01. Materi 3 242
01. Materi 3 242
INFORMASI
Amelia Setiawan
MATERI 3
Risk Assessment
RISK?
Framework: NIST 800-30 ; NIST 800-39
NIST. (2012). NIST Special Publication 800-30 Revision 1 - Guide for Conducting Risk Assessments. In NIST Guide
for Conducting Risk Assessments (Issue September).
■ Threats
■ Vulnerabilities
■ Likelihood
■ Impact
■ Risk
■ Aggregation
■ Uncertainty
Risk Approaches
■ Assessment approaches
■ Analysis approaches
Risk Management Hierarchy
Risk Assessments at the Organizational Tier
■ IS Operations:
– Offsite Storage
– Onsite Storage
■ Information Security:
– Password management
– User Access
■ Change Control Management
Top 10 Application Security Risks Per OWASP
https://www.ox.security/application-security-vulnerabilities/