iv Table of Contents
Chapter 2: Survey of Security Risk Management Practices ........................... 13
Comparing Approaches to Risk Management .................................................. 13
The Reactive Approach ......................................................................... 13
The Proactive Approach ........................................................................ 15
Approaches to Risk Prioritization .................................................................. 16
Quantitative Risk Assessment ................................................................ 16
Details of the Quantitative Approach ................................................. 17
Qualitative Risk Assessment .................................................................. 19
Comparing the Two Approaches ............................................................. 20
The Microsoft Security Risk Management Process ........................................... 21
Chapter 3: Security Risk Management Overview ........................................... 23
The Four Phases of the Microsoft Security Risk Management Process ................. 23
Level of Effort ................................................................................ 25
Laying the Foundation for the Microsoft Security Risk Management
Process ......................................................................................... 25
Risk Management vs. Risk Assessment .................................................... 25
Communicating Risk ............................................................................. 26
Determining Your Organization's Risk Management Maturity Level ............... 28
Organizational Risk Management Maturity Level Self Assessment ........... 30
Defining Roles and Responsibilities ......................................................... 31
Building the Security Risk Management Team ..................................... 33
Summary ................................................................................................. 34
Chapter 4: Assessing Risk ............................................................................. 35
Overview .................................................................................................. 35
Required Inputs for the Assessing Risk Phase ........................................... 36
Participants in the Assessing Risk Phase .................................................. 37
Tools Provided for the Assessing Risk Phase ............................................. 37
Required Output for the Assessing Risk Phase .......................................... 38
Planning ................................................................................................... 38
Alignment ........................................................................................... 38
Scoping .............................................................................................. 38
Stakeholder Acceptance ........................................................................ 39
Preparing for Success: Setting Expectations ............................................. 39
Embracing Subjectivity ......................................................................... 39
Facilitated Data Gathering .......................................................................... 40
Data Gathering Keys to Success ............................................................. 40
Building Support ............................................................................. 41
Discussing vs. Interrogating ............................................................. 41