All you should know about Risk Management
- Date: 03 April, 2021
Cybersecurity is obviously one the hot topic in the industry and Global Knowledge interviewed an expert, Béchir Sebaï, to answer to all our questions about what is Risk Management, its associated jobrole and methods to make a successful implementation of risk management.
GK : Can you explain to us in a few words what this consists of, and how or at what stage the risk management takes place in the "cybersecurity" process?
"The risk-based approach is an essential practice in a process of securing the information system, risk management guarantees the effectiveness of security measures and the adequacy of risk treatment options in order to minimize the impacts, risks and consequences in the event of incidents or cyber attacks."
Risk management for whom?
GK : Is risk management a unique role, dedicated to a single person in the company, or is this role "cumulative"?
"This is a culture to be established within the organization (objectives, methods, resources, skills, etc.).
Even if the company must designate the "Risk Manger", the person in charge of risk management, the activity itself is the responsibility of all stakeholders in the company."
GK : What is jobtitle the best suited to take on this role?
"The first condition for the designation of the "Risk Manager" is that he is involved in the activities and processes concerned by risk management, he must also master the risk management methods as well as the security profession of the information.
The CIO often seems to be best placed for this mission, however the most mature companies have created new functions of "Risk Security Officer" and cyber security risk coordinator under the responsibility of the CIO, whose mission is risk management and IT monitoring."
GK : Are we addressing an ultra technical profile or rather a transversal / project manager?
"The Risk Manager does not have to be an expert in cybersecurity, he must nevertheless have in addition to managerial predispositions, an understanding of the techniques to exchange with the technical experts for the implementation of the security measures that he is supposed to recommend and to follow."
GK : Besides, does a risk manager only intervene in IT?
"Risk Management is a transversal field that concerns all business lines and activities of the company, it must nevertheless focus on the risks related to information security. The operational risk coordinators, for their part, consolidate all the risks of the organization."
GK : Have you noticed or are you observing an evolution of this jobrole?
"In a hyper-connected cyberspace where cyber attacks are increasingly sophisticated, risk management is becoming a central activity in the company.
Managers have become aware of the impact of these risks on the business processes and the activity of the organization and that adequate protection implies the effective management of cybersecurity risk, they are therefore giving themselves more means to control cybersecurity risks."
Risk Management activity needs standard methods
GK : One or more methods are associated with risk management: ISO27005, Ebios, Mehari, are there others?
"Risk assessment methods are used to help the company to automate and then industrialize their risk assessment processes and to prioritize them in order to prepare for their treatment. Moreover, at ACG Cybersecurity we have developed a risk management methodology in accordance with ISO 27005, adapted to the latest Cybersecurity techniques and immersing digital risks."
GK : What are the most widely used methods in the world?
"EBIOS RM and MEHARI being French methods (the first created by ANSSI and the second by Club CLUSIF) they are widely used in France and Europe, they have the advantage of being aligned with the ISO 27005 standard.
Obviously other methods exist, but companies can create or adapt their own risk assessment method."
GK : In what context do we use one more than the other?
"The risk culture as well as that of its management is specific to each organization in its internal and external context.
The criteria that companies take into account when choosing their assessment method are the language of the method, the existence of documentation and software, the cost as well as the comparison tools."
GK : When we talk about an international standard such as ISO27005, does that mean that we have equal and "mandatory" risk management everywhere?
"ISO 27005 is the international reference standard for information security risk management.Other standards and frameworks exist either generic such as ISO 31000, or adapted to other cultures and approaches such as (Risk Management Framework of NIST and ISACA)."
How to become an efficient risk manager ?
GK : Can we exercise as a risk manager without relying on a standard or a method?
"Risk Management must be a structured and methodical activity, the activity must produce reproducible, comparable and efficient results.
Beyond the effectiveness of information security measures, the use of norms, standards and methods allows continuous improvement of Risk Management activities."
GK : Can we take the ISO27005 training without computer security background?
"ISO 27005 training is intended for all audiences and stakeholders, the conduct of risk management projects in the field nevertheless requires project management skills, openness, curiosity and always looking for compromises and arbitration."
GK : Can you give 3-4 essential tips for a successful implementation of risk management?
"Each Risk Manager must adapt its implementation to the context and culture of his company, however certain activities can help to better define the activity:
- Establishment of an information system security watch.
- Generalize awareness of information security risks for employees.
- Periodically review the risks and whenever there is a major change in the company
- Perform rigorous monitoring of risk treatment plans and residual risks.
A big thank-you to Béchir Sebai for his time and detailed answers.