📘 CodingMarble Learn

Information Security Management

Managing security means writing a policy (the rules), finding and scoring risks (chance x harm), treating them (reduce, transfer, avoid or accept), and planning business continuity so work restarts quickly after a failure. It is a repeating cycle: plan, do, check, improve.

🎬 Step-by-step story

  1. A policy is the rulebook for safe information: who may see what, what is allowed, and what to do if something goes wrong.
  2. A risk is a bad thing that could happen. We score it: chance x harm. Here the chance is 2 and the harm is 2, so the score is 4. The tower is green and low.
  3. Now the chance becomes 4 and the harm becomes 4. The score is 16. The tower grows tall and turns red. This risk needs action.
  4. We treat it. Better locks and training reduce the chance from 4 to 2. The score falls from 16 to 8 and the tower turns amber.
  5. Some bad things still happen. The main server fails. A ready backup server takes over, and the work is back in 1 hour. This is business continuity.
  6. Free play. Move the chance and harm sliders, or press a treatment button. Try to bring any risk down to green.

Tip: drag the 3D scene to turn it. Use two fingers to zoom.

🤔 Common doubts, cleared

Why multiply chance and harm instead of adding?

A very likely but tiny harm, or a huge but near-impossible harm, should not look as big as something both likely and harmful. Multiplying makes the tower tall only when both are high.

Can I make a risk zero?

Usually not. Avoiding the activity can remove it, but most risks only get smaller. What is left is the residual risk.

Who writes the policy?

Managers, with help from the technical and legal people. The top leader approves it so that all staff take it seriously.

What if my main system fails?

The continuity plan switches work to a backup system and restarts services in the planned order, like the green backup server.

Information security policy

A security policy is a short written document that says how an organisation protects its information. The top boss approves it so everybody takes it seriously.

A policy must be written in simple words, shared with everyone, and updated when things change.

Risk control: find, score, treat

A risk is a bad event that could happen to something valuable (an asset). To manage it we follow four steps.

  1. Find the assets (data, computers, people) and the dangers to each.
  2. Score each risk: risk = chance x harm. Give each a number from 1 (small) to 5 (big) and multiply.
  3. Treat the big ones first.
  4. Check again later, because things change.

There are four ways to treat a risk:

What is left after treating is the residual risk.

Business continuity

Even good protection can fail: fire, floods, power cuts, ransomware. Business continuity means the important work keeps going, or restarts fast, when this happens.

Fixing the technology after a failure is called disaster recovery. It is one part of business continuity.

The PDCA cycle

Security management never ends. It repeats: Plan (write policy and find risks), Do (put measures in place), Check (test and review), Act (improve). Each turn of the cycle makes the system stronger.

Try it

In the 3D (last step): set the chance to 5 and the harm to 5. Press "Reduce chance" three times. What score do you reach? Now press "Insure". Which button lowers the score more at the start?

At home: list three risks to your phone (dropped, stolen, hacked). Give each a chance and a harm from 1 to 5, multiply, and decide which one to treat first.

Key formulas and definitions

Worked examples

1. A risk has chance 3 and harm 5. Find the score.

Score = 3 x 5 = 15. This is high (red) and should be treated soon.

2. Two risks: A has chance 5, harm 1. B has chance 2, harm 4. Which is bigger?

A = 5 x 1 = 5. B = 2 x 4 = 8. B is bigger, even though A is more likely.

3. A shop buys insurance against a fire in its shop. Which treatment is this?

Transfer. The insurance company carries the money loss.

4. A risk has chance 4, harm 4. Training cuts the chance to 2. What are the old score, new score and the drop?

Old = 16. New = 2 x 4 = 8. The score drops by 8, so it falls from red to amber.

Common mistakes

Practice quiz

1. Risk score is calculated as...
2. Buying insurance is which risk treatment?
3. A written set of rules for protecting information is a...
4. The goal of business continuity is to...
5. Risk left after treatment is called...

Practice: answer these yourself

Type or choose your answer, then press Check. Use a hint if you are stuck; the full solution appears after you answer.

Frequently asked questions

What is an information security policy?

A written set of goals and rules, approved by the leaders, that tells everyone how information must be protected.

What is the difference between risk and threat?

A threat is something that can cause harm (a virus, a flood). A risk is how likely it is and how big the harm would be.

What is the difference between business continuity and disaster recovery?

Business continuity keeps the whole business going. Disaster recovery is the part that repairs the computers and data afterwards.

Where this is taught

Japan高校(専門学科)1〜3年Information Security

Learn first

Related lessons

All Computer Science lessons