12 lety

    Clearly this guy knows is Job. Love from Africa (Mali)

  • @makeitsimpleyo
    @makeitsimpleyo Před 10 lety +1

    Excellent teacher.

  • @nicholashughes8214
    @nicholashughes8214 Před 10 lety +2

    Great Presentation!

  • @DaBBoSaH
    @DaBBoSaH Před 10 lety

    wow!! You are fantastic, I already know many of these, but listening to you was such a pleasure :D .. fantastic well done

  • @sambitsarkar6987
    @sambitsarkar6987 Před 10 lety

    U rock bro!!!!!!! THANKS TO U, learning became fun and easy.

  • @johnathanhunt6440
    @johnathanhunt6440 Před 10 lety +7

    Bro, not gonna lie, this was awesome. you are now my idol! Few things though, risk 101...risk is never 0. Also you cracked me up with definition of HIPAA. I also liked "because Linksys dies....a lot"

    • @brownj0002
      @brownj0002 Před 8 lety +1

      Risk of volcano in Florida = 0
      Risk of (natural) fire in Arctic = 0
      Risk of tsunami in Colorado = 0
      Risk of (natural) flood damage 500 feet above ground water level = 0
      Risk of Computer failure if you have no computers, risk = 0
      Risk of employee fraud, if you have zero employees = 0
      Etc.
      You can argue:
      … risk is 0.000000000000000000000000000001
      … or that a volcano will not pop up in Florida, but it will in Iceland and impact Florida indirectly, etc.
      I think the point was it’s a relative comparison of probability and at some point some situations do not appear on your radar at all- it depends on LOCAL conditions which do vary.
      It took some thought to find those scenarios, thanks for the thought exercise. Fun.

    • @abdollahabdi4900
      @abdollahabdi4900 Před 5 lety

      @@brownj0002 These are not risk then. There is no risk with the probability of occurrence equal to zero. It would become a fact not a risk.

  • @oscarmanuelguarinfigueroa1808

    thanks Eli,,,very important things you´ve tryied...so, if you can talk us about one Risk Analysis Methodology like CRAMM or OCTAVE or NIST it will be very interest and complementary and we´ll appreciate of that.....and you´re a good teacher, i would say knowledge consultant of Information Security.....and believe me,,i have been in a many bored webminars....

  • @irispep
    @irispep Před 5 lety

    Thank you for sharing this with us. You are awesome.

  • @karmakarnestein4009
    @karmakarnestein4009 Před 11 lety

    Hi Ely! Thanks so much for all these preciuos info. Could u reccommand me the best e possibly the esiest to manage free firewall software to run on Windows seven,inted of the integrated one? I use Zone alarm right now, is pretty good but in my opinio has many suff that runs in background and it's not so simple to configure.

  • @dicktongtong
    @dicktongtong Před 11 lety

    Very good and thanks! I will see more from Eli.

  • @daNeterAUsaru999
    @daNeterAUsaru999 Před 12 lety

    Hey Eli do you have any tutorials that covers continuous monitoring?

  • @mahbubislam4179
    @mahbubislam4179 Před 8 lety

    I really like this discussion . Now I am understand about risk. :)

  • @sisirakosgoda7700
    @sisirakosgoda7700 Před 10 lety

    Nice lecture after long time, it is like a University lecture.

  • @marthacatra1322
    @marthacatra1322 Před 3 lety

    I love your explanation, its clear and sound

  • @ForteanOrg
    @ForteanOrg Před 11 lety +1

    The formula 'Risk = threat x vulnerability' is new to me. Risk is indeed sometimes defined in quasi-mathematical wordings, the one best known to me is 'Risk = likelihood (of an event) x impact (of the event)'. Such events could be seen as actors on vulnerabilities of assets and are known as security incidents. . I'm very happy, however, that you do point out that these 'formulae' are actually not real formulae - after all, what are the units of measurement for threats and vulnerabilities..?

  • @TheBebe4ever
    @TheBebe4ever Před 8 lety

    HI Eli, thanks much indeed , you are really professional and i like your way of coaching. just wandering do you have any thing related to CRISC. Thanks alot

  • @Susannnnnn
    @Susannnnnn Před 9 lety

    great stuff, thank you.

  • @googo34
    @googo34 Před 6 lety

    And yet again I search for some random string on youtube and.... when I see Eli, I watch his video(s)!

  • @BriWells426
    @BriWells426 Před 5 lety +1

    Yeah linksys sucks. I’m about to do a risk methodology powerpoint and I was pleasantly surprised that you have a video on this bc I’m subscribed to you and you’re my savior In networking lol

  • @elithecomputerguy
    @elithecomputerguy  Před 11 lety +4

    On vacation ;)

  • @theindianguy3148
    @theindianguy3148 Před 5 lety

    Thanks Eli..It was really good...Pls post more videos on Risk Assessment and how to initiate audit for any system or organisation?

  • @Qibilii
    @Qibilii Před 12 lety

    Great tutorial design!

  • @maddox4747
    @maddox4747 Před 10 lety +40

    Ugh... please fix so that both my ears can hear this, and not just my left.

    • @gopaltsg
      @gopaltsg Před 4 lety +1

      It's only on left 👂

  • @brandonfarfan1978
    @brandonfarfan1978 Před 5 lety

    Nice lesson. It is very informative.

  • @hopemariemcfadden4900
    @hopemariemcfadden4900 Před 2 lety

    This video was informative & entertaining. Bravo!

  • @shingyau2
    @shingyau2 Před 9 lety

    You are excellent!!!

  • @ChecksSuperstore
    @ChecksSuperstore Před 11 lety

    Great presentation!

  • @ssambadenis9401
    @ssambadenis9401 Před 2 lety

    straight on point.. Thanks

  • @reeyakarki4588
    @reeyakarki4588 Před 3 lety

    Great presentation 😍
    Do you offer classes too? If so I am willing to take with you. Trying to take computer system validation course.

  • @mashakulatunga5553
    @mashakulatunga5553 Před 4 lety

    very helpful .. thank you very much!

  • @zmorrell1562
    @zmorrell1562 Před 10 měsíci

    Is it just me or does the audio only output through the left earpiece on a headset?

  • @kennySg101
    @kennySg101 Před 7 lety

    Good intro. More pragmatic approach.

  • @cybersaintify
    @cybersaintify Před 12 lety

    Awesome tutorial :)

  • @mediacoregroupph
    @mediacoregroupph Před 9 lety

    event - what to do - how to do it - act - event : is this the same as Eli's explaination?

  • @kbadwi
    @kbadwi Před 11 lety

    good job and well done, I like it a lot.

  • @z3jlewhhda376
    @z3jlewhhda376 Před 10 měsíci

    It's 2023 and still I found this perfect presentation on CZcams

  • @triforcelink
    @triforcelink Před 12 lety

    This is good information, where did you learn it all?

  • @mm0c12951
    @mm0c12951 Před 12 lety

    thanks for the upload.

  • @Danieled91
    @Danieled91 Před 4 lety +1

    2020, I discovered this only now.

  • @Accenn7
    @Accenn7 Před 2 lety

    Hello Eli I received a request to put in place a data center ….it been several years that I am watching your videos ..I think you might be able to help putting this in place.
    Please let me know if you can be on board on this.
    Thanks.

  • @anshumankak
    @anshumankak Před 10 lety

    best tutorial....

  • @mekabay
    @mekabay Před 11 lety

    Excellent video! Thanks. Minor error: HIPAA = Health Insurance Portability and Accountability Act. M. E. Kabay, PhD, CISSP-ISSMP / Prof Comp Info Sys / Norwich University

  • @mokar0873
    @mokar0873 Před 11 lety

    Tres bien, Merci

  • @trivenisatyanarayana877
    @trivenisatyanarayana877 Před 10 lety

    this guy looks and speaks cool!
    generally i am using "risks" iPhone app by hanumappa to manage all my risks

  • @silentlips8871
    @silentlips8871 Před 7 lety

    good topic v informatic

  • @Fineghang8768
    @Fineghang8768 Před 3 lety

    very easy to understand

  • @earlejones
    @earlejones Před 10 lety +1

    Eli: Good stuff!
    Don't say "ek cetera" - say "et cetera."

  • @abubakarmtom8505
    @abubakarmtom8505 Před 7 lety

    Thank you sir

  • @digbyte
    @digbyte Před 10 lety

    I think about risk differently. Risk = a dangerous or harmful scenario. i.e. driving the highway with your eyes closed is dangerous (Risky). Risk isn't the likelihood of loss. Risk Assessment is estimating the likelihood of loss… i.e. assessing X scenario occurring over Y scenario and providing rationale and recommendations to minimise the danger / harm or stop X from happening.

  • @_first_touch_
    @_first_touch_ Před 6 lety

    My left ear liked the video!

  • @Starius2
    @Starius2 Před 11 lety

    Love it

  • @bassambusiness8990
    @bassambusiness8990 Před 9 lety

    Thanks

  • @igotmail9
    @igotmail9 Před 13 lety

    Good examples

  • @ryanm4769
    @ryanm4769 Před 3 lety +1

    My left ear enjoyed this presentation lol

  • @williamwellborn9200
    @williamwellborn9200 Před 9 lety

    Awesome

  • @digbyte
    @digbyte Před 10 lety

    threat discussion is basically 'Business Continuity Planning'. And there's a whole suite of thinking in this space: en.wikipedia.org/wiki/Business_continuity_planning

  • @mikethompson3635
    @mikethompson3635 Před 9 lety

    Just cannot hear anything. Normally have no trouble with CZcams

  • @TheStevenWhiting
    @TheStevenWhiting Před 11 lety

    Not with cross shredding. But yeah, burning is better but not great for the environment.

  • @sam111880
    @sam111880 Před 11 lety

    there is no such thing as zero risk amazon servers could fail :) though risk relative to your environment I agree

  • @mmughal
    @mmughal Před 8 lety +1

    why one channel!

  • @Fevah5
    @Fevah5 Před 5 lety

    Excellent at normal speed, Phenomenal at 1.25x

  • @techiegz
    @techiegz Před 4 lety

    HIPAA = Health Insurance Portability & Accountability Act

  • @Adam-vo6cr
    @Adam-vo6cr Před 10 lety +1

    LOL ALL THE TIME! Who is your ISP? Who is your phone provider? Who is blah blah blah, BLAAAAANNKKKK STARES...

  • @oussamagharbi5419
    @oussamagharbi5419 Před 5 lety +1

    this video made me think that i ruined my earphone again

  • @indrajeetmahajan4691
    @indrajeetmahajan4691 Před 5 lety +3

    my right ear feels lonely

  • @baglover917
    @baglover917 Před 5 lety

    I liked your video but not the part about the boss moving his desk next to the assistant then risk of info being comprimised is high. Not all assistants are the same. They are ppl and the integrity of an assistant and any other worker is based on the person and their morals so using an assistant as an example is not a good one. Otherwise, good video 👍 at least you don’t have a heavy Chinese accent like my professor who I can barely understand 😩😩

  • @eligraham55
    @eligraham55 Před 11 lety

    Great risky presentation (see what I did there?) :)

  • @planck10-43
    @planck10-43 Před 4 lety

    "Linksys stuff dies .. a lot.."

  • @loubino18
    @loubino18 Před 8 lety +2

    can barely hear even with headphone.

    • @dr.wazihahmad786
      @dr.wazihahmad786 Před 8 lety +11

      +loubino18 change your ears or headphone

    • @brad4058
      @brad4058 Před 7 lety +1

      Volume is good. Your headphones sucks.

  • @BigJyeTV
    @BigJyeTV Před 11 lety

    I know right? People always complain about FREE stuff...smh

  • @KennethHawkinsMyBos
    @KennethHawkinsMyBos Před 6 lety

    $$$

  • @ljiljanaprimorac1740
    @ljiljanaprimorac1740 Před 7 lety

    yyy

  • @heho5936
    @heho5936 Před 4 lety

    Cant take it the whole 57minutes with just the left ear.

  • @digbyte
    @digbyte Před 10 lety

    You mention malicious activity…your talking about the principles of information security: confidentiality, integrity, availability. Hackers look to get the information, change the information or make it unavailable.

  • @arturpojo
    @arturpojo Před 6 lety

    please .. both ears!! :((

  • @Svinqvai
    @Svinqvai Před 12 lety

    too long.....he can make a long story shorter can't wait an hour to see if he will tell the thing I'm interested in

  • @faheemahsan672
    @faheemahsan672 Před 4 lety

    Linksys stuff dies haha.

  • @Shermanre1
    @Shermanre1 Před 4 lety

    That's not what HIPAA stands for...lol!

  • @horizon2814
    @horizon2814 Před 3 lety +1

    dog water my guy

  • @victorqwilleran3331
    @victorqwilleran3331 Před 6 lety

    I love your videos but I hate how you say et cetera.... It's two words and the first one is pronounced eht not ehk.