1.4 Risk Management, Security Policies, and Security Auditing
Key Takeaways
Risk analysis connects assets, threats, vulnerabilities, likelihood, and impact; residual risk is what remains after controls are applied and accepted by an authorized risk owner.
Policies state management intent, standards make requirements measurable, procedures define repeatable steps, and guidelines provide recommended flexibility.
Security audits test evidence against defined criteria and independence requirements; vulnerability assessments and penetration tests answer different technical questions.
Incident handlers use audit trails, control ownership, exception records, and risk registers to decide what to preserve, whom to notify, and which containment authority applies.
An actionable audit finding commonly records criteria, observed condition, evidence, risk, ownership, corrective action, target date, and validation method; required fields depend on the audit methodology.
Risk Management, Security Policies, and Security Auditing
Incident handlers do not make containment decisions in a vacuum. They operate within a governance system that identifies important assets, assigns risk ownership, defines acceptable use, and records which controls should exist. During an incident, that system tells the team why a database matters, which executive can accept downtime, what evidence must be retained, and whether a failed control was approved as an exception or simply neglected.
Translating Threats into Risk
A practical risk statement identifies an asset, a threat event, an exploitable vulnerability or condition, and the resulting business impact. Risk is commonly ranked from likelihood and impact, but a numeric score is only a decision aid; organizations must define the scale and document assumptions.
- Inherent risk is exposure before considering controls. An internet-facing payroll portal storing tax identifiers has substantial inherent confidentiality risk.
- Control effectiveness asks whether safeguards are correctly designed, implemented, and operating. A written MFA standard provides no protection if a legacy authentication path bypasses it.
- Residual risk remains after controls. It must be accepted by an authorized risk owner, transferred, avoided, or reduced further.
- Risk appetite is the broad level and type of risk an organization is willing to pursue or retain. Risk tolerance sets narrower measurable boundaries, such as a maximum recovery time or number of privileged exceptions.
The risk register should record the scenario, affected assets, owner, rating rationale, existing controls, treatment plan, target date, and acceptance decision. During triage, responders use these records as context rather than treating them as proof: an asset labeled “low impact” may still hold newly regulated data or provide a path to a critical system.
Governance Document Hierarchy
Exam scenarios frequently test whether the handler chooses the correct document level:
| Document | Purpose | Incident-response example |
|---|---|---|
| Policy | States management intent, scope, authority, and mandatory outcomes | The organization shall maintain an incident response capability and report suspected incidents |
| Standard | Defines measurable mandatory requirements | Critical systems must forward security logs to protected centralized storage |
| Procedure | Gives ordered operational steps | Validate an alert, open a case, preserve volatile data, and escalate by severity |
| Guideline | Offers recommended practices where judgment is permitted | Suggested interview questions for a post-incident review |
| Baseline | Defines an approved minimum configuration | Required endpoint logging, time synchronization, and EDR settings |
Policies should name owners, review cycles, exception authority, enforcement, and related standards. An exception is not an informal waiver: it should identify scope, justification, compensating controls, approver, expiration, and review date. During an incident, the team preserves exception records because they may explain why a control was absent without proving that the decision was reasonable.
Security Auditing versus Technical Testing
A security audit compares evidence with defined criteria, such as internal policy, contract terms, or a regulatory control set. Independence matters: a control owner can perform monitoring or self-assessment, but an audit requires sufficient objectivity for its intended assurance level.
A vulnerability assessment identifies and prioritizes suspected weaknesses, generally without exploiting them. A penetration test attempts authorized exploitation to demonstrate attack paths and impact within agreed rules of engagement. Neither activity automatically constitutes an audit, and a clean scan does not prove policy compliance.
Audit evidence may include configurations, tickets, identity records, access reviews, approved exceptions, training records, SIEM events, backup-restore tests, and interviews. Evidence should be relevant, reliable, sufficient, and traceable to the population and period being tested. Screenshots without source, time, account, or collection context are weak evidence.
From Audit Finding to Incident Improvement
A defensible finding contains:
- Criteria: the policy, standard, contract, or control requirement.
- Condition: what the auditor observed.
- Evidence: reproducible records supporting the condition.
- Cause: why the condition occurred, distinguished from speculation.
- Risk and impact: what could happen and which assets or obligations are affected.
- Corrective action: owner, due date, milestones, and validation test.
Incident handlers contribute facts to this process but should not alter evidence to make a control appear effective. Suppose a ransomware investigation finds that domain-controller logs retained only three days despite a 180-day standard. The immediate task is to preserve remaining logs and find alternate telemetry. The audit task is to document the retention failure, determine whether storage capacity, configuration drift, or an expired exception caused it, assign remediation, and later verify that the corrected pipeline retains searchable records for the required period.
Exam Scenario Method
When an ECIH question describes a governance failure, ask four questions: Who owns the risk? Which document sets the requirement? What objective evidence shows whether the control operated? How will remediation be validated? This avoids confusing an incident ticket with a risk acceptance, a scan with an audit, or a policy aspiration with an implemented control.
An audit finds that a privileged remote-access service lacks MFA. Management approved a six-month exception with compensating IP restrictions, but the exception expired two months ago. Which statement best describes the current exposure?
The original approval permanently transferred the risk to the auditor
The missing MFA is irrelevant because an IP restriction always provides equivalent assurance
The organization has residual risk without a current authorization, and the expired exception plus control evidence should be preserved and escalated
A penetration test must exploit the service before the condition can be recorded
Which artifact is a procedure rather than a policy, standard, or guideline?
A board-approved statement that the organization will maintain an incident response capability
A mandatory requirement that critical servers retain centralized security logs for 180 days
Recommended interview prompts that facilitators may adapt during lessons learned
An ordered checklist for validating a malware alert, opening a case, collecting volatile data, and escalating it
A compliance team reviews a sample of access approvals against the company standard, while a separate red team attempts to exploit excessive privileges. What is the correct distinction?
Both activities are audits because they concern the same accounts
The evidence review is an audit test against criteria; the red-team exercise is authorized adversarial testing that demonstrates attack paths
Only the red-team exercise can produce a valid control finding
The evidence review is a vulnerability scan and the red team performs risk acceptance
Sections you finish are checked off in the contents.