4 - Risk Assessment Methodologies
Advanced Analytical Techniques for Modern Information Systems Context: Moving beyond the standard qualitative matrices introduced in Module 2, this module equips participants with specific, specialised frameworks (STRIDE, FMEA, Red Teaming) and structured elicitation techniques required to assess deterministic Cloud risks and highly subjective, probabilistic AI risks.
Lesson Objectives:
Differentiate Analytical Approaches: Select and apply the appropriate methodology (asset-based vs. event-based) based on the specific technological domain and threat landscape.
Execute Cloud Threat Modelling: Systematically deconstruct cloud architectures using the STRIDE framework to identify vulnerabilities before deployment.
Assess Opaque AI Vulnerabilities: Navigate the subjective nature of AI risks (e.g., model drift, bias, hallucinations) using structured expert elicitation and qualitative impact evaluation where historical data is absent.
Integrate Adversarial Findings: Translate the results of specialised testing techniques, such as AI Red Teaming and Failure Modes and Effects Analysis (FMEA), directly into formal, actionable entries in the risk register.