SDLC covers many activities across well defined phases.

Describe concepts for implementing a risk mitigation plan. Cost is an important factor of risk management.

Before we can look at risk we must first know what will be lost if a threat exploits a vulnerability, which will result in a loss to an organization. To do this a risk assessment must be undertaken starting with an asset inventory, followed by a business impact analysis BIA.

The maximum acceptable outage MAO must also be calculated. Service level agreements and operational level agreements must be drawn up. It was signed into law on December 21,and was found to be constitutional by the United States Supreme Court on June 23, Other laws may require other controls 8 Creating a Risk Mitigation Plan Complete a risk assessment Identify costs Perform cost-benefit analysis CBA Implement plan 9 Creating a Risk Mitigation Plan High-level review of risk assessment Identify and evaluate relevant threats Identify and evaluate relevant vulnerabilities Identify and evaluate countermeasures Develop mitigating recommendations 10 Reviewing Risk Assessment Countermeasures In-place countermeasures Planned countermeasures Approved countermeasures Overlapping countermeasures 11 Calculating Costs Initial purchase Facility Installation Training 12 Calculating Costs Look for hidden costs Is extra power required to eliminate a single point of failure?

Reducing the impact of threats to an acceptable level Reducing a vulnerability to an acceptable level Risk assessment RA is a point-in-time assessment 33 Identifying Risk Mitigation and Risk Reduction Elements Account management controls Access controls Physical access Personnel policies Security awareness and training 34 Operational Impact Tradeoff with security: The more secure a system, the harder it is to use The easier it is to use, the less secure it is Firewall implicit deny philosophy 35 Prioritizing Risk Elements 36 Following Up on the Risk Mitigation Plan Ensure countermeasures are implemented POAM Ensure security gaps have been closed.

