Analyzing and Assessing Cloud Security Risks
Once risks have been identified, they must be analyzed, assessed, classified, and prioritized, to determine the correct response to each risk.
In this phase, you determine the following:
- The likelihood of a threat succeeding
- The threat’s anticipated impact on both critical and non-critical assets
- A business impact analysis (BIA) to evaluate the consequences of a threat succeeding (including financial losses, reputation damage, downtime, and time to full recovery)
- Which threats should be prioritized for remediation
- The cost and time to remediate
Qualitative versus Quantitative Risk Analysis Methods
Qualitative analysis methods are subjective, usually manually performed, and are the first step in analysis and assessment (e.g., matrices, categorization).
Quantitative analysis methods are objective, typically involve numerical data collection, are often automated, and are the next step in analysis...