Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Public Data for Risk Management

Public Data for Risk Management

Risk management requires you to estimate that frequency of stuff. Wish you had some data? Come and get it! It's like that Selena Gomez song: "when you're ready come and get it. Na na na na."

Avatar for Kevin Thompson

Kevin Thompson

May 13, 2014
Tweet

More Decks by Kevin Thompson

Other Decks in Technology

Transcript

  1. Public  Data  for  Risk  Management   -­‐  Or  –  

    Pu9ng  the  data  in  Data  Driven   Security  
  2. Agenda   •  Review  risk  management  lifecycle   •  Cool

     pictures  –  manager  like   •  Risk  models  –  nerds  like   •  Powered  by  data   •  Helping  out  
  3. Who  dat?   •  Kevin  Thompson   – Data  Alchemist  at

     Verizon   – Co-­‐author  of  DBIR  (we’ll  see  that  later)   – Fascinated  by  risk   •  Former  board  member  Society  of  InformaPon  Risk   Analysts   •  Member  of  Society  of  Risk  Analysis   – CISSP,  FAIR,  ITIL,  Security+  
  4. Talk  to  me   •  I’m  friendly  and  I’ll  answer

     quesPons   – TwiUer:  @bfist   •  I  love  to  look  at  code  too.    Hit  me  up.   – Github:  blackfist   •  Want  these  slides?   – hUps://speakerdeck.com/blackfist/  
  5. Risk  Management   •  This  is  how  we  decide  to

     allocate  the  scarce   resources  of  our  security  budget.   •  Generally  consists  of  impact,  frequency,  and   controls  at  the  most  basic  level.  
  6. “Risk  is  a  measure  of  adverse  deviaPon  from  the  

    expectaPon,  expressed  at  a  level  of  uncertainty   (probability).”   “A  New  Approach  for  Managing  OperaPon  Risk”  Society  of  Actuaries  2010  
  7. Controversial  statement   •  The  ulPmate  goal  of  risk  management

     is  to   reduce  the  cost  of  uncertain  events  happening   to  an  IT  system  and  to  reduce  the  uncertainty   around  those  costs.  
  8. Risk  Management   •  Impact  of  what  though?  Frequency  of

     what?   •  We  call  that  Risk  IdenPficaPon.   •  I  like  to  describe  loss  scenarios.   •  Later  we’ll  see  why  that  makes  sense.  
  9. Risk  Management   •  Acer  risk  idenPficaPon  we  have  risk

      assessment.   •  How  bad  will  this  hurt  us?   •  Helps  in  prioriPzing  stuff.  
  10. Risk  Management   •  Then  we  have  risk  control  

    •  Actually  pu9ng  stuff  in  place  to  reduce  either   the  impact  or  frequency  of  bad  stuff.    
  11. Risk  Management   •  All  3  phases  are  present  in

     any  org  that  does   not  have  infinite  budget.   •  Lot  of  variaPon  in  the  maturity  of  these   phases  from  org  to  org.  
  12. Our  task   •  Make  it  more  mature.   • 

    Reduce  uncertainty   •  Reduce  cost  
  13. That’s  cool  but  …   •  The  report  gives  you

     a  way  to  sort  the  relaPve   frequency  of  loss  scenarios  
  14. Various  Risk  Models   •  ALE   •  Binary  Risk

     Assessment   •  FAIR   •  NIST  800-­‐30  
  15. All  of  them   •  Try  to  figure  out  which

     threat  scenarios  will   happen  more  ocen.   •  Ocen  Pmes  we  guess   •  That’s  not  all  bad  
  16. Acer  the  guessing   •  A  guess  that  you  write

     down  becomes  a   testable  hypothesis.   •  Now  validate  it  with  informaPon.   •  Use  the  DBIR   •  And  you  could  stop  here  if  you  want  
  17. You  need  some  data   •  Vcdb.org  has  your  data.

      •  Detailed   •  Free   •  Growing   •  Community  
  18. Detailed   •  Every  incident  in  the  data  set  is

     based  on  the   VERIS  framework.   •  Can  be  very  detailed   •  Can  be  very  general  too  
  19. Free   •  All  content  is  CreaPve  Commons  licensed  

    •  No  worrying  that  the  data  will  get  closed  off   and  restricted  down  the  road.   •  Open  source  project,  open  source  data  
  20. That’s  perfect   •  No,  not  quite.   •  Only

     the  detail  found  in  public  reports   •  Not  always  accurate  
  21. But  you  can  make  it  beUer   •  This  is

     a  community  project.   •  There  is  a  lot  of  work  that   needs  to  be  done   •  Go  to  vcdb.org  and   volunteer.  
  22. Help  out   •  Go  to  vcdb.org   •  Click

     on  the  volunteer  link   •  You  might  get  instrucPons  on  how  to   volunteer   •  You  met  get  presented  an  arPcle  and  asked  to   code  it  right  now  
  23. Open  Source  Project   •  Vcdb.org  links  to  github.  

    •  Get  the  firehose.   •  Follow  @verisdb  on  twiUer  
  24. Open  Source  Project   “If  you’ve  ever  wanted  to  contribute

     to  an  open   source  project  but  you’re  not  a  good   programmer  then  this  is  the  project  for  you.”     -­‐-­‐  me  
  25. Y  U  NO  ASK  QUESTIONS?   Kevin  Thompson   TwiUer:

     @bfist   Github:  blackfist   Speakerdeck:  blackfist