
attacks are devastating to recover from.(Jhanjhi and
Shah, 2024) In today’s landscape, maintaining small
and medium-sized businesses from various threats
is crucial for ensuring a secure environment. This
paper presents a targeted risk assessment for diet
centres, focusing on its broader applicability by
keeping the company’s identity confidential, referred
to as Diet Centre X. Hence, Diet Centre X is
committed to empowering individuals to live healthier
lives through tailored meal plan subscriptions and
expert dietitian consultations. By continually
monitoring health assessments, the centre tracks
customer progress and provides essential resources,
enabling clients to confidently pursue their long-term
wellness goals. Diet Centre X does not have a
technical team of experts because it is not very
useful in its field of business. Still, this decision
has negatively impacted the business’ information
security. Most employees lack security knowledge,
and this is very dangerous because, in their day-to-day
tasks, they deal with critical business information.
Because the managers lack technical knowledge,
they have ranked the security measure as the least
priority. Given that the most suitable framework
approach for Diet Centre X is Operationally Critical
Threat, Asset, and Vulnerability Evaluation Allegro
(OCTAVE-Allegro) (Hom et al., 2020a) because it
delivers an in-depth risk assessment that matches the
operational requirements of the diet centre.
The rest of the paper is organized as follows. In
section 2, we discuss the related works of literature
on past risk assessment approaches, In section 3,
we present an in-depth discussion of the tools and
techniques, in section 4 we assess and identify the
risks by using the OCTAVE Allegro framework, in
section 5 we present the lessons learned, solutions,
and recommendations in response to the risks and
threats identified, lastly in section 6 we conclude the
paper and summarize the findings.
2 REVIEW OF RELATED
LITERATURE
This section reviews past approaches to information
security risk management and the framework tools
used in the risk assessment approach, particularly
in small and medium-sized businesses like Diet
Centre X. This section aims to find the best
framework tool to conduct it on Diet Centre X
for a risk assessment. In the insurance sector,
researchers used two framework tools, the ISO/IEC
27005:2018 (Fahrurozi et al., 2020) and NIST Special
Publication 800-30 series (Van Devender, 2023) to
enable organizations to conduct an exhaustive risk
assessment. ISO 27005:2018’s strengths include
offering structured guidelines for identifying and
assessing vulnerabilities and all potential threats
and providing consistency in monitoring the risks.
Their methodology handles large volumes of
sensitive customer data, such as personal, financial,
and health information. The conducted approach
helps insurance companies identify and assess data
security, privacy, and regulatory compliance risks
and implement targeted risk mitigation strategies for
improving data protection and security practices.
This approach has enhanced risk management and
ensures better alignment with global standards,
improving insurance companies’ security posture
and compliance.(Putra and Soewito, 2023) The
researchers showed in their study how organizations
with limited funding and basic technological
understanding. OCTAVE Allegro focuses on
identifying and safeguarding vital information assets,
evaluating current security measures, and assessing
possible threats and vulnerabilities (Suroso and
Fakhrozi, 2018) in addition, it is distinguished
by its outstanding features and unparalleled
capabilities, making it an undeniable leader in
its field due to its methodology’s user-friendly nature,
which allows organizations with low cybersecurity
resources to adapt it. This methodology thoroughly
identifies the important assets and vulnerabilities,
evaluates risks, and then ranks the risks based on
impacts. The OCTAVE Allegro framework will
help the organization implement the proper security
measures to protect private information and increase
awareness. (Hom et al., 2020b) Another small
and medium-sized business, a medical clinic has
implemented three frameworks, HIPAA (Moore
and Frye, 2019), NIST, and ISO/IEC 2700, which
have provided the clinic with a thorough approach
to an information security risk assessment and a
guarantee that the clinic’s security procedures are
strong, legal, and efficient in all facets of data
privacy and cybersecurity. The researchers combined
three different frameworks to provide extensive
coverage. Each framework provided a distinct
advantage, with the NIST framework focusing on the
technical angle of cybersecurity risk management
and protection procedures. In contrast, HIPAA
focuses on the legal angle, addressing certain legal
compliance requirements in the healthcare industry.
ISO/IEC 27001 focuses on the organizational angle,
guaranteeing a comprehensive information security
management system. As a result, the researchers
got a comprehensive risk management procedure
that addresses information security’s technological,
A Risk Assessment of Information Security in a Diet Centre Business: A Case Study
859