Module Overview

Defensible, metrics-driven risk management across the socio-technical stack

This module synthesised my approach to defensible, metrics-driven risk management: coherent threat modelling, quantitative justification of investment, prescriptive controls with ownership, and verifiable continuity. Tutor feedback directly shaped the action plan to improve control specificity, model transparency, resilience evidence, and GDPR operationalisation.

Module Learning Outcomes

The five outcomes assessed by this module

🧩

Threat & Risk Analysis

Identify and analyse threats using STRIDE; prioritise risks with FMEA and probability–impact techniques.

📈

Quantitative Modelling

Quantify risk with Expected Monetary Value and Monte Carlo simulations to justify security investment.

🛡️

Prescriptive Control Design

Design controls mapped to risk appetite, KPIs (MTTD/MTTR), ownership, and GDPR (privacy by design/by default).

🔄

Resilience & Continuity

Develop BC/DR strategies with explicit RTO/RPO targets and tested failover procedures.

🗣️

Executive Communication

Communicate findings to technical and executive audiences via structured reports and summaries.

Key Artefacts

Summative submissions and tutor feedback

🤝

Team Project — Pampered Pets Risk Identification Report (Group D)

TEAM SUMMATIVE

I contributed to a comprehensive risk assessment for a fictional digital transformation, framing capabilities with NIST CSF and modelling threats via STRIDE, then using FMEA to prioritise remediation. We addressed compliance, data protection, operational continuity, and stakeholder engagement, proposing next steps for mitigation planning, testing, and continuous monitoring.

📊

Individual Executive Summary — Security Risk Management

INDIVIDUAL SUMMATIVE

I integrated prior units into an executive-level report that quantified disruption and quality-risk exposure using EMV and a 10,000-run Monte Carlo. Outputs informed a budget-aware roadmap: QMS uplift and training, zero-trust enhancements, supplier diversification, and an active-active BC/DR pattern aligned to sub-minute RTO/RPO.

🪞

Reflective Review — Professional Growth

REFLECTIVE

I evaluated my progression from a tool-centred practitioner to a strategy-oriented professional, integrating ethics, analytics, and communication. I emphasised stakeholder engagement, horizon-scanning, and pairing technical controls with compliance and user awareness.

Reflections and Notes

Key takeaways shaping ongoing practice

🧭

Control traceability

Added a STRIDE → control mapping with KPIs (e.g., % encryption coverage, MTTD/MTTR) and owners.

📐

Quantitative rigour

Documented Monte Carlo inputs, ranges, correlations, and sensitivity checks to support decisions.

🧪

Resilience evidence

Defined RTO/RPO targets and scheduled failover drills with logs for verification.

⚖️

Governance & GDPR

Reinforced privacy-by-design practices through DPIAs, training, and periodic audits.

Professional Skills Matrix (Learnt)

Capabilities developed through the module

Skill Summary
Risk Identification & Modelling Applied NIST CSF, STRIDE, and FMEA to surface and prioritise risks.
Quantitative Risk Analysis Built EMV and Monte Carlo models; interpreted distributions and sensitivity findings.
Control Design & KPIs Linked controls to risks; defined ownership and measurable outcomes (MTTD/MTTR).
Resilience & Continuity Set RTO/RPO targets; planned and evaluated failover and restoration drills.
Governance & Compliance Embedded GDPR privacy-by-design/default; maintained audit-ready artefacts.
Executive Communication Produced concise executive summaries and action-oriented roadmaps.

Action Plan

Concrete, time-bound goals derived from tutor feedback

  1. Control specificity & ownership. Map each control to a STRIDE risk, KPI, and accountable owner; publish traceability. Target: Dec 2025
  2. Quantitative model transparency. Publish Monte Carlo assumptions, ranges, correlations, and sensitivity analysis. Target: Dec 2025
  3. BC/DR evidence cadence. Run quarterly failover tests; track RTO/RPO results and remediation actions. Target: Jan 2026
  4. GDPR-by-design checklist. Adopt a DPIA template and a one-page control checklist; audit quarterly. Target: Jan 2026

Conclusion

This module synthesised my approach to defensible, metrics-driven risk management: coherent threat modelling, quantitative justification of investment, prescriptive controls with ownership, and verifiable continuity. Tutor feedback directly shaped the action plan to improve control specificity, model transparency, resilience evidence, and GDPR operationalisation.

References

ISO/IEC (2022) ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements. Geneva: International Organization for Standardization.

ISO/IEC (2022) ISO/IEC 27005:2022 Information security, cybersecurity and privacy protection — Guidance on managing information security risks. Geneva: International Organization for Standardization.

National Institute of Standards and Technology (2024) The NIST Cybersecurity Framework (CSF) 2.0. NIST CSWP 29. Gaithersburg: NIST. Available at: https://doi.org/10.6028/NIST.CSWP.29

Council of the European Union (2016) Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data (General Data Protection Regulation). Brussels.

Hubbard, D.W. and Seiersen, R. (2016) How to Measure Anything in Cybersecurity Risk. Hoboken: Wiley.

Shostack, A. (2014) Threat Modeling: Designing for Security. Indianapolis: Wiley.