Risk vs. Business Need

Simply put, business needs are all the processes and activities required to both run a business and make it profitable.

7 slides · 2 min read · Domain 8

Slide 1

As security professionals, our role is only that of advisors. Security doesn't dictate what the business does, it merely allows the business to do so safely and securely.

However, if the business decides on a course of action, an area of operation or a means to meet the business requirements, then that is what the business will do.

As professionals, we must understand what the business drivers are. Then, we must evaluate the associated risks by whatever means we have at our disposal and recommend a course of action to mitigate these risks.

There are four basic steps that a business might take in identifying its needs:

1. Consult or Ask

Here, through discussions, questionnaires and working groups, the business should consult its stakeholders about:

  • what they do,
  • what they think they provide to the business and
  • what tools they might use to accomplish this end goal.

This should be thought of as a discovery phase and often needs to be repeated to obtain consistent answers.

2. Evaluate

In this step, the business should evaluate the answers recorded in the consult step, because business leaders often can't clearly articulate what they do and the ways in which they do it.

As a result, the answers obtained will often be wrong.

3. Agree

Based on the evaluated responses from the consult step, the business will make a series of assumptions to reconcile its thinking with those of the stakeholders. If and when all parties agree, the business can produce a set of business plans.

4. Document

The business should record the process and plan everything as this plan will become the working model for the business.

This is a basic overview of the steps a business might take. Naturally, business needs will change over time, the business will expand, contract, move into different business areas, geographical locations, etc.

However, this process does not consider risk. It is simply a reflection of what the business says it currently needs.

In most cases, the security team, with perhaps the exception of the security architect, is not involved in these discussions.

Instead, once a decision has been reached and implemented it falls to the security team to ensure the business plan is secure.

While risk has been discussed at length, here we need to evaluate the software security requirements.

Test this domain