I’m an info sec risk analyst for my bank. This is great resource!!
@aliqureshi2227 Жыл бұрын
Thank you very much. Really appreciate it!
@esmatsaidy Жыл бұрын
You put everything in order and the explanation was so comprehensive
@aliqureshi2227 Жыл бұрын
Thank you very much for your kind feedback
@ramganesh6027 Жыл бұрын
One of the excellent and crisp explanations that I have seen so far. Thank You so much!
@aliqureshi2227 Жыл бұрын
Thank you @ramganesh
@AhmedAbrahan3 жыл бұрын
I will be joining as a Information Security Risk Analyst next month. This will help me prepare. Thank you.
@aliqureshi22272 жыл бұрын
It definitely will. Do let me know on what other topics you would like to hear me on.
@x8EchoslaM8x4 жыл бұрын
Thank you for your time and effort at creating this. Good job. Keep it up. I learned something new too.
@aliqureshi22274 жыл бұрын
Thank you very much. I really appreciate it.
@calvinworst8 ай бұрын
Here are the learning outcomes for anyone who needs them (they're all listed at 27:59) What is Risk? Why do we need risk management What is risk management? What is risk assessment? What is risk treatment? What is likelihood, impact, inherent and residual risk? Difference between threat, vulnerability and risk. Difference between asset owner and asset custodian. Difference between risk management and risk assessment. Difference between quantitative, qualitative, and semi-quantitative risk management. The Risk Management Process.
@vback42388 ай бұрын
Excellent job!! You are great!
@aliqureshi22278 ай бұрын
Thank you very much!
@adilaziz67783 жыл бұрын
Excellent content for beginners. Thank you for your effort
@aliqureshi22273 жыл бұрын
Thank you very much Adil.
@mamtakrishna2901 Жыл бұрын
Quite helpful and interesting, thank you
@aliqureshi2227 Жыл бұрын
Thank you very much Mamta!
@mayankraj2806 Жыл бұрын
Very good content. Thanks for sharing this
@aliqureshi2227 Жыл бұрын
Thank you for your feedback @mayankraj2806. Really appreciate it
@javedakhter822 жыл бұрын
Very easy understanding. Thanks for such working.
@aliqureshi22272 жыл бұрын
Thank you very much Javed! Really appreciate it.
@rruth90982 жыл бұрын
This is a great overview.
@aliqureshi2227 Жыл бұрын
Thank you
@MatiniSanni Жыл бұрын
Great information Ali. I like how you structure and explained the concepts. Keep up the good work!
@aliqureshi2227 Жыл бұрын
Thank you very much!
@asankadhananjaya8431 Жыл бұрын
Wow…. Great explanation and well organized. 👏👏👏
@aliqureshi2227 Жыл бұрын
Thank you very much Asanka!
@ihammads Жыл бұрын
good video, Thank you! but need to learn, how to implement this as well :)
@aliqureshi2227 Жыл бұрын
Thank you and best of luck ☺️
@adedejiyesufu1451 Жыл бұрын
Thank you, extremely helpful
@nihalshah4113 Жыл бұрын
Hi Ali Would be very helpful if you can provide a link to the actual slide deck itself. Great video! Thanks for the explanation!
@salaheddinebelmadani28923 ай бұрын
Hello Ali , Thank you for this helpful video . can you make video about Assent / process Inventory exercise ?
@ramamohangadiyaram9004 Жыл бұрын
Excellent Mr Ali!!
@aliqureshi2227 Жыл бұрын
Thank you very much Ram!
@kestere98624 жыл бұрын
Excellent delivery. Thank you.
@aliqureshi22274 жыл бұрын
Thank you very much Kester. I really appreciate it.
@tejaswiniaradhya3008 Жыл бұрын
Are we not considering the process value/asset value for risk score calculation?
@aliqureshi2227 Жыл бұрын
Thank you very much for bringing this up. Yes, in this video the asset valuation is not discussed in specific however, theoretically just in the context of this content, consider it be part of asset identification.
@ahmedaliareeb87832 жыл бұрын
It was informative, Ali! Thanks for the video
@aliqureshi22272 жыл бұрын
Thank you very much Ahmed. Really appreciate it.
@bala007raju4 жыл бұрын
Thanks for the session , I guess in 18:01 , it should be NIST SP 800-30 in place of NIST SP 800-50 .
@aliqureshi22274 жыл бұрын
Thank you! and Absolutely. Apologies from my end. Will manage the rectification.
@waqasabro98554 жыл бұрын
Nice initiative Ali.. 👍😇
@rohizzcool3 жыл бұрын
very good work..appreciate it
@aliqureshi22273 жыл бұрын
Thanks Rohit
@TheKnowledgeGateway4984 жыл бұрын
Good one.
@aliqureshi22274 жыл бұрын
Thank you!
@stevejobs-m1u4 жыл бұрын
Very concise and informative.
@aliqureshi22274 жыл бұрын
Thank you very much Kaleem!
@tausefkhan2 жыл бұрын
Thank you for the informative information. Do you have a default template to use?
@aliqureshi2227 Жыл бұрын
Thanks Tausef. Unfortunately, no.
@phathiswabam26304 жыл бұрын
Thank you very much for this video. It came very handy. Would you be able to recommend the academic journals within IT Security Risk Assessment that I could refer to for my literature review? That will be much appreciated.
@aliqureshi22274 жыл бұрын
Hi Phathiswa! Thank you for your kind words. It was encouraging. My apologies, I am no aware about any specific academic journals within the domain. But you can always refer to standardizing bodies and international platforms like SANS for the same.
@phathiswabam26304 жыл бұрын
@@aliqureshi2227 so much appreciated Ali. I found something I could use by U Kumar plus the standards. Have a blessed new year 🙏
@ziyadalvi20944 жыл бұрын
Keep up the good work ❤️
@aliqureshi22274 жыл бұрын
Thank you Ziyad!
@sandrapink17 Жыл бұрын
Great
@aliqureshi2227 Жыл бұрын
Thank you
@paraskhullar36602 жыл бұрын
Hello, i will a writing assignment about information security, security risks, security control, and the application of risk control and risk measures. So, can you help me like you make video as well as notes on it. Please help me.
@tanaysamanta47303 жыл бұрын
Nice !
@aliqureshi22273 жыл бұрын
Thanks 🙏
@lokanathmuduli6347 Жыл бұрын
What is the meaning of waiver and Derogation? in risk treatment.
@aliqureshi2227 Жыл бұрын
Waiver and derogation are just literal jargon. Both of them are related to risk acceptance. Waiver is where management allows you to allow a particular risk open as untreated. Same story is with derogation. The real deal is that what constitutes such waivers and derogation? - If the risk levels are low? If risk likelihood is high but impact is low? Or the benefit realized from a particular thing is far greater in value than the impact of the risk?
@ras4033 жыл бұрын
An excellent way of teaching. Thanks. In video while defining, residual risk = inherent risk - control value However, in overview of risk management process, residual risk = inherent risk divided by control value Which one is right?
@aliqureshi22273 жыл бұрын
Thank you very much. I would recommend to use division as it leads to a reasonable residual risk value.
@sanjai46857 ай бұрын
👌🏻❤
@jasondudko3968 Жыл бұрын
Thank you
@aliqureshi2227 Жыл бұрын
You're welcome Jason.
@TVVDINAKARAN4 жыл бұрын
@16:45
@aliqureshi22274 жыл бұрын
I am sorry. Can you please translate that in to English if that is a question?
@TVVDINAKARAN4 жыл бұрын
@@aliqureshi2227 Oops sorry mate i marked the timeline for my purpose So that i can resume the video later from where i left it off