Your goal is to determine which identified risks present the greatest concern to SCHN based on their likelihood and potential impact. You will not calculate financial loss estimates or numerical risk scores.
Purpose
In the previous projects, you developed a risk management foundation for the Sabine Coastal Health Network (SCHN), identified important assets and business activities, and analyzed threats, vulnerabilities, and potential exploits.
In Project 4, you will use that work to conduct a qualitative risk assessment.
Your goal is to determine which identified risks present the greatest concern to SCHN based on their likelihood and potential impact.
You will not calculate financial loss estimates or numerical risk scores. Instead, you will use defined qualitative categories, organizational evidence, and professional judgment to evaluate and prioritize risk.
The results of this assessment will become the starting point for Project 5: Turning a Risk Assessment into a Risk Mitigation Plan.
Required Course Sources
Your analysis should be based primarily on the assigned textbook.
Primary Sources – Textbook
Managing Risk in Information Systems, 3rd Edition
Chapter 5 – Defining Risk Assessment Approaches
Chapter 5 should provide the primary foundation for:
Purpose of a risk assessment Scope of a risk assessment Critical areas Qualitative versus quantitative approaches Risk assessment challenges Resource and data limitations Estimating impact Using assessment results to support resource allocation and risk acceptance Chapter 6 – Performing a Risk Assessment
Chapter 6 should provide the primary foundation for actually conducting the assessment, including:
Selecting an assessment methodology Reviewing previous findings Identifying relevant assets and activities Evaluating threats Evaluating vulnerabilities Considering existing and planned controls Performing qualitative analysis Developing conclusions Presenting risk assessment results Chapter 8 – Identifying and Analyzing Threats, Vulnerabilities, and Exploits
Use Chapter 8 to support and verify the threat and vulnerability analysis you developed in Project 3.
Project 4 should build upon Project 3 rather than recreate it.
Secondary Sources – NIST Guidance
The textbook is the primary authority for this assignment.
The following NIST publications may be used as secondary sources to strengthen or clarify your analysis.
NIST SP 800-30 Rev. 1 – Guide for Conducting Risk Assessments
This is the most directly relevant NIST publication for Project 4.
It may be used to support concepts involving:
Preparing for a risk assessment Threats and vulnerabilities Likelihood Impact Existing controls Qualitative risk assessment Determining risk Communicating assessment results NIST SP 800-37 Rev. 2 – Risk Management Framework for Information Systems and Organizations
Use this publication primarily to understand how the risk assessment fits within the broader NIST Risk Management Framework (RMF).
The risk assessment performed in this project helps SCHN make better risk-based decisions as it moves toward selecting and implementing responses to identified risks.
NIST SP 800-39 – Managing Information Security Risk: Organization, Mission, and Information System View
This publication may be used when considering how cybersecurity risks affect:
Organizational operations Mission and business functions Organizational assets Individuals Reputation Management decision-making Source Priority
For this project:
Textbook Chapters 5, 6, and 8 = Primary Sources
NIST Publications = Secondary Supporting Sources
Students are not expected to reproduce the complete NIST risk assessment methodology.
Use NIST to support and strengthen the concepts learned in the textbook.
Scenario Update
SCHN leadership has completed a midyear review of its financial and cybersecurity position.
Several conditions now affect cybersecurity decision-making:
Operating expenses have increased. SCHN continues to operate with limited cybersecurity personnel and financial resources. Management cannot address every identified cybersecurity risk at the same time. SCHN has some historical incident information, but it does not have sufficiently reliable historical loss, frequency, or cost data to support a defensible quantitative risk assessment. Executive management needs a practical way to determine which cybersecurity risks deserve the greatest immediate attention. Because reliable quantitative data are limited, management has directed the cybersecurity team to perform a qualitative risk assessment.
Leadership wants the assessment to:
Use a consistent approach. Evaluate both likelihood and impact. Consider SCHN's actual organizational conditions. Account for existing controls where known. Clearly distinguish higher-priority risks from lower-priority risks. Identify the three risks that should move forward into formal risk mitigation planning. You are the cybersecurity analyst responsible for conducting this assessment.
Your Assignment
Using the SCHN scenario and the work completed in Projects 1, 2, and 3, conduct a qualitative risk assessment of the organization.
You must assess at least six significant risks.
Your assessment should demonstrate the progression from:
Asset or Business Activity → Threat → Vulnerability → Organizational Risk → Likelihood → Impact → Risk Level → Priority
Do not restart the analysis from the beginning.