Guidelines for conducting a risk assessment

Interview

Guidelines for conducting a risk assessment

What's the best procedure for conducting a risk assessment for an organization such as a drug research and trial company? Should ISO 17799 play a role by default?
A pharmaceutical company has a lot at risk since pretty much all its intellectual property is in the form of electronically stored compounds and trial data, which is very valuable. For instance, consider a blockbuster drug that has the potential to be a multi-billion-dollar business. Clearly the focus of the assessment should be on protecting those kinds of assets.

Once polices are to make sure they adequately set the stage to protect critical assets, it's time to see whether the rubber meets the road by conducting some vulnerability testing. I'm a fan of both electronic testing, as well as human testing. So perform automated scans (to find obvious stuff) and use penetration testing tools (for both networks/systems and applications) to view your environment as a hacker sees it.

Periodically an organization should administer a manual

    Requires Free Membership to View

    SearchFinancialSecurity.com members gain immediate and unlimited access to in-depth technical advice, strategies, and expert guides for securing data in high-risk financial environments. Join me on SearchFinancialSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchFinancialSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchFinancialSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

pen test, where a skilled attacker uses social engineering techniques and looks for logic flaws in an environment. Most regulations require a formal "assessment" at least once per year -- so these are probably already happening.

Relative to ISO 17799 and its successor, ISO 27001, those are relatively comprehensive frameworks laying out all of the things (policies and procedures) that can be protected, as opposed to all of the assets that should be protected.

If you need a list of things to "assess," one of the ISO frameworks can be used as a starting point. But I would consider it a default if it's already understood what's protected and how the attackers can get the data.