1 of 34

By: Mohammad Shoab

Security Management and Risk Assessment

2 of 34

Overview

  • Security requirements means asking
    • what assets do we need to protect?
    • how are those assets threatened?
    • what can we do to counter those threats?

  • IT security management answers these
    • determining security objectives and risk profile
    • perform security risk assessment of assets
    • select, implement, monitor controls

2

Professional Cybersecurity

Department of Computer Science

3 of 34

Security Management

Security Management: a process used to achieve and maintain appropriate levels of confidentiality, integrity, availability, accountability, authenticity and reliability. IT security management functions include:

∙ organizational IT security objectives, strategies and policies

∙ determining organizational IT security requirements

∙ identifying and analyzing security threats to IT assets

∙ identifying and analyzing risks

∙ specifying appropriate safeguards

∙ monitoring the implementation and operation of safeguards

∙ developing and implement a security awareness program

∙ detecting and reacting to incidents

3

Professional Cybersecurity

Department of Computer Science

4 of 34

ISO 27000 Security Standards

4

Professional Cybersecurity

Department of Computer Science

5 of 34

IT Security Management Process

5

Professional Cybersecurity

Department of Computer Science

6 of 34

Plan - Do - Check – Act (Deming Cycle)

establish policy; define

objectives and processes

implement and operate

policy, controls, processes

assess and measure

and report results

take corrective and

preventative actions

(based on audits)

6

Professional Cybersecurity

Department of Computer Science

7 of 34

Organizational Context and Security Policy

  • First examine organization’s IT security:
    • objectives - wanted IT security outcomes
    • strategies - how to meet objectives
    • policies - identify what needs to be done

  • Maintained and updated regularly
    • using periodic security reviews
    • reflect changing technical/risk environments

7

Professional Cybersecurity

Department of Computer Science

8 of 34

Security Policy: Topics to Cover

  • Needs to address:
    • scope and purpose including relation of objectives to business, legal, regulatory requirements
    • IT security requirements
    • assignment of responsibilities
    • risk management approach
    • security awareness and training
    • general personnel issues and any legal sanctions
    • integration of security into systems development
    • information classification scheme
    • contingency and business continuity planning
    • incident detection and handling processes
    • how when policy reviewed, and change control to it

8

Professional Cybersecurity

Department of Computer Science

9 of 34

Management Support

  • IT security policy must be supported by senior management
  • Need IT security officer
    • to provide consistent overall supervision
    • manage process
    • handle incidents

  • Large organizations needs IT security officers on major projects/teams
    • manage process within their areas

9

Professional Cybersecurity

Department of Computer Science

10 of 34

Security Risk Assessment

  • Critical component of process
    • else may have vulnerabilities or waste money
  • Ideally examine every asset vs risk
    • not feasible in practice
  • Choose one of possible alternatives based on organization’s resources and risk profile
    • baseline
    • informal
    • formal
    • combined

10

Professional Cybersecurity

Department of Computer Science

11 of 34

Baseline Approach

  • Use “industry best practice”
    • easy, cheap, can be replicated
    • but gives no special consideration to org
    • may give too much or too little security
  • Implement safeguards against most common threats
  • Baseline recommendations and checklist documents available from various bodies
  • Alone only suitable for small organizations

11

Professional Cybersecurity

Department of Computer Science

12 of 34

Informal Approach

  • Conduct informal, pragmatic risk analysis on organization’s IT systems
  • Exploits knowledge and expertise of analyst
  • Fairly quick and cheap
  • Does address some org specific issues
  • Some risks may be incorrectly assessed
  • Skewed by analysts views, varies over time
  • Suitable for small to medium sized orgs

12

Professional Cybersecurity

Department of Computer Science

13 of 34

Detailed Risk Analysis

  • Most comprehensive alternative
  • Assess using formal structured process
    • with a number of stages
    • identify likelihood of risk and consequences
    • hence have confidence controls appropriate
  • Costly and slow, requires expert analysts
  • May be a legal requirement to use
  • Suitable for large organizations with IT systems critical to their business objectives

13

Professional Cybersecurity

Department of Computer Science

14 of 34

Combined Approach

  • Combines elements of other approaches
    • initial baseline on all systems
    • informal analysis to identify critical risks
    • formal assessment on these systems
    • iterated and extended over time
  • Better use of time and money resources
  • Better security earlier that evolves
  • May miss some risks early
  • Recommended alternative for most orgs

14

Professional Cybersecurity

Department of Computer Science

15 of 34

Detailed Risk Analysis Process

15

Professional Cybersecurity

Department of Computer Science

16 of 34

Establish Context

  • Determine broad risk exposure of org
    • related to wider political/social environment
    • legal and regulatory constraints
  • Specify organization’s risk appetite
  • Set boundaries of risk assessment
    • partly on risk assessment approach used
  • Decide on risk assessment criteria used

16

Professional Cybersecurity

Department of Computer Science

17 of 34

Asset Identification

  • Identify assets
    • “anything which needs to be protected”
    • of value to organization to meet its objectives
    • tangible or intangible
    • in practice try to identify significant assets
  • Draw on expertise of people in relevant areas of organization to identify key assets
    • identify and interview such personnel
    • see checklists in various standards

17

Professional Cybersecurity

Department of Computer Science

18 of 34

Terminology

18

Professional Cybersecurity

Department of Computer Science

19 of 34

Threat Identification

  • To identify threats or risks to assets ask
    • who or what could cause it harm?
    • how could this occur?
  • Threats are anything that hinders or prevents an asset providing appropriate levels of the key security services:
    • confidentiality, integrity, availability, accountability, authenticity and reliability
  • Assets may have multiple threats

19

Professional Cybersecurity

Department of Computer Science

20 of 34

Threat Sources

  • Threats may be
    • natural “acts of god”
    • man-made and either accidental or deliberate
  • Should consider human attackers
    • motivation
    • capability
    • resources
    • probability of attack
    • deterrence
  • Any previous history of attack on org

20

Professional Cybersecurity

Department of Computer Science

21 of 34

Threat Identification

  • Depends on risk assessors experience
  • Uses variety of sources
    • natural threat chance from insurance stats
    • lists of potential threats in standards, IT security surveys, info from governments
    • tailored to organization’s environment
    • and any vulnerabilities in its IT systems

21

Professional Cybersecurity

Department of Computer Science

22 of 34

Vulnerability Identification

  • Identify exploitable flaws or weaknesses in organization’s IT systems or processes
  • Hence determine applicability and significance of threat to organization
  • Need combination of threat and vulnerability to create a risk to an asset
  • Again can use lists of potential vulnerabilities in standards etc.

22

Professional Cybersecurity

Department of Computer Science

23 of 34

Analyze Risks

  • Specify likelihood of occurrence of each identified threat to asset given existing controls
    • management, operational, technical processes and procedures to reduce exposure of org to some risks
  • Specify consequence should threat occur
  • Hence derive overall risk rating for each threat

risk = probability threat occurs x cost to organization

  • In practice very hard to determine exactly
  • Use qualitative not quantitative, ratings for each
  • Aim to order resulting risks in order to treat them

23

Professional Cybersecurity

Department of Computer Science

24 of 34

Determine Likelihood

24

Professional Cybersecurity

Department of Computer Science

25 of 34

Determine Consequence

25

Professional Cybersecurity

Department of Computer Science

26 of 34

Determine Resultant Risk

Consequences

Likelihood

Doomsday

Catastrophic

Major

Moderate

Minor

Insignificant

Almost

Certain

E

E

E

E

H

H

Likely

E

E

E

H

H

M

Possible

E

E

E

H

M

L

Unlikely

E

E

H

M

L

L

Rare

E

H

H

M

L

L

Risk Level

Description

Extreme (E)

Will require detailed r

esearch and management planning at an

executive/director level. Ongoing planning and monitoring will be required

with regular reviews. Substantial adjustment of controls to manage the

risk are expected, with costs possibly exceeding original forecasts.

H

igh (H)

Requires management attention, but management and planning can be left

to senior project or team leaders. Ongoing planning and monitoring with

regular reviews are likely, though adjustment of controls are likely to be

met from within existing resources

Medium (M)

Can be managed by existing specific monitoring and response procedures.

Management by employees is suitable with appropriate monitoring and

reviews.

Low (L)

Can be managed through routine procedures.

26

Professional Cybersecurity

Department of Computer Science

27 of 34

Document in Risk Register�and Evaluate Risks

27

Professional Cybersecurity

Department of Computer Science

28 of 34

Risk Treatment

28

Professional Cybersecurity

Department of Computer Science

29 of 34

Risk Treatment Alternatives

  • Risk acceptance: accept risk (perhaps because of excessive cost of risk treatment)
  • Risk avoidance: do not proceed with the activity that causes the risk (loss of convenience)
  • Risk transfer: buy insurance; outsource
  • Reduce consequence: modify the uses of an asset to reduce risk impact (e.g., offsite backup)
  • Reduce likelihood: implement suitable controls

29

Professional Cybersecurity

Department of Computer Science

30 of 34

Case Study: Silver Star Mines

  • Fictional operation of global mining company
  • Large IT infrastructure
    • both common and specific software
    • some directly relates to health & safety
    • formerly isolated systems now networked
  • Decided on combined approach
  • Mining industry less risky end of spectrum
  • Management accepts moderate or low risk

30

Professional Cybersecurity

Department of Computer Science

31 of 34

Assets

  • Reliability and integrity of SCADA nodes and net
  • Integrity of stored file and database information
  • Availability, integrity of financial system
  • Availability, integrity of procurement system
  • Availability, integrity of maintenance/production system
  • Availability, integrity and confidentiality of mail services

31

Professional Cybersecurity

Department of Computer Science

32 of 34

Threats & Vulnerabilities

  • Unauthorized modification of control system
  • Corruption, theft, loss of info
  • Attacks/errors affecting procurement system
  • Attacks/errors affecting financial system
  • Attacks/errors affecting mail system
  • Attacks/errors maintenance/production affecting system

32

Professional Cybersecurity

Department of Computer Science

33 of 34

Risk Register

33

Professional Cybersecurity

Department of Computer Science

34 of 34

Thank You

34

Professional Cybersecurity

Department of Computer Science