1 of 42

Session 3: Administrative and Policy-Level Threat Detection

Policy gaps, governance failures, and administrative indicators of threats

Justin Pineda CISSP, CISM

Faculty

2 of 42

Pre-Work

3 of 42

4 of 42

5 of 42

Learning Objectives

  • Identify administrative and policy-level threats
  • Detect governance and policy gaps as risk indicators
  • Relate policy failures to real-world security incidents

6 of 42

Motivation Question

If your organization has strong technical controls but weak policies, are you really secure? Why or why not?

7 of 42

What Are Administrative Threats?

  • Non-technical weaknesses
  • Policy, process, and governance failures
  • Often invisible but high impact

8 of 42

Who is responsible for managing administrative threats?

9 of 42

Policy-Level Threats Explained

  • Missing policies
  • Outdated policies
  • Policies not enforced

10 of 42

11 of 42

Why Policy Gaps Matter

  • Enable insider abuse
  • Increase regulatory risk
  • Undermine technical controls

12 of 42

13 of 42

Governance Failures

  • Lack of accountability
  • No clear ownership of security
  • Weak oversight

14 of 42

15 of 42

Administrative Indicators of Threats

  • Repeated audit findings
  • Unclear roles and responsibilities
  • Exceptions becoming normal

16 of 42

Scenario: You are managing a rural bank with increasing number of branches.

Issue: No firewall available but branch needs to open.

17 of 42

Example: Access Control Policy Gap

  • No formal user access review
  • Excessive privileges persist
  • High insider threat risk

18 of 42

19 of 42

Example: Incident Response Policy Gap

  • No documented IR plan
  • Delayed response
  • Regulatory and reputational impact

20 of 42

Shadow IT as an Admin Threat

  • Lack of approval processes
  • Employees bypass policies
  • Data exposure risk

21 of 42

22 of 42

Compliance vs Security

  • Compliance is minimum baseline
  • Policies must reflect real risks

23 of 42

Policy vs Practice

  • Policies exist but ignored
  • Training and enforcement lacking

24 of 42

Third-Party Governance Gaps

  • Weak vendor policies
  • No risk assessments
  • Supply chain exposure

25 of 42

Change Management Failures

  • Unauthorized changes
  • No documentation
  • System instability

26 of 42

Scenario: You, in IT Security, learned that your client-facing web application has a critical security vulnerability that allows attackers to remote access the server. What do you do?

27 of 42

Human Factors in Policy Failures

  • Convenience over compliance
  • Lack of awareness
  • Poor leadership example

28 of 42

Detecting Policy-Level Threats

  • Policy reviews
  • Internal audits
  • Management interviews

29 of 42

Role of Management

  • Tone at the top
  • Resource allocation
  • Accountability

30 of 42

Summary

  • Administrative threats are often overlooked
  • Policy gaps can enable major incidents
  • Governance and enforcement are critical

31 of 42

References

  • ISO/IEC 27001
  • NIST CSF
  • CIS Controls
  • Organizational security policies

32 of 42

Knowledge Check (1/3)

Which of the following is an example of an administrative threat?

  • A. Unpatched operating system vulnerability
  • B. Weak encryption algorithm
  • C. Repeated audit findings with no corrective action
  • D. Malware detected on an endpoint

33 of 42

Knowledge Check (2/3)

Why are policy gaps dangerous even with strong technical controls?

  • A. Policies only apply to compliance audits
  • B. Threat actors ignore technical controls
  • C. Human behavior and decision-making bypass controls
  • D. Technical controls automatically fail over time

34 of 42

Knowledge Check (3/3)

What is a common indicator of governance failure?

  • A. Firewall rule misconfiguration
  • B. No assigned owner for information security risk decisions
  • C. Antivirus signatures not updated
  • D. Failed phishing simulation result

35 of 42

Debrief / Wrapping Up

What did you learn today about administrative and policy-level threats?

36 of 42

Case Example: BSP-Regulated Bank

  • Context:
  • • Mid-sized universal bank under BSP supervision

  • Observed Policy & Governance Gaps:
  • • Access review policy exists but not enforced
  • • IT and Risk ownership unclear
  • • Repeated audit findings year-on-year

  • Threat Indicators:
  • • Privileged access creep
  • • Insider fraud exposure
  • • Regulatory sanctions risk

37 of 42

Case Example: SME (Non-Regulated)

  • Context:
  • • Growing SME with limited security budget

  • Observed Policy & Governance Gaps:
  • • No formal information security policies
  • • Security handled ad hoc by IT admin
  • • No incident response or vendor risk process

  • Threat Indicators:
  • • Shadow IT usage
  • • Delayed breach detection
  • • Business continuity impact

38 of 42

Case Example: University IT Environment

  • Context:
  • • Higher education institution with hybrid learning systems

  • Observed Policy & Governance Gaps:
  • • Weak account lifecycle management
  • • No formal data classification policy
  • • Faculty autonomy overrides security controls

  • Threat Indicators:
  • • Dormant accounts abused
  • • Student data exposure
  • • Ransomware susceptibility

39 of 42

ISO/IEC 27001 Mapping – Administrative Threats

  • Policy & Governance Gaps Mapped to ISO 27001:

  • • Clause 4 – Context of the Organization:
  • – Unclear scope, stakeholders, and regulatory obligations

  • • Clause 5 – Leadership:
  • – Weak tone at the top, unclear accountability

  • • Clause 6 – Planning:
  • – Risks not identified from policy failures

  • • Clause 7 – Support:
  • – Lack of awareness, training, and documentation

  • • Clause 9 – Performance Evaluation:
  • – Repeated audit findings, no management review

  • • Clause 10 – Improvement:
  • – No corrective actions for known gaps

40 of 42

ISO 27001 Annex A – Key Control Areas

  • Relevant Annex A Controls:

  • • A.5 – Information Security Policies
  • • A.6 – Organization of Information Security
  • • A.7 – Human Resource Security
  • • A.8 – Asset Management
  • • A.9 – Access Control
  • • A.15 – Supplier Relationships

  • Administrative Threat Signal:
  • • Controls exist on paper but are not implemented or enforced

41 of 42

NIST Cybersecurity Framework Mapping

  • Administrative & Policy-Level Threat Detection:

  • • IDENTIFY (ID):
  • – ID.GV: Governance, policies, roles, and responsibilities
  • – ID.RA: Risk assessments missing administrative risks

  • • PROTECT (PR):
  • – PR.IP: Policies and procedures not maintained
  • – PR.AT: Lack of awareness and training

  • • DETECT (DE):
  • – DE.CM: No monitoring of policy compliance
  • – DE.DP: Delayed detection due to unclear processes

42 of 42

Case Scenarios – Framework Alignment

  • BSP-Regulated Bank:
  • • ISO 27001: Clauses 5, 6, 9 | Annex A.9, A.15
  • • NIST CSF: ID.GV, ID.RA, PR.IP

  • SME:
  • • ISO 27001: Clauses 4, 6, 7 | Annex A.5, A.6
  • • NIST CSF: ID.GV, PR.AT

  • University IT:
  • • ISO 27001: Clauses 5, 7, 9 | Annex A.7, A.8, A.9
  • • NIST CSF: ID.GV, PR.IP, DE.CM