Answer Minimum in 300 words. Should be in APA format.

profilelucky1091
ch05.pptx

IT for Management: On-Demand Strategies for Performance, Growth, and Sustainability

Eleventh Edition

Turban, Pollard, Wood

Chapter 5

Cybersecurity and Risk Management Technology

Learning Objectives (1 of 5)

2

Copyright ©2018 John Wiley & Sons, Inc.

The Face and Future of Cyberthreats

Figure 5.1: Number of 2016 U.S. Data Breaches by Industry Sector. The number of cyberthreats in which data records have been stolen by hackers has increased at an alarming rate.

3

Copyright ©2018 John Wiley & Sons, Inc.

3

Cyberthreat Terminology

Cyberthreat is a threat posed by means of the Internet (a.k.a. cyberspace) and the potential source of malicious attempts to damage or disrupt a computer network, system, or application.

Vulnerability is a gap in IT security defenses of a network, system, or application that can be exploited by a threat to gain unauthorized access.

Incident is an attempted or successful unauthorized access to a network, system, or application; unwanted disruption or denial of service; unauthorized use of a system for processing or storage of data; changes to a system without the owner’s knowledge, instruction, or consent.

Data Breach is the successful retrieval of sensitive information by an individual, group, or software system.

4

Copyright ©2018 John Wiley & Sons, Inc.

Figure 5.2 The three objectives of data and information systems security

5

Copyright ©2018 John Wiley & Sons, Inc.

2016 Biggest Data Breaches Worldwide

Company Type of Breach Records Breached
Anthem Insurance Identity theft—healthcare records 78.8 million
Turkish General Directorate Identity theft—malicious outsider (government agency) 50 million
Korean Pharmaceutical Info. Center Identity theft—malicious insider 43 million
U.S. Office of Personnel Management Personally Identifiable Information (PII) (government agency) 22 million
Experian Identity theft—malicious outsider (credit bureau) 15 million

6

Copyright ©2018 John Wiley & Sons, Inc.

Major Sources of Cyberthreats (1 of 2)

Unintentional cyberthreats can be caused by

Human error (a majority of internal security issues)

Poorly designed systems

Faulty programming

Neglecting to change passwords

Unaware users

Environmental hazards

Natural disasters

Faulty HVAC systems

Computer systems failure

Poor manufacturing or maintenance

7

Copyright ©2018 John Wiley & Sons, Inc.

Major Sources of Cyberthreats (2 of 2)

Some intentional forms of cyberthreats are:

Hacking

Phishing

Crimeware

Distributed Denial of Service (DDoS)

Insider and Privilege Misuse

Physical Theft

8

Copyright ©2018 John Wiley & Sons, Inc.

Intentional Cyberthreats: Hacking

Hacking is broadly defined as intentionally accessing a computer without authorization or exceeding authorized access. There are three types of hackers.

White Hat: Computer security specialist who breaks into protected systems and network to test and assess their security.

Black Hat: Person who attempts to find computer security vulnerabilities and exploit them for personal and/or financial gain, or other malicious reasons.

Gray Hat: Person who may violate ethical standards or principles, but without the malicious intent ascribed to black hat hackers.

Hacktivist: is short for hacker-activist, or someone who performs hacking to promote awareness, or otherwise support a social, political, economic, or other cause.

9

Copyright ©2018 John Wiley & Sons, Inc.

Intentional Cyberthreats: Spear Phishing

Spear phishers often target select groups of people with something in common

Trick user into opening an infected email

Emails sent that look like the real thing

Confidential information extracted through seemingly legitimate website requests for passwords, user IDs, PINs, account numbers, and so on.

10

Copyright ©2018 John Wiley & Sons, Inc.

Intentional Cyberthreats: Crimeware

Malware refers to hostile or intrusive software, including computer viruses, rootkits, worms, Trojan horses, ransomware, and other malicious programs used to disrupt computer or mobile operations, gather sensitive information, gain access to private computer systems.

Spyware is tracking software that is not designed to intentionally damage or disable a system but to monitor or track activities.

Adware is software that embeds advertisement in the application

Ransomware is a type of malware that is designed to block access to a computer system until a sum of money has been paid.

11

Copyright ©2018 John Wiley & Sons, Inc.

Intentional Cyberthreats: Variants

Malware Reinfections, Signatures, Mutations, and Variants

Malware is captured in backups or archives. Restoring the infected backup or archive also restores the malware.

Malware infects removeable media, and could reinfect a host years later when it accessed again.

Most antivirus (AV) software relies on signatures to identify and then block malware.

12

Copyright ©2018 John Wiley & Sons, Inc.

Intentional Cyberthreats: Botnets

A botnet is a group of external attacking entities and is a totally different attack method/vector from malware, which is internal to the system.

A group of infected computers, called zombies, can be controlled and organized into a network of zombies on the command of a remote botmaster (also called a bot herder).

13

Copyright ©2018 John Wiley & Sons, Inc.

Intentional Cyberthreats: Denial of Service Attacks

Distributed Denial-of-Service (DDoS) crashes a network or website by bombarding it with traffic (i.e., requests for service) and effectively denies service to all those legitimately using it, leaving it vulnerable to other threats

Telephony Denial-of-Service (TDoS) floods a network with phone calls and keeps the calls up for long durations to overwhelm an agent or circuit and prevent legitimate callers, such as customers, partners, and suppliers, from using network resources

Permanent Denial-of-Service (PDoS) prevents the target’s system or device from working. Instead of collecting data or providing some on-going perverse function, its objective is to completely prevent the target’s device(s) from functioning.

14

Copyright ©2018 John Wiley & Sons, Inc.

Intentional Cyberthreats: Internal Threats

Internal threats from employees can be some of the most challenging to defend against

Data tampering is a common means of internal attack

Refers to an attack during which someone enters false or fraudulent data into a computer, or changes/deletes existing data

Data tampering is extremely serious because it may not be detected; the method often used by insiders and fraudsters

15

Copyright ©2018 John Wiley & Sons, Inc.

New Attack Vectors

Attack Vector is a path or means by which a hacker can gain access to a computer or network server in order to deliver a malicious outcome.

Mobile devices and apps, social media, and cloud services introduce even more attack vectors for malware, phishing, and hackers.

Malicious (rogue) apps can serve up Trojan attacks, other malware, or phishing attacks.

Found in Google Play Store for Andriod phones.

16

Copyright ©2018 John Wiley & Sons, Inc.

The Face and Future of Cyberthreats Review

Define and give an example of an intentional threat and an unintentional threat.

Why might management not treat cyberthreats as a top priority?

Describe the differences between distributed denial-of-service (DDoS), telephony denial-of-service (TDoS), and permanent denial-of-service (PDoS).

Why is social engineering a technique used by hackers to gain access to a network?

List and define three types of malware.

What are the risks caused by data tampering?

Define botnet and explain why they are dangerous.

Why is Ransomware on the rise? How might companies guard against ransomware attacks?

17

Copyright ©2018 John Wiley & Sons, Inc.

Suggested Answers:

 Examples of intentional threats include data theft include inappropriate use of data (e.g., manipulating in-puts); theft of computer time; theft of equipment and/or software; deliberate manipulation in handling, entering, programming, processing, or transferring data; sabotage; malicious damage to computer resources; destruction from malware and similar attacks; and miscellaneous computer abuses and Internet fraud. Unintentional threats fall into three major categories: human error, environmental hazards, social unrest and computer system failures.

 

2. Answers may vary. Current cybersecurity technologies and policies are simply not keeping pace with fast-evolving threats. Organizations need to acquire a deeper knowledge of cyberattacks and combine it with business context, valuation techniques, and financial quantification to establish the true costs of their losses. Applying this more accurate knowledge of potential business impacts, leaders can be much more effective in managing and controlling cyber risk and improve their ability to recover from a cyberattack.   

3. Distributed Denial-of-Service (DDoS) – crashes a network or website by bombarding it with traffic (i.e., requests for service) and effectively denying services to all those legitimately using it and leave it vulnerable to other threats.

Telephony Denial-of-Service (TDoS) – floods a network with phone calls and keep the calls up for long durations to overwhelm an agent or circuit and prevent legitimate callers such as customers, partners and suppliers from using network resources.

Permanent Denial-of-Service (PDoS) - completely prevents the target’s system or device from working. This attack type is unique. Instead of collecting data or providing some on-going perverse function its' ob-jective is to completely prevent its target’s device(s) from functioning.

4. Social engineering, also known as human hacking, is tricking users into revealing their credentials and then using those credentials to gain access to networks or accounts. It is a hacker’s clever use of deception or manipulation of people’s tendency to trust, be helpful, or simply follow their curiosity. Powerful IT security systems cannot defend against what appears to be authorized access. Humans are easily hacked, making them and their social media posts high-risk attack vectors. For instance, it is often easy to get users to infect their corporate network or mobiles by tricking them into downloading and installing malicious apps or backdoors7. A hacktivist is someone who does hacking as a way to protest for a cause.

 

5. Viruses, worms, trojans, rootkits, backdoors, and keyloggers are all types of malware.

6. Data tampering is extremely serious because it may not be detected. This is the method often used by insiders.

7. A botnet is a group of external attacking entities. Infected computers, called zombies, can be controlled and organized into a network of zombies on the command of a remote botmaster,

8. Computer security experts have theorized that this type of attack has a higher rate of success versus other cybercrime activity that has become more difficult, probably due to the centralization of data resources in an organization. The best insurance against Ransomware is to have offline or segregated backups of data.

17

Learning Objectives (2 of 5)

18

Copyright ©2018 John Wiley & Sons, Inc.

Cyberattack Targets and Consequences

Managers make the mistake of underestimating IT vulnerabilities and threats, and appear detached from the value of confidential data (even high-tech companies).

Targets for cyberattacks include critical infrastructure, theft of intellectual property, identity theft, BYOD, and social media.

These attacks can be “high profile” or “under the radar”.

19

Copyright ©2018 John Wiley & Sons, Inc.

High Profile and Under the Radar Attacks

Advanced Persistent Threats (APT)

Launched by attacker through phishing to again access to enterprise’s network

Designed for long-term espionage

Profit-motivated cybercriminals often operate in stealth mode to continue long-term activities

Hackers and hacktivists, commonly with personal agendas, carry out high-profile attacks to further their causes.

Anonymous and LulzSec are two hacker groups who have committed daring data breaches, data compromises, data leaks, thefts, threats, and privacy invasions.

20

Copyright ©2018 John Wiley & Sons, Inc.

Critical Infrastructure Attacks

Figure 5.3 U.S. Critical Infrastructure Sectors.

Critical infrastructure is defined as systems and assets so vital to the country that their incapacity or destruction would have a debilitating effect.

21

Copyright ©2018 John Wiley & Sons, Inc.

21

Theft of Intellectual Property

Intellectual Property is a work or invention that is the result of creativity that has commercial value.

Includes copyrighted property such as a blueprint, manuscript or a design, and is protected by law from unauthorized use by others.

Intellectual property can represent more than 80% of a company’s value.

Losing customer data to hackers can be costly and embarrassing but losing intellectual property, commonly known as trade secrets, could threaten a company’s existence.

22

Copyright ©2018 John Wiley & Sons, Inc.

Identity Theft

One of the worst and most prevalent cyberthreats is identity theft.

Made worse by electronic sharing and databases

Businesses reluctant to reveal incidents in which their customers’ personal financial information may have been stolen, lost, or compromised

23

Copyright ©2018 John Wiley & Sons, Inc.

Bring Your Own Device (BYOD)

Bring Your Own Device (BYOD): employees providing their own (mobile) devices for business purposes to reduce expenses through cut purchase and maintenance costs.

Roughly 74% of U.S. organizations are using or planning to use BYOD

Cuts business costs by not having to purchase and maintain employees’ mobile devices

Security risk: mobile devices rarely have strong authentication, access controls, and encryption even though they connect to mission-critical data and cloud services. Could also be lost or stolen.

24

Copyright ©2018 John Wiley & Sons, Inc.

Social Media Attacks

Social networks and cloud computing increase vulnerabilities by providing a single point of failure and attack for organized criminal networks.

FBI: social media-related events have quadrupled over the past five years.

Pricewaterhouse Coopers found that more than one in eight enterprises has suffered at least one security breach due to a social media-related cyberattack.

Facebook scams were the most common form of malware distributed in 2015.

25

Copyright ©2018 John Wiley & Sons, Inc.

Networks and Services Increase Exposure to Risk

Time-to-exploitation is the elapsed time between when vulnerability is discovered and when it is exploited

Launched by attacker through phishing to again access to enterprise’s network

Designed for long-term espionage

Profit-motivated cybercriminals often operate in stealth mode to continue long-term activities

Hackers and hacktivists, commonly with personal agendas, carry out high-profile attacks to further their causes.

Anonymous and LulzSec are two hacker groups who have committed daring data breaches, data compromises, data leaks, thefts, threats, and privacy invasions.

26

Copyright ©2018 John Wiley & Sons, Inc.

Cyberattack Targets and Consequences Review

What is a critical infrastructure?

List three types of critical infrastructures.

How do social network and cloud computing increase vulnerability?

Why are patches and service packs needed?

Why is it important to protect intellectual property?

How are the motives of hacktivists and APTs different?

Explain why data on laptops and computers need to be encrypted.

Explain how identity theft can occur.

27

Copyright ©2018 John Wiley & Sons, Inc.

Suggested Answers:

Critical infrastructure is defined as “systems and assets, whether physical or virtual, so vital to the United States that the incapacity or destruction of such systems and assets would have a debilitating impact on security, national economic security, national public health or safety, or any combination of those matters.

Some types of critical infrastructure are: commercial facilities; defense industrial base; transportation systems; national monuments and icons; banking and finance; and agriculture and food.

Social networks and cloud computing increase vulnerabilities by providing a single point of failure and attack for organized criminal networks, putting critical, sensitive, and private information is at risk.

Patches are software programs that users down-load and install to fix a vulnerability. Microsoft, for example, releases patches that it calls service packs to update and fix vulnerabilities in its operating systems Patches and Service Packs are released by the vendor or security organization to repair new vulnerabilities discovered in the security system.

Intellectual property is also known as trade secrets. Theft of intellectual property could cause security risks or incur financial loss. For example, a government agency could have blueprints for a secret new weapon system stolen by foreign agents, or an employee of a popular game developer might steal their latest game before it is released to the public.

APTs are profit-motivated cybercriminals who often operate in stealth mode. In contrast, hackers and hacktivists with personal agendas carry out high-profile at-tacks to gain recognition and notoriety.

Encryption is a part of a defense-in-depth approach to information security. Laptops, tab-lets, modems, routers and USBs are much more easily transportable than mainframes or servers. When a laptop or tablet with unencrypted sensitive documents on it goes missing it’s difficult to determine if a data breach has actually occurred, but precautions must always be taken.

Identity theft occurs when individuals’ Social Security and credit card numbers are stolen and used by thieves for financial gain.

27

Learning Objectives (3 of 5)

28

Copyright ©2018 John Wiley & Sons, Inc.

Cyber Risk Management

Risk is the probability of a threat successfully exploiting a vulnerability and the estimated cost of the loss or damage.

Factors leading to an increased risk of cyberattack:

Interconnected, interdependent, wirelessly networked business environment

Smaller, faster, cheaper computers and storage devices

Decreasing skills necessary to be computer hacker

International organized crime taking over cybercrime

Lack of management support

29

Copyright ©2018 John Wiley & Sons, Inc.

IT Defenses

Some essential defenses organizations can institute to defend again cyberattacks

Antivirus Software: designed to detect malicious codes and prevent users from downloading them.

Intrusion Detection Systems (IDSs): scans for unusual or suspicious traffic (passive defense)

Intrusion Prevention Systems (IPSs): is designed to take immediate action—such as blocking specific IP addresses—whenever a traffic-flow anomaly is detected (active defense)

Security is an ongoing, unending process

30

Copyright ©2018 John Wiley & Sons, Inc.

Figure 5.7 Basic IT security concepts

31

Copyright ©2018 John Wiley & Sons, Inc.

Security Defenses for Mobiles

Biometric Control is an automated method of verifying the identity of a person, based on physical or behavioral characteristics

The most common biometrics are a thumbprint or fingerprint, voice print, retinal scan, and signature.

Mobile biometrics can significantly improve the security of physical devices and provide stronger authentication for remote access or cloud services.

Voice biometrics are an effective authentication solution across a wide range of consumer devices including smartphones, tablets, and TVs.

32

Copyright ©2018 John Wiley & Sons, Inc.

Additional IT Defenses: Do-Not-Carry Rules

U.S. companies, government agencies, and organizations may impose rules that assume mobile technologies will inevitably be compromised.

Only “clean” devices are allowed to be brought inside

Devices are forbidden from connecting while abroad

Some individuals carry no electronics on trips for compliance

33

Copyright ©2018 John Wiley & Sons, Inc.

Business Continuity Planning

Business continuity refers to maintaining business functions or restoring them quickly when there is a major disruption

A business continuity plan covers business processes, assets, human resources, business partners

Keeps the business running after a disaster occurs

Covers fires, earthquakes, floods, power outages, malicious attacks, and other types of disasters

34

Copyright ©2018 John Wiley & Sons, Inc.

Figure 5.8

35

Copyright ©2018 John Wiley & Sons, Inc.

Cyber Risk Management Review

Explain why it is becoming more important for organizations to make cyber risk management a high priority?

Name four U.S. Government Regulations that relate to cyber risk management.

What is the purpose of Rogue Application Monitoring?

Why is a mobile kill switch or remote wipe capability an important part of managing cyber risk?

Why does an organization need to have a business continuity plan?

Name the three essential cybersecurity defenses.

Name three IT defenses.

Why do companies impose do-not-carry rules?

36

Copyright ©2018 John Wiley & Sons, Inc.

Suggested Answers:

The growth of mobile technologies and the Internet of Things (IoT) threaten to provide attackers with new opportunities, making cyber risk management a high priority in organizations.

Four U.S. Government Regulations relating to cyber risk management are found in Figure 5.8.

Rogue app monitoring is a type of defense to detect and destroy malicious apps in the wild. Several vendors offer 24/7 monitoring and detection services to monitor major app stores and shut down rogue apps to minimize exposure and damage.

A mobile kill switch or remote wipe capability is needed in the event of loss or theft of a device.

An organization needs to have a business continuity plan to keep the business running after a disaster occurs. The plan covers business processes, assets, human resources, business partners, and more in the event of fires, earthquakes, floods, power outages, malicious attacks, and other types of disasters that could hit data centers.

Three essential cybersecurity defenses are Antivirus software, Intrusion Detection Systems, and Intrusion Prevention Systems.

Same as question 6.

8. Many U.S. companies and government agencies are imposing do-not-carry rules on mobiles to prevent compromise. Travelers can bring only “clean” devices and are forbid-den from connecting to the government’s network while abroad.

36

Learning Objectives (4 of 5)

37

Copyright ©2018 John Wiley & Sons, Inc.

Defending Against Fraud

Crime

Violent crime involves physical threat or harm

Nonviolent crime uses deception, confidence, and trickery by abusing the power of their position or by taking advantage of the trust ignorance, or laziness of others, otherwise known as fraud.

Fraud

Occupational fraud refers to the deliberate misuse of the assets of one’s employer for personal gain.

38

Copyright ©2018 John Wiley & Sons, Inc.

Occupational Fraud Prevention and Detection

Corporate Governance

Enterprise-wide approach greatly increases the prevention and detection of fraud

Intelligent Analysis

Forms insider profiling to find wider patterns of criminal networks.

Anomaly Detection

Audit trails from key systems and personnel records used to detect anomalous patters, such as excessive hours worked, deviations in patterns of behavior, copying huge amounts of data, attempts to override controls, unusual transactions, and inadequate documentation about a transaction.

39

Copyright ©2018 John Wiley & Sons, Inc.

Internal Controls (IC)

A process to ensure that sensitive data are protected and accurate designed to achieve:

Reliability of financial reporting, to protect investors

Operational efficiency

Compliance with laws, regulations, and policies

Safeguarding of assets

40

Copyright ©2018 John Wiley & Sons, Inc.

Cyber Defense Strategies

The major objectives of Defense Strategies are:

Prevention and deterrence

Detection

Contain the Damage (damage control)

Recovery

Correction

Awareness and compliance

Auditing can provide an additional layer of safeguards.

41

Copyright ©2018 John Wiley & Sons, Inc.

Defending Against Fraud Review

What defenses help prevent occupational fraud?

What level of employee commits the most occupational fraud?

What is the purpose of internal controls?

What federal law requires effective internal controls?

Explain the concepts of Intelligence Analysis and Anomaly Detection.

Name the major categories of general controls.

Explain authentication and name two methods of authentication.

What are the six major objectives of a defense strategy?

42

Copyright ©2018 John Wiley & Sons, Inc.

Suggested Answers:

1. Occupational fraud refers to the deliberate misuse of the assets of one’s employer for personal gain. The single most effective fraud prevention tactic is making employees aware that fraud will be detected by IT monitoring systems and punished, with the fraudster possibly turned over to the police or FBI. The fear of being caught and prosecuted is a strong deterrent.

 

2. According to the latest Annual Global Fraud Survey, 81 percent of organizations have been victims of frauds perpetrated by insiders. Of these, 36 percent were carried out by senior or middle managers and 45 percent were attributed to junior employees.

3. The internal control environment is the work atmosphere that a company sets for its employees. Internal control (IC) is a process designed to achieve:

• Reliability of financial reporting, to protect investors

• Operational efficiency

• Compliance with laws, regulations, and policies

• Safeguarding of assets

4. The Sarbanes-Oxley Act (SOX) requires companies to set up comprehensive internal controls.

5. Most detection activity can be handled by intelligent analysis engines using advanced data warehousing and analytics techniques. These systems take in audit trails from key systems and personnel records from the HR and finance departments. The data are stored in a data warehouse where they are analyzed to detect anomalous patterns, such as excessive hours worked, deviations in patterns of behavior, copying huge amounts of data, attempts to override controls, unusual transactions, and inadequate documentation about a transaction. Information from investigations is fed back into the detection system so it learns of any anomalous patterns.

6. The major categories of general controls are physical controls, access controls, data security controls, communication network controls, and administrative controls.

7. Authentication, which is also called user identification, requires the user to provide proof that they are who they claim to be..

Authentication methods include:

• Something only the user knows, such as a password

• Something only the user has, for example, a smart card or a token

• Something only the user is, such as a signature, voice, fingerprint, or retinal (eye) scan; implemented via biometric controls, which can be physical or behavioral

8. The major objectives of Defense Strategies are: Prevention and deterrence, Detection, Contain the Damage (damage control), Recovery, Correction, and Awareness and compliance.

42

Learning Objectives (5 of 5)

43

Copyright ©2018 John Wiley & Sons, Inc.

Frameworks, Standards, and Models

Current Frameworks and standards have been developed to address compliance:

Enterprise Risk Management (ERM)

Control Objectives for Information and Related Technology (COBIT)

Industry Standards, for example, Payment Card Industry Data Security Standard (PCI DSS)

44

Copyright ©2018 John Wiley & Sons, Inc.

Enterprise Risk Management Framework (ERM)

Risk-based approach to managing an enterprise

Developed by the Committee of Sponsoring Organizations of the Treadway Commission (COSO) ERM

Integrates internal control, the Sarbanes-Oxley Act mandates, and strategic planning

Consists of eight components, listed in Table 5.13

45

Copyright ©2018 John Wiley & Sons, Inc.

Figure 5.11 COBIT 5 Principles COBIT 5 is the leading framework for the governance and security of IT

46

Copyright ©2018 John Wiley & Sons, Inc.

Industry Standards: Payment Card Industry Data Security Standard (PCI DSS)

Created by Visa, MasterCard, American Express, and Discover

Requires merchants and card payment providers to make certain their Web applications are secure

Improves customers’ trust in e-commerce

Increase the Web security of online merchants

Penalties for noncompliance are severe

47

Copyright ©2018 John Wiley & Sons, Inc.

Figure 5.12 IT security defense-in-depth model.

48

Copyright ©2018 John Wiley & Sons, Inc.

Frameworks, Standards, and Models Review

Who created the Enterprise Risk Management Framework (ERM)? What is its purpose?

What are the 5 principles of COBIT 5? Explain.

Why do industry groups have their own standards for cybersecurity? Name one standard.

Are measurements of direct costs sufficient to reflect total damage sustained by a cyberattack?

What 4 components comprise the IT Security Defense-in-Depth model?

What are the 4 steps in the IT Security Defense-in-Depth IT security model?

Explain why frameworks, standards, and models are important parts of a cybersecurity program.

49

Copyright ©2018 John Wiley & Sons, Inc.

Suggested Answers:

 ERM is a risk-based approach to managing an enterprise developed by the Committee of Sponsoring Organi-zations of the Treadway Commission (COSO). ERM integrates internal control, the Sarbanes–Oxley Act mandates, and strategic planning.

The five principles of COBIT 5 are: Meeting stakeholder needs, Covering the Enterprise end-to-end, Applying a single integrated framework, Enabling a holistic approach, and Separating governance from management.

Industry groups impose their own standards to protect their customers and their members’ brand images and revenues. One example is the Payment Card Industry Data Security Standard (PCI DSS) created by Visa, MasterCard, American Express, and Discover.

Measurement of direct costs is not sufficient to estimate the true damages imposed by a cyberattack. The effects of a cyberattack can linger for years, resulting in a wide range of intangible costs tied to a damaged reputation, disruption of operations, loss of intellectual property or other strategic assets.

The four components or steps in the Defense-in-Depth model are:

Step 1: Gain senior management commitment and support.

Step 2: Develop acceptable use policies and IT security training.

Step 3: Create and Enforce IT security procedures and enforcement.

Step 4: Implement Security Tools: Hardware and software.

6. See question 5.

7. No matter which frameworks, standards and controls are used to assess, monitor and control cyber risk, they provide a balanced approach to measuring direct costs and intangible impacts associated with cyberattacks must be used to paint an accurate picture of the damage sustained and to guide the creation of increased security measures going forward.

49

Copyright

Copyright © 2018 John Wiley & Sons, Inc.

All rights reserved. Reproduction or translation of this work beyond that permitted in Section 117 of the 1976 United States Act without the express written permission of the copyright owner is unlawful. Request for further information should be addressed to the Permissions Department, John Wiley & Sons, Inc. The purchaser may make back-up copies for his/her own use only and not for distribution or resale. The Publisher assumes no responsibility for errors, omissions, or damages, caused by the use of these programs or from the use of the information contained herein.

50

Copyright ©2018 John Wiley & Sons, Inc.

50