Applying a risk-based approach to cyber security
Using a risk management framework
The risk management framework used by the ISM draws from National Institute of Standards and Technology (NIST)
Special Publication (SP) 800-37 Rev. 2, Risk Management Framework for Information Systems and Organizations: A
System Life Cycle Approach for Security and Privacy. Broadly, the risk management framework used by the ISM has
six steps: define the system, select security controls, implement security controls, assess security controls, authorise
the system and monitor the system.
Define the system
Determine the type, value and security objectives for the system based on an assessment of the impact if it were to
be compromised.
When embarking upon the design of a system, the type, value and security objectives for the system, based on
confidentiality, integrity and availability requirements, should be determined. This will ultimately guide activities, such
as selecting and tailoring security controls, to meet those security objectives and determine the level of residual
security risk that will be accepted before the system is authorised to operate.
Following the determination of the type and value of a system, along with its security objectives, a description of the
system and its characteristics should be documented in the system’s system security plan.
Select security controls
Select security controls for the system and tailor them to achieve desired security objectives.
Each cyber security guideline discusses security risks associated with the topics it covers. Paired with these discussions
are security controls that the ACSC considers to provide efficient and effective mitigations based on their suitability to
achieve the security objectives for a system.
While security risks and security controls are discussed in the cyber security guidelines, and act as a baseline, they
should not be considered an exhaustive list for a specific system type or technology. As such, the cyber security
guidelines provide an important input into an organisation’s risk identification and risk treatment activities however do
not represent the full extent of such activities.
While the cyber security guidelines can assist with risk identification and risk treatment activities, an organisation will
still need to undertake their own risk analysis and risk evaluation activities due to the unique nature of each system, its
operating environment and the organisation’s risk tolerances.
Following the selection and tailoring of security controls for a system, they should be recorded along with the details of
their planned implementation in the system’s system security plan annex. In addition, and as appropriate, security
controls should also be recorded in both the system’s incident response plan and continuous monitoring plan.
Finally, the selection of security controls for a system, as documented in the system’s system security plan annex,
should be approved by the system’s authorising officer.
Implement security controls
Implement security controls for the system and its operating environment.
Once suitable security controls have been identified for a system, and approved by its authorising officer, they should
be implemented. In doing so, the details of their actual implementation, if different from their planned
implementation, should be documented in the system’s system security plan annex.
2