Technology Standard

 


Contingency Planning and Business Recovery Program

Risk Assessment for Information Technology Systems

Version: 1.0
Status: Approved: 2/21/07
Contact: Director, Technology Services


PURPOSE

The Risk Assessment process is conducted to identify the potential threat to an IT system, determine the likelihood a potential threat will occur, identify and evaluate vulnerabilities, and determine the loss impact if one or more vulnerabilities are exploited by a potential threat. The output of this process aids in identifying appropriate controls for reducing or eliminating risk.


SCOPE

The Risk Assessment Standard for Information Technology Systems covers all VCCS and college business processes and the related Information Technology infrastructure. 


APPLICABILITY

The Risk Assessment Standard for Information Technology Systems process is applicable to the System Office and all Colleges.


STANDARD

The VCCS Vice Chancellors and individual College Presidents are responsible for conducting a risk assessment of all sensitive information technology systems. The Contingency Planning Coordinator, assigned in the Business Impact Analysis stage of the Contingency Planning and Business Recovery Program, will coordinate the risk assessment process and provide an executive summary to advise all applicable parties of all known threats so that security safeguards can be effectively utilized to minimize the potential for future losses.

Requirement:

Requirement:

Once the appropriate worksheets of the Business Impact Analysis Template are complete, an understanding of the systems processing environment should be shown. A risk assessment must be completed for each system classified as sensitive to include:

Requirement:

Risk Mitigation recommendations must also be included in the risk assessment. The goals and mission of the VCCS or college should be considered when selecting the risk mitigation options. This process is addressed during the questionnaire process and options should be selected from the following:

Recommendation:

Questionnaires are listed below to assist in evaluating the risks and exposures. The VCCS and individual colleges are encouraged to utilize the questionnaires listed below and are encouraged to develop additional questionnaires as deemed necessary to complete the overall risk assessment process.

A brief narrative of each form is included; as well as, a recommendation of the employee position to most appropriate to complete the questionnaire.

Contingency Planning and Business Recovery Program, Business Impact Analysis Questionnaire

This questionnaire collects information on the organizations development and implementation of standards, best practices, and etc. prescribed in the COV ITRM Standard SEC501-01, Information Technology Security Standard.  The individual(s) responsible for coordinating and planning the business recovery effort functions is the recommended candidate to complete this questionnaire. (Contingency Planning Coordinator)

Contingency Planning and Business Recovery Program, System Server Questionnaire

This questionnaire collects information on computers utilized as servers that meet the needs of customers for file, print, application, database, web, mail, and etc. The individual(s) responsible for server administration functions would be the recommended candidate to complete this questionnaire. (System Administrator)

Contingency Planning and Business Recovery Program, Local Area Network (LAN) Management Questionnaire

This questionnaire collects information on Local Area Network (LAN).  The individual(s) responsible for the Local Area Network is the recommended candidate to complete this questionnaire. (LAN Administrator)

Contingency Planning and Business Recovery Program, Application Management Questionnaire 

This questionnaire collects information on Application Management.  The individual(s) responsible for application support is the recommended candidate to complete this questionnaire. (Application Support Administrator)

Contingency Planning and Business Recovery Program, LOGON Identification Management Questionnaire 

This questionnaire collects information on the Logon procedures in place for all applications and services that are provided.  The individual(s) responsible for the security access to applications and services is the recommended candidate to complete this questionnaire. (Security Administrator)

Contingency Planning and Business Recovery Program, Operations & Administrative Management Questionnaire

This questionnaire collects information on the operations and administrative support of software and hardware.  The individual(s) responsible for distribution and support of hardware and software is the recommended candidate to complete this questionnaire. (Operation Support Administrator) 

 Contingency Planning and Business Recovery Program, Enterprise Application Management Questionnaire

This questionnaire collects information on the VCCS or College development and implementation of standards and best practices prescribed in the COV ITRM Standard SEC501-01.  The individual(s) responsible for application support would be the recommended candidate to complete this questionnaire (Application Support Administrator).

Requirement:

The Contingency Planning Coordinator will produce an Executive Summary to advise all applicable parties of all known threats so that security safeguards can be effectively utilized to minimize the potential for future losses. The Executive Summary should include the purpose and scope of the assessment, the manner in which the data was collected (via interviews, questionnaires, etc.), and the risk assessment results.

The risk assessment results must contain a formal written response for all questions where a "No" response was recorded on the questionnaire. This information will be obtained from the individual questionnaire and will include the threat, likelihood, vulnerability, and risk mitigation information. A summary table may be included at the end of each questionnaire category referenced in the Executive Summary. If potential privacy risks are identified, measures need to be taken to avert or mitigate these risks. The nature of these measures must be outlined for each risk.

Requirement:

Additional security controls should be applied to protect against significant risks. Additional control areas are listed below and links are provided to the specific documents which discuss each security control area:


RELATED LINKS

IT Systems Security, IT System Hardening

IT Systems Security, IT Systems Interoperability Security

IT Systems Security, Malicious Code Protection

IT Systems Security, IT Systems Development Life Cycle Security

Logical Access Control, Account Management

Logical Access Control, Password Management

Logical Access Control, Remote Access

Data Protection, Data Storage Media Protection

Data Protection, Encryption

Threat Management, Threat Detection

Threat Management, Incident Handling

Threat Management, IT Security Monitoring and Logging

Personnel Security, Access Determination and Control

Personnel Security, Acceptable Use

Facilities Security, Physical Security

 


Return to Information Security Program