Risk assesment

anilkumr23
risk_assessment_molugu.xlsx

Sheet1

Threat and Risk Assessment Risk Treatment Plan
Asset ID Common potential points of failure and known vulnerabilities Threat Type Threat sources Consequence Current Risk Likelihood Risk Rating Treatment Option & reference Control Objectives Selection of controls to achieve objectives Consequence Likelihood of Occurrence Residual Risk
People Personnel with low technical skills Availability T1,T2 Moderate Almost certain High Reduce A3 Ensuring all the required resources are available to manage and operate SCADA systems Skill improvement sessions for the staff members Moderate Unlikely Medium
Careless about their personal informations such as user ids, password etc. People write it on stick notes paste on their desks T1,T2 Implementing electronic token generation on staff cell phones to provide access to their systems
short term contract employees T1,T2 Access to business secrets must be restricted to contract employees
People who resigned from the company can reveal the confidential information Confidentiality T1,T2 Moderate Likely High Reduce A1 Sensitive SCADA information must be kept confidential by the people Restrict ex-employee access to company database. Moderate Unlikely Medium
Employees getting help from people outside organization to get their job done can lead to risk of revealing confidential information T1,T2 Role based access system to the registered employees devices
Unaware of consequences if something goes wrong while handling critical things T1,T2 Well documented and circulated response procedures among employees
All the employee activities such as system access, contacts etc should be monitored constantly Integrity T1,T2 Moderate Likely High Reduce A2 Ensuring all the SCADA resources are adequately trained, motivated and are loyal Monitoring systems must be installed and systems logging must be maintained Moderate Unlikely Medium
Unethical way of using organizations software or try to break it using virus or malicious code T1,T2 Restrict use of social media, flashdrive and implement admin restrcition for installing new softwares or changes
Management Various policies related to security issues have to be taken into consideration Integrity T1, T2, T3, T4, T5 Catastrophic Likely Extreme Reduce B2 Providing correct and controlled access to SCADA information Develop security policies based on NIST framework Minor Unlikely Low
No efficiency in work done by the employees T1, T2, T3, T4, T5 Proper performance measurement indicator systems must be implemented
No proper agreements at various levels such as service level agreements T1, T2, T3, T4, T5 Third party consultation for vetting service level agreements (SLAs)
Poor allocation security roles and responsibilities, No proper authorization based on designation Confidentiality T1, T2, T3, T4, T5 Catastrophic Likely Extreme Reduce B1 Providing incident response and readiness processes Developing incidence response plan along with assigned staff member Minor Unlikely Low
Lack of appropiate response to the security issues T1, T2, T3, T4, T5 Developing Incidence handling guide as per NIST standards
On frequent basis proper reviwening all operation procedures, implementations and planning Availability T1, T2, T3, T4, T5 Catastrophic Likely Extreme Reduce B3 Ensuring dedicated and effective Management support for SCADA systems Updating SCADA management policies and procedures Moderate Unlikely Medium
weak and lame personnel in security committee T1, T2, T3, T4, T5 Requiremnt of well defined management controls Implementing Key Performance Indicators & measurements for staff operations
Building/Site management Lack of proper maintainence handeling Integrity T1, T2 Minor Possible Medium Reduce C2 To prevent loss to site and infrastructure Develop incident response and emergency procedures Minor Unlikely Low
Natural disasters T1, T2 Develop & circulate disaster reovery and business continuity plans (BCP)
losses and harm caused to personnel and service due to Environmental hazards Availability T1, T2 Moderate Unlikely Medium Reduce C3 To ensure safety of assets and normal operations after interruption to the SCADA operations Develop Health Safety & Environment (HSE) Policy and the establisment must be able to with stand any inclement weather Minor Unlikely Low
No proper planning and designing T1, T2 Develop disater management plan and use of uninterruptible power supply (UPS)
No proper security for property and infrastructure T1, T2 Defining security measures for establishment
Environment in office not secured or less secured Confidentiality T1, T2 Minor Possible Medium Reduce C1 To prevent interruption to business processes and to avoid compromise of assets Required protection systems against fire, wind, water and snow must be implemented Minor Unlikely Low
Information Management Constantly monitoriing and auditning the softwares Integrity T1, T2 Moderate Almost Certain High Reduce D2 To ensure proper operation of systems using information monitoring Periodically updating all the software applications Moderate Unlikely Medium
Strong Password policy should be entact and enforced T1, T2 Implementing electronic token generation for access to individual systems
Ex-employees access id and password should be regularly monitered to avoid un-authorized and illegally actvities T1, T2 Disabling ex-employees access rights
Access control should be limted to concerned people to protect un authorized access T1, T2 Access to business secrets will be limited only to the concerned persons and information must be encrypted
Any software update should be done from licensed copies only Availability T1, T2 Moderate Almost Certain High Reduce D3 Information processes maintains systems availability Patching of the software with regual updated from the licensed providers Moderate Unlikely Medium
Installing inappropriate hardware/software or without proper knowledge T1, T2 Enabling systems administration restriction on all systems in the network
Recovery plan or devices should be continously monitered T1, T2 Regularly updating the recovery plan with lessons learned documents
unorganized and inadequacy in data management may leads to data breach Confidentiality T1, T2 Moderate Almost Certain High Reduce D1 Ensuring access control to SCADA systems Efficient operating manuals will maintain data properly Moderate Unlikely Medium
Policies and procedures should be up to data and documented T1, T2 Periodical reviews and updating all the operating procedures and manuals
T1, T2
Communication and Network Mis interpretation of information may results in breach of the data Confidentiality T1, T2 Minor Likely Medium Reduce E1 To protect the SCADA information during transmission of data Prescribed encryption methods must be implemented to secure data Minor Unlikely Low
loop holes in policies, rules of network equipment. T1, T2 Use of well documented SCADA operating procedures and device manuals
weak segment network leads to network valunerability T1, T2 Perform vulnerability assessments on all access points into the SCADA network
Unprotected wireless channels grant unapproved access, network breach. T1, T2 Detecting unauthorized user in the network using intrusion detection systems (IDS)
Unethical hacking, cyber attacks, interruptions in data transmissions Integrity T1, T2 Moderate Almost Certain High Reduce E2 To secure network configurations Applying encryption protocols like ISM Cryptography, ISO and NIST standards Moderate Unlikely Medium
No proper time to time network activity analysis T1, T2 Implementing of systems logging for detecting any unauthorized access or activity
Eradicating irrelevant information Availability T1, T2 Moderate Almost Certain High Reduce E3 Maintaining network connectivity Applying dataming techniques Moderate Unlikely Medium
Obstruction from different devices T1, T2 Conducting systems integration testing to identify any compactibility issues
SCADA Application Software Lack of new technology Integrity T1, T2 Major Likely High Reduce F2 To maintain all the systems and software updates Regular updating of old SCADA system with new devices Moderate Unlikely Medium
Use of licensed software T1, T2 Buying the licensed software from the certified software vendor
Challenges in maintaining the modern software T1, T2 Proper contracts must be made with the software vendors for updating the patches
Network crash Availability T1, T2 Major Likely High Reduce F3 To ensure effective change management Acceptance testing must be carried out before installing new devices to prevent crash Moderate Unlikely Medium
User fails to cope up with the required changes T1, T2 Required training must be provided to the staff for any change management
Lack of knowledge of the new introduced software T1, T2 Thorough working process and trainig needs to be given to the staff
Difficulty in software maintenance T1, T2 Developing prescribed maintenace manuals with reference to industry standards
Problem faced through stern security Confidentiality T1, T2 Moderate Likely High Reduce F1 To ensure security mechanisms in place to withstand unauthorised access attempts Conducting acceptance testing to verify compactibility with security systems Moderate Unlikely Medium
SCADA Hardware including operating System Application Inconsistency Integrity T1, T2 Moderate Likely High Reduce G2 To ensure proper configuration Configuration management and control procedures to ensure proper working Moderate Unlikely Medium
Management failure Confidentiality T1, T2, T3, T4 Moderate Almost Certain High Reduce G1 To ensure resilience against foreign access control Implementing change management process and control strategies Moderate Unlikely Medium
possibility of system accessible by many T1, T2 Enabling role based access controls
Improper access codes T1, T2 Implementing electronic token systems for access
Failure of equipment Availability T1, T2 Moderate Almost Certain High Reduce G3 To ensure normal operation after any disruption Stocking up of spare devices for any equipment failure Minor Possible Medium
Lack of extra quipment T1, T2 Making necessary arrangements for any extra equipments
Power failures T1, T2 Using UPS and backup diesel generators
No proper monitoring and planning T1, T2 Implementing inventory management for all the hardware and software components
SCADA Field Devices Failure in security hardening Confidentiality T1, T2 Moderate Likely High Reduce H1 To prevent unauthorised access to network Use of encrypted data communication systems Minor Unlikely Medium
Having same default security configuration for every system T1, T2 Applying network segmentation to isolate one system from the other
Using older username and password T1, T2 Deactivation of default old accounts and changing it once every month
physicial damage Availability T1, T2 Moderate Almost Certain High Reduce H3 To ensurecontrolling of devices and services Using solid framework for rack and stack of devices Minor Unlikely Medium
access to the service T1, T2 Generation of electronic token for user access
Hardware and Software application Integrity T1, T2 Minor Likely Medium Reduce H2 To ensure stability of devices Regular updating and servicing of devices and applications Minor Unlikely Low
use of other devices for operating T1, T2 Conducting acceptance testing prior to use of any device
Supporting Utilities power deficiency Integrity T1, T2 Moderate Likely High Reduce I2 Ensuring normal operation in the event of power interruptions Power must be supplied by use of UPS, solar, wind and backup diesel generators Minor Unlikely Medium
backup power defieciency Availability T1, T2 Major Likely High Reduce I3 Preventing disruption to SCADA operations during power failure. Having portable power supply arrangement from market vendors Moderate Unlikely Medium
Capacity planning T1, T2 Establishing a 5 day power back systems using combination of UPS, solar and diesel generators
Damage to utilities which are used in support T1, T2 Appropriate power conditioning devices must be used to protect devcies
Breach of confidentiality Confidentiality T1, T2 Minor Possible Medium Reduce I1 Protecting SCADA systems from compromise during power failure Employing intrusion detection and protection systems (IDPS) Minor Rare Low