CMM7XX
NIST Cyber Security Framework
Session 10: Risk Assessment
Learning Objectives
- Differentiate Quantitative vs Qualitative Risk Assessment methodologies.
- Apply the FAIR (Factor Analysis of Information Risk) framework mathematically.
- Deconstruct the five core functions of the NIST Cybersecurity Framework (CSF).
- Evaluate NIST Implementation Tiers and organizational maturity.
- Design target NIST Profiles to align cyber defense with business objectives.
Task 1: Quantitative Risk Modeling
Timing: 45 minutes
A hospital database (AV = £10M due to regulatory fines and lost trust) faces a ransomware threat. If successful, the EF is estimated at 40%. Threat Intel estimates an ARO of 0.25 (once every 4 years).
- Calculate the SLE and the ALE for the current state.
- A vendor proposes an immutable backup solution costing £200,000/year. This solution does not stop the attack (ARO remains 0.25), but reduces the EF to 2%.
- Calculate the new SLE and ALE.
- Calculate the ROI: Does the reduction in ALE justify the £200,000 annual cost? Present your finding as a Board-level summary.
15 Minute Break
Please return promptly for Part 2.
Part 2: The NIST Framework
Duration: 1.5 Hours
NIST Cybersecurity Framework (CSF)
A voluntary framework developed by the US government to help organizations manage cyber risk. It provides a common language for executives and engineers.
The CSF Core consists of five concurrent functions:
- Identify (ID): Develop organizational understanding of assets and risks (Asset Management, Risk Assessment).
- Protect (PR): Develop safeguards to ensure delivery of services (Access Control, Encryption, Training).
NIST CSF Core (Continued)
- Detect (DE): Identify the occurrence of a cybersecurity event (Continuous Monitoring, Anomalies).
- Respond (RS): Take action regarding a detected incident (Response Planning, Containment, Mitigation).
- Recover (RC): Maintain plans for resilience and restore impaired capabilities (Recovery Planning, Communications).
Most organizations over-invest in Protect and heavily under-invest in Detect and Respond.
Implementation Tiers
Measure the organization's approach to cybersecurity risk management.
- Tier 1 (Partial): Reactive. Ad hoc processes. No formalized risk management.
- Tier 2 (Risk Informed): Management approves risk decisions, but processes are not organizational-wide policies.
- Tier 3 (Repeatable): Formal policies in place. Risk management is treated as a corporate-wide requirement.
- Tier 4 (Adaptive): Proactive. Continuous improvement based on predictive indicators and advanced threat hunting.
Introduction to Task 2
A NIST "Profile" is the alignment of the CSF Core to a specific business scenario. You create a "Current Profile" and a "Target Profile" to identify gaps.
We will act as consultants developing a Target Profile for a recently breached organization.
Task 2: NIST Profile Development
Timing: 50 minutes
A regional healthcare provider (Tier 1) suffered a catastrophic ransomware attack because they lacked asset visibility and had no offline backups. They wish to reach Tier 3 within 18 months.
- Focusing only on the Identify and Recover functions, draft a Target Profile summarizing the specific outcomes they must achieve.
- Map at least two specific technical controls (e.g., automated network discovery, tape backups) to your stated outcomes.
- Formulate a high-level 18-month roadmap to bridge the gap between their Current (Tier 1) and Target (Tier 3) profiles.
Summary & Next Steps
- Cybersecurity is fundamentally a risk management discipline. Technical controls exist solely to mitigate quantified business risks.
- Frameworks like NIST provide the structure to communicate complex technical posture to non-technical boards.
Next Week: Security Policy (Formation and Enforcement)