At this point, the intersection of risk management and cybersecurity has begun to come together. This is where the real development of the information security program begins. In Stage 1 of this framework, organizations conducted a thorough inquiry into the current state of their digital environment. Now, in Stage 2, that environment has been thoroughly studied and assessed to uncover important assets and the cyber risks posed to them. Those risks have now been prioritized, and countermeasures can be selected.

Risk responses are the decisions and actions an organization chooses to take to manage identified risks and reduce them to an acceptable level. There are five specific categories of risk responses:

  1. Risk Acceptance: The organization acknowledges the risk and decides to take no action because the cost of countermeasures exceeds the potential losses if the risk were realized.
  2. Risk Avoidance: The organization completely removes the root cause of the risk by removing or significantly altering the affected asset.
  3. Risk Mitigation: The organization reduces the probability of a risk occurring and/or lessens the impact it will have if realized by implementing proactive measures. Most cybersecurity controls fall under risk mitigation.
  4. Risk Sharing: The organization reduces the burden of a risk by distributing some of the responsibility to other parties. The most common example is cyber insurance.
  5. Risk Transference: The organization removes the burden of a risk by transferring responsibility to a third party. This is commonly accomplished through outsourcing services to cloud providers or hiring an MSSP.

Organizations need to think carefully about which risk responses they wish to select. There is no universally correct answer, as circumstances differ from one organization to another. Low-impact risks that would cost a fortune to address may be accepted and left untouched. Outdated technology platforms that create catastrophic risks to the organization's well-being may be best avoided entirely.

However, for the most part, risk mitigation is the response method that will be selected for the majority of cyber risks. Mitigation involves the selection and implementation of countermeasures to reduce the risk posed by each vulnerable asset to an acceptable level. Countermeasures are actions, devices, procedures, techniques, or other measures that reduce the vulnerability of an information system. In information security and cyber risk management, these countermeasures are more commonly referred to as controls.

Cybersecurity controls can be broken down into the following control types and control functions.

Control Types (How They Are Implemented)

  • Technical (Logical) Controls: Software and hardware mechanisms.
  • Administrative Controls: Policies, procedures, guidelines, and other documents that govern behavior within the environment.
  • Physical Controls: Tangible mechanisms that protect assets from real-world damage.

Control Functions (What They Do)

  • Preventive Controls: Proactive controls that stop a cyber incident before it occurs.
  • Detective Controls: Controls that identify and alert on malicious activity that is occurring or has already occurred.
  • Corrective Controls: Controls that mitigate damage and restore assets to a baseline state after an incident.
  • Deterrent Controls: Controls that discourage adversaries from initiating cyber incidents.
  • Compensating Controls: Alternative methods of securing assets when the primary control is unavailable or impractical.
  • Directive Controls: Rules and regulations that enforce specific behaviors to help prevent cyber incidents.

From this outline, you can see the overall flow:

Information Security Program = Vulnerabilities and Threats Create Risks → Risks Are Uncovered and Assessed → Risks Are Selected for Mitigation → Control Types Are Chosen → Control Functions Are Implemented

Stage 3: Implement of the CyberLadder Framework provides a comprehensive list of cybersecurity controls across several domains, along with brief descriptions of their functionality. At this point, organizations can consult that stage and select cybersecurity controls to address the risks uncovered during Stage 2.

Once controls have been selected, the organization will possess a risk profile, prioritized risks, selected risk responses, and a list of controls designed to address those risks. Together, these elements form the first iteration of the organization's information security program.

The remainder of Stage 2: Plan focuses on determining how the necessary controls will be procured and creating an organized roadmap for their implementation.