Meet with your team (and other teams if you have formed a multi-industry council) to review the Round 2 outcomes, reports, and debrief from the CISO. Collaborate on what new decisions need to be made.

profileMichelle_Michy
20200606170510groupnz_cyb670_p4_aar_1_06_06_201.docx

Running Head: AFTER ACTION REPORT #1

AFTER ACTION REPORT #1 33

After Action Report #1

Sandra Jones, Mathew Trageser, Earl Freeman,

Bradley Dmuchowski

CYB 670

University of Maryland University College

Contents Introduction 3 Stakeholders 3 Identification of Security Risks / Methods of Mitigation 4 Rationale 17 Assessing Effectiveness of Controls 18 Results 19 Appendix 1: Debrief Report 21 Appendix 2: Outcome Report 21 Appendix 3: Hytema Specific Debrief Report 21

Introduction

Hytema is dedicated to providing defense contracting services and products. As one of the world’s largest defense contractors, we feel the need to provide for both the Department of Defense as well as the stakeholders of our company. Hytema constantly seeks to defend the interests of our customers while spending our resources in a way that doesn’t waste resources or limit return on investment. Recent cybersecurity incidents have tested the organizations decisions regarding cybersecurity policies and controls. This report captures both the decisions regarding cybersecurity as well as the outcomes of those decisions.

The recent attacks on the cybersecurity of Hytema came in the form of criminal hacking as well as a Distributed Denial of Service Attack (DDoS). The criminal hacking attempted to access Hytema servers using multiple vulnerabilities across the network. The DDoS attacks utilized “bot armies” or large groups of attacking machines to flood the Hytema network with traffic in order to overload service and bring them down. The decision making of Hytema was effective in responding to these attacks but not perfect. Outcomes of these decisions will be used to inform later decision making. Hytema is committed to providing high quality defense products and services while protecting the interests of its stakeholders.

Stakeholders

The largest stakeholder for Hytema is the Department of Defense. Last year, 83 percent of Hytema’s sales came from military sales. This makes the largest stakeholder the US government and the American tax payer. These sales were across several sectors to include aeronautics, electronic systesm, information systems and solutions, and space systems. Hytema does have some foreign stakeholders with 3 percent of sales coming from foreign government contracts. Additionally, 29% of sales are to commercial and other contractors. Hytema also has a duty to its investors and lenders.

Identification of Security Risks / Methods of Mitigation

1. Backup

a. Raid Levels

i. Methods of Mitigation: 0, 1, 5, 6

ii. Choice:

2. Data Encryption

a. Level of Encryption

i. Methods of Mitigation: No encryption, File, Folder, Drive

ii. Choice:

b. Encryption strength in bits

i. Methods of Mitigation: 32 bits, 64 bits, 128 bits

ii. Choice:

3. Load Management

a. DDoS protection through SYN binding

i. Methods of Mitigation: Disable, Enable

ii. Choice:

b. HTTP security through load balancing

i. Methods of Mitigation: Disable, Enable

ii. Choice:

4. Patch Management

a. Frequency of patch management

i. Methods of Mitigation: Critical updates only, Critical and important updates, All updates

ii. Choice:

b. Degree of patch testing prior to installation

i. Methods of Mitigation: Low, Medium, High

ii. Choice:

c. Trustworthiness of patch

i. Methods of Mitigation: Unofficial, Trusted, Official

ii. Choice:

5. Role Based Access Control

a. Degree of role-based access control

i. Methods of Mitigation: Low, Medium, High

ii. Choice:

6. Virtualization OR Cloud Computing

a. Choose virtualization or cloud computing

i. Methods of Mitigation: Virtualization, Cloud computing

ii. Choice:

7. If Virtualization Chosen:

a. Degree of Virtualization

i. Methods of Mitigation: Limited, Significant, Full

ii. Choice:

b. Degree of isolation of network

i. Methods of Mitigation: Minor, Medium, Complete

ii. Choice:

c. Traffic monitoring on network

i. Methods of Mitigation: Limited, Significant, Full

ii. Choice:

8. If Cloud Computing Chosen

a. Cloud Hosting Model

i. Methods of Mitigation: Private, Hybrid, Public

ii. Choice:

9. Firewall

a. Filtering Strictness

i. Methods of Mitigation: Low, Medium, Medium-high, High

ii. Choice:

10. DNS Redundancy

a. DNS Server Redundancy

i. Methods of Mitigation: Yes, No

ii. Choice:

b. Split DNS Topology

i. Methods of Mitigation: Yes, No

ii. Choice:

11. Database Security

a. Frequency of forcing password changes in days

i. Methods of Mitigation: 15, 30, 60, 90

ii. Choice:

b. Degree of separation of roles for admin and operator roles

i. Methods of Mitigation: None, Limited, Complete

ii. Choice:

c. Control privileges

i. Methods of Mitigation: Restricted, Distributed

ii. Choice:

d. OS Services and associated ports

i. Methods of Mitigation: Disable, Enable

ii. Choice:

e. Database honeypots

i. Methods of Mitigation: Disable, Enable

ii. Choice:

12. IDPS

a. Type of intrusion detection system to install

i. Methods of Mitigation: Network-based intrusion detection, Host-based Intrusion Detection (HIDS), Both

ii. Choice:

b. Class of honeypot to deploy

i. Methods of Mitigation: Production honeypot, Research honeypot

ii. Choice:

c. Strength of honeypot to deploy

i. Methods of Mitigati0on: Pure honeypot, Low interaction honeypot, High interaction honeypot

ii. Choice:

13. Hiring and Employee Policy

a. IT team size

i. Methods of Mitigation: Less than average, Average, More than average

ii. Choice:

b. Full-time employees as a percentage of the workforce

i. Methods of Mitigation: All, 0.9, 0.8

ii. Choice:

c. Hiring by average experience in years

i. Methods of Mitigation: 3, 5, 7, 8, 9

ii. Choice:

d. Forced rotation of employees

i. Methods of Mitigation: Disable, Enable

ii. Choice:

e. Forced vacation for employees

i. Methods of Mitigation: Disable, Enable

ii. Choice:

14. Advisory Subscription and Federal Help

a. Degree of advisory referral

i. Methods of Mitigation: None, Limited

ii. Choice:

b. Reliance on federal government support

i. Methods of Mitigation: None, For critical issues only, Ongoing

ii. Choice:

15. Training Incentives

a. Average compensation bonus as a fraction of technical certification fees

i. Methods of Mitigation: 25% of fees, 50% of fees, 75%of fees, 100% of fees

ii. Choice:

b. Link training outcomes to promotion

i. Methods of Mitigation: Yes, No

ii. Choice:

c. Link training outcomes to evaluation

i. Methods of Mitigation: Yes, No

ii. Choice:

16. Training and Auditing

a. Frequency of physical audits of the equipment

i. Methods of Mitigation: Every three months, Every six months, Once a year

ii. Choice:

17. Business Continuity Planning

a. Degree of IT data storage redundancy

i. Methods of Mitigation: Low, Medium, High

ii. Choice:

b. Degree of IT network redundancy

i. Methods of Mitigation: Low, Medium, High

ii. Choice:

c. Levels of power backup redundancy

i. Methods of Mitigation: 1, 2, 3

ii. Choice:

d. Number of backup sites

i. Methods of Mitigation: 1, 2, 3

ii. Choice:

e. Number of redundant backup communication links

i. Methods of Mitigation: 1, 2, 3

ii. Choice:

f. Policy review frequency in months

i. Methods of Mitigation: 3, 6, 9, 12

ii. Choice:

18. Information Sharing

a. Degree of information sharing on attacks

i. Methods of Mitigation: High – full disclosure, Medium – non-sensitive disclosure, Low – no disclosure

ii. Choice:

b. Degree of non-crisis information sharing

i. Methods of Mitigation: High – full disclosure, Medium – non-sensitive disclosure, Low – no disclosure

ii. Choice:

19. Emergency Bypass Policy

a. Response to violations of typical separation of duties protocol

i. Methods of Mitigation: Not allowed, Permitted with limitations, Allowed

ii. Choice:

b. Violation penalties

i. Methods of Mitigation: Focus on warnings, Focus on fines, Focus on suspensions, Focus on terminations

ii. Choice:

20. Information Sharing Policy

a. No. of people in groups to overlook and enforce internal information sharing

i. Methods of Mitigation: 2, 3, 4, 5, 6

ii. Choice:

b. Internal information sharing by role-based access control

i. Methods of Mitigation: Strictly need to know, Limited access, Open system

ii. Choice:

c. Degree of external information sharing

i. Methods of Mitigation: Strictly need to know, Limited access, Open system

ii. Choice:

d. Frequency of disclosure for Infragard communication in days

i. Methods of Mitigation: 7 days, 14 days, 21 days, 28 days

ii. Choice:

e. Violation Penalties

i. Methods of Mitigation: Warnings, Fines, Suspensions, Terminations

ii. Choice:

21. Breach Notification Policy

a. Degree of openness of breach notification

i. Methods of Mitigation: All incidents, Critical and significant incidents, Only critical incidents, None of the incidents

ii. Choice:

b. Investigative agencies to call in for major security breaches

i. Methods of Mitigation: Private investigatoes, Forensic investigators, CERT, FBI/NSA

ii. Choice:

c. Violation penalties

i. Methods of Mitigation: Focus on warnings, Focus on fines, Focus on suspensions, Focus on terminations

ii. Choice:

22. Information Privacy Policy

a. Appoint a dedicated privacy officer

i. Methods of Mitigation: Yes, No

ii. Choice:

b. Degree of information and record retention

i. Methods of Mitigation: Critical information, operational information, All information

ii. Choice:

c. Violation penalties

i. Methods of Mitigation: Focus on warnings, Focus on fines, Focus on suspensions, Focus on terminations

ii. Choice:

23. General Access Policies

a. Degree of freedom given to employees regarding communications over the Internet

i. Methods of Mitigation: Restricted, Time-limited, Free

ii. Choice:

b. Degree of freedom over browsing non-business sites

i. Methods of Mitigation: Restricted, Time-limited, Free

ii. Choice:

c. Degree of logging of Internet access and other systems actions and accesses

i. Methods of Mitigation: None, Limited actions, Critical system access only, All actions

ii. Choice:

d. Number of permitted login attempts

i. Methods of Mitigation: 3, 5, 7

ii. Choice:

e. Password validity in days

i. Methods of Mitigation: 15, 30, 45

ii. Choice:

f. Password length requirements

i. Methods of Mitigation: 4, 6, 8

ii. Choice:

g. Non-use of prior passwords

i. Methods of Mitigation: 1, 3, 6

ii. Choice:

h. Violation Penalties

i. Methods of Mitigation: Focus on warnings, Focus on fines, Focus on suspensions, Focus on terminations

ii. Choice:

24. Physical Security

a. Physically isolate rooms containing important infrastructure

i. Methods of Mitigation: Free access, Limited access, Restricted access

ii. Choice:

b. Restricting physical access through role-based access control

i. Methods of Mitigation: Free access, Limited access, Restricted access

ii. Choice:

c. Degree of access given to visitors

i. Methods of Mitigation: Free access, Accompanied limited access, Accompanied free access, Accompanied limited access, Restricted access

ii. Choice:

d. Violation penalties

i. Methods of Mitigation: Focus on warnings, Focus on fines, Focus on suspensions, Focus on termination

ii. Choice:

25. Remote Access Policy

a. Degree of remote access by employee grade

i. Methods of Mitigation: Executive management only, Upper management, Middle management, All professional staff members

ii. Choice:

b. Access privileges permitted

i. Methods of Mitigation: Low - read only, Medium – read/write, High – read/write/delete, Very high – administrator level

ii. Choice:

c. Violation penalties

i. Methods of Mitigation: Focus on warnings, Focus on fines, Focus on suspensions, Focus on termination

ii. Choice:

26. Authorized Software Policy

a. Type of software permitted for use by employees

i. Methods of Mitigation: Freeware, Games, Open-source, Approved software

ii. Choice:

b. Software evaluation frequency in months

i. Methods of Mitigation: 6, 12, 18

ii. Choice:

c. Violation penalties

i. Methods of Mitigation: Focus on warnings, Focus on fines, Focus on suspensions, Focus on terminations

ii. Choice:

27. Systems Development Testing

a. Intensity of quality assurance testing

i. Methods of Mitigation: Low, Medium, High

ii. Choice:

b. Degree of reliance on external vendor

i. Methods of Mitigation: Usability and other minor testing, Supplementary testing, Comprehensive testing

ii. Choice:

28. Antivirus Policy

a. Quality of antivirus solution used

i. Methods of Mitigation: Baseline, Strong, State-of-the-art

ii. Choice:

b. Frequency of scans

i. Methods of Mitigation: Multiple times per day, Once daily, Once per week, Once per month

ii. Choice:

c. Frequency of patch updates

i. Methods of Mitigation: Always once release, Only for major and critical updates, Only for critical updates

ii. Choice:

29. Insurance Policy

a. Degree of Insurance used against a cyberattack

i. Methods of Mitigation: Yes, No

ii. Choice:

Rationale

The selections were made by balancing impact to the profitability of the company with the impacts to the organization if a risk was exploited. When there was an industry best practice defined, Hytema used it as the standard. When no standard was available the controls were reviewed on a case by case basis to determine what potential impacts, they would have to the organization. Two factors were taken into consideration when determining whether they would impact the bottom line of the organization. The first factor was the cost of implementation and the second was the potential cost savings if the risk was exploited in conjunction with the likelihood of the exploitation. Considering that there was actionable intelligence that a DDoS attack and criminal hacking might happen, the likelihood of these attacks were considered higher.

With these things in mind, some controls stand out as examples or worthy of discussion to illuminate the thinking of the cyber security team. Raid levels are an example where an industry best practice or recommendation was taken advantage of. A Raid 0 configuration creates significant risk and is not recommended by industry. Restricting physical access to rooms was another example of an industry standard that affected the potential mitigations available. It is not recommended to allow free access to IT rooms since some hardware, for example routers and switches, can be reset or affected by a manual connection. This makes physical access a particularly impactful situation. Another example of industry best practice affecting decision making was the data encryption setting. Having no encryption was not an option, especially considering that the stakeholders included the Department of Defense. In order to meet the standards of the US government, information that is considered to risk national security was maintained at a level required of all US Government information.

Other settings posed more variability in the potential outcome or were less straight forward in their potential impacts. In these cases, preference was placed on using the lowest possible setting to ensure security while saving the organization money in the short and long term. An example of this would be the degree of freedom given to employees to browse non-business sites. This would increase employee morale but no not necessarily affect the bottom line significantly or decrease security significantly. This went for the degree of freedom given to employees regarding communication over the internet as well. These variables were selected to be at as low of a level as possible to allow security with preference placed on retaining company funds as opposed to having a higher level of security.

Assessing Effectiveness of Controls

Reviewing Appendix 1 Dashboard shows that Hytema did not do the worst of all sectors, scoring a 93.6 compared to DTL Power’s 90.8. However, all other teams scored higher after these attacks than DTL power. The federal government faired the best with a 99.9 overall score. When looking at the service objective, Hytema scored a 114 placing it in the middle of the pack of five organizations with the top score being a 130 (DTL Power) and the bottom being a 94 (Federal Government).

Reviewing the individual areas in Appendix 3, its evident that the internal security index was the most negatively affected by decisions. With a score of 82, this demonstrates a need to place more funds into the controls that affect this area. With a score of 114, the downtime was most positively affected by the decisions made by the Hytema cybersecurity team. This outlier could account for some significant dragging down of the overall score. The next lowest controls were customer satisfaction and profitability. Both of these areas were scored as a 91. Since profitability was low it alludes to the likelihood that money was spent on controls that were not directly impactful on the DDoS and criminal hacking. More time should be spent ensuring that the controls chosen for higher levels of spending are directly related to the potential attacks against the system.

A significant number of factors remained at the 100-point mark or near it indicating that the level of controls chosen were appropriate in relation to the threat. 12 of the 25 factors remained at 100 or within two points of the baseline (98 to 102). Some of these areas included performance, system resiliency and the technical security index. This consistent level of performance with the baseline implies that controls relating to these factors were at the appropriate level for this particular threat and similar threats should be met with similar controls.

Results

The chosen level of controls didn’t achieve the desired levels of results but didn’t hugely impact the organization. It’s obvious that the aversion to spending from the company budget put too much emphasis on saving money and not enough on security. Increasing security settings will help raise the overall score with acceptable loses to the budget. Based on the performance in comparison to other teams/sectors its important to increase the level of spending to help prevent lose of points during future potential cybersecurity incidents.

Appendix 1: Debrief Report

Included as separate attachment: Instructor_Debrief_319_332-1.xlsx

Appendix 2: Outcome Report

Included as separate attachment: Hytema Defense Round 1.pdf

Appendix 3: Hytema Specific Debrief Report

Included as separate attachment: Hytema Defense Round 1.xlsx