← CISM: manage security, risk, and incidents
23 / 25 · 155 MIN

Threat scenarios and limits of estimation

Build and challenge an event tree to compare responses under explicit assumptions.

Define the population and window before calculating

The exercise models one fictional quarter with at most one material disclosure. The service remains in one of two mutually exclusive states for that quarter: normal or degraded. This simplification allows terminal outcomes to be added without counting the same quarter twice. It is not a universal description of services. If several material events are possible, a different frequency and loss model is needed. Before running the script, distinguish “probability of at least one event in the quarter” from “expected number of events in the quarter.” The second can exceed one; the first lies between zero and one. Renaming the window does not convert the parameters.

Multiply conditional probabilities

In normal configuration, the state probability is 0.8; access opportunity given that state is 0.25; disclosure given the opportunity and state is 0.05. The complete path is 0.8 × 0.25 × 0.05 = 0.01. Multiplication uses explicit conditions and does not assume independence between stages. In degraded operation, the figures are 0.2, 0.3 and 0.4, producing 0.024. Total disclosure probability in the model is 0.034. Do not multiply an average opportunity rate by a simple average of the disclosure rates: those rates refer to different conditional populations. The ledger preserves the conditions that give each number its meaning.

Exclusive and exhaustive branches

States must cover the whole population without overlap. The script requires state probabilities to sum exactly to one and identifiers to be unique. This detects arithmetic and some structural errors; it does not prove that the states represent reality. If “normal” and “external provider present” can occur together, adding them as exclusive alternatives double-counts part of the population. Define mutually exclusive combinations or use a model representing the dependency. At work, review that definition with specialists who understand the operation. A total of one hundred percent can conceal poorly defined categories, just as an incorrect sum may reveal only an input error.

From probability to expected consequence

The lab assigns a synthetic loss of 200,000 units per disclosure in either state. The normal contribution is 2,000 and the degraded contribution is 4,800; the sum is 6,800 per modeled quarter. This is the model’s expected value, not a promised loss or a maximum. An individual quarter may have zero loss or 200,000 under these assumptions. If consequence differs by state, multiply each path by its own loss before summing. Do not use this expectation to ignore a constraint on extreme consequences. Currency, horizon and included components must be comparable before options are contrasted.

Execute and check another representation

Run run.py with fixture.json and a new output file. The --self-check option compares the result with an independent enumeration of 10,000 synthetic quarters: 100 normal-state disclosures and 240 degraded-state disclosures. These counts are not collected observations; they are another representation of the defined figures. Checks cover zero and one probabilities, incomplete branches, invalid values and missing assumptions. Read the result and explain why probability can remain unchanged when assigned loss is zero. Then introduce a state-sum error and observe rejection. Passing checks demonstrates program behavior for these examples without validating the input probabilities.

Compare two interventions without hiding costs

Intervention A reduces conditional disclosure in normal operation from 0.05 to 0.01, keeping other parameters unchanged. Expected loss falls from 6,800 to 5,200. Intervention B reduces the degraded-state rate from 0.4 to 0.1 and produces 3,200. Before preferring B, consider its cost, operating capacity and unmodeled consequences. If both had equal cost, were feasible and the objective were only to minimize this loss, B would have the larger modeled reduction. Change separate input files and preserve the original. Do not call the difference between runs using chosen inputs an observed effect; it is a conditional comparison of assumptions.

One assumption can reverse the recommendation

Now assign degraded operation probability 0.02 and normal operation 0.98. Retain each state’s conditional probabilities. The reduction from A becomes 1,960 units and from B 360. The ordering changes because A affects a much larger population. This analysis does not determine which state probability is correct. Identify operational evidence that distinguishes the assumptions: relevant degraded conditions, configuration and suitability of the window. Even a time measurement does not automatically represent the probability of a state persisting for an entire quarter. If that simplification does not fit the service, revise the model rather than force data into it.

Deliver a recommendation with useful limits

Give the committee one page showing the scenario, branches, parameter origins, option comparison and assumptions that change the choice. Identify who can collect missing evidence and by when. The program does not provide calibrated probability, an insurance valuation or investment authorization. Its teaching value is making reasoning reproducible and open to challenge. At work, a decision may proceed under uncertainty when the responsible authority understands it and constraints are respected. Summarize what was calculated, what was observed and what remains judgment. Tie the next review to the fact that could change the action.

From report origin to local relevance

Three bulletins may represent one observation when all reproduce the same source. Record that lineage before raising confidence through “corroboration.” Repetition can increase visibility but does not provide independence. Also distinguish mechanism confirmation from group attribution: knowing an attacker’s name does not always change authorized protection for compromised access. Do not invent a name to complete the record or make public attribution a prerequisite the decision does not require. Relevance can depend on operating mode. A technique requiring maintenance access can be irrelevant in normal operation yet pertinent during the two hours when that access opens. Model these states without automatically spreading exposure across every hour. Negative findings need the same care. A search with no matches in five complete days observes nothing about two days without a sensor. Sensor failure does not confirm attack, but prevents treating those days as evidence of absence. Exercise: build three columns (observed fact, assumption and unresolved point) for a bulletin with common origins and a missing-log window. Propose the additional source that would close the gap within authorized scope.

Compare intervals without losing dependencies

An assumption range is not automatically a confidence interval. If, over the same horizon and criterion, A’s loss lies between 20 and 40 and B’s between 50 and 70, A’s maximum is below B’s minimum. A is preferable in every admitted combination, provided costs, obligations and feasibility are equivalent. This is a logical conclusion within the bounds; it does not establish that the bounds reliably estimate the real world. Overlap can also mislead when options share a variable. For A=10+40x and B=20+40x, with the same x between 0 and 1, separate ranges overlap. Yet B−A=10 for every x. Comparing A at x=1 with B at x=0 mixes incompatible states for the proposed comparison. Exercise: calculate both options at x=0, 0.5 and 1, then prove the difference algebraically. Identify which assumption would need to be abandoned to allow different x values. Preserve that dependence in the model, results and decision explanation. Preference can be robust to the shared variable while remaining dependent on other unvalidated assumptions.

A small mean can fail a tail limit

Write the admissibility criterion first. In a quarterly exercise, A loses 1,000 with probability 1% and zero otherwise; B loses 200 with probability 10% and zero otherwise. Their means are 10 and 20. If the rule requires probability of losing at least 500 to remain at or below 0.5%, A fails at 1%, while B passes because its loss never reaches 500 in the model. Minimizing the mean only after that gate selects B despite its higher mean. Three quantities differ: loss size, probability of reaching that size and expected loss. Comparing the mean with the 500 threshold does not test the rule. Comparing the 10% probability of any loss with 0.5% does not test it either, because the relevant event is losing at least 500. Exercise: draw the possible outcomes and mark those belonging to the criterion’s event. Sum only their probabilities, then calculate the means of admissible options. Values are entirely synthetic; the exercise establishes neither any bank’s tolerance nor a real tail estimate.

Changing the denominator changes the question

In a synthetic set of 10,000 requests with 1% improper activity, there are 100 improper and 9,900 legitimate requests. A rule alerting on 90% of improper requests produces 90 true alerts. If it also alerts on 1% of legitimate requests, it produces 99 false alerts. Among all 189 alerts, 90/189≈47.6% represent improper activity. This does not contradict 90% detection: it answers another question. “Alerts among improper requests” uses 100 as denominator; “improper requests among alerts” uses 189. The percentage of legitimate requests without alerts uses 9,900. Swapping these conditions can mislead forecasts of triage work or an individual alert’s usefulness. A small false-alert rate can generate many cases when the legitimate population is large. Exercise: build a table with improper/legitimate activity as rows and alert/no alert as columns. Fill 90, 10, 99 and 9,801 and check the margins. Explain which fraction answers the committee’s question. Rates are exact only in the exercise; an actual service needs suitable definitions, sampling, coverage and uncertainty.

Bound what is worth paying for information

A study has economic value when it changes a decision usefully enough to offset its cost under the chosen criterion. First calculate the best option without additional information. With states N=0.8 and D=0.2, A loses 20 in N and 100 in D; B loses 60 and 30. A’s mean is 36 and B’s is 54, so the no-study choice is A. Perfect information permits choosing A when N occurs and B when D occurs. Expected loss becomes 0.8×20+0.2×30=22. Maximum information benefit is 36−22=14. A study costing 16 that can only improve this choice does not pay under this model even if perfect: loss plus cost totals 38. An imperfect study cannot exceed that maximum benefit under these assumptions. Exercise: identify where comparing only 22 with 36 omits price, and where comparing the reduction of 70 in D with price omits probability 0.2. This conclusion requires the stated assumptions: no other benefit, cost, delay or scenario change. It does not turn every investigation into a monetary problem; it clarifies only the supplied economic decision.

cd content/labs/cism-risk-decisions
python3 run.py --self-check --output learner-run.json
IN PRACTICE

Under baseline assumptions, A reduces expected loss by 1,600 and B by 3,600 units. With degraded-state probability 2%, A reduces it by 1,960 and B by 360.

Common pitfalls

Multiplying marginal rates, adding overlapping branches, changing the window without reviewing inputs or presenting expectation as a loss ceiling.

Related topics: Scenarios and exposure conditions · Risk treatment and monitoring · Decision under uncertainty

Take this idea with you

An event tree is useful only when conditions, the time window and evidence limits are explicit.

Create account

References

CISM® is a registered trademark of ISACA. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by ISACA. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.