Personal Data Classification and Controls (1000 words essay )

profilewfwfaf
CSC-200---Week-1---Lectures-1--2-15-38.pdf

8/23/2017

15

C-I-A Triad

• Confidentiality

• Integrity

• Availability

• Sometimes two other desirable characteristics: • Authentication

• Nonrepudiation 29

Confidentiality

 The information that is classified as private should remain secret. The secrecy should be enforced at each level of data processing and should prevent unauthorized disclosure

 The threats to confidentiality include stealing of confidential information such as Social Security Numbers, Protected Health Information, trade secrets etc.,

8/23/2017

16

Integrity

 Integrity of information is assured when the accuracy and reliability of information is maintained and also controlling the unauthorized access to the information.

 For example: Bank Accounts or Salary Information. A software defect in a pay-roll software may add zeroes inadvertently thus making the salary figures to $30,000 instead of $3,000, thus affecting the integrity of the data.

Availability

 Availability of ensures reliable and timely access of information to authorized individuals. All the devices, hardware, software and networks, shall provide with adequate level of performance to provide the availability of information.

 One of the key challenges of information security is malicious personnel targeting the availability of information.

 For example: Ransomware Hackers encrypt the medical records of a patient making it unavailable, threatening to destroy it permanently if the ransom is not paid

8/23/2017

17

Personal health information is 50 times more valuable on the black market than financial information, and stolen patient health records can fetch as much as $60 per record.

Source: Cybersecurity Ventures Inc., and Herjavec Group Inc.

$ value

Source: Gizmo, Feb 12, 2014

Source: New York Times, Feb 11, 2014

Source: Financial Times Limited, Feb 25, 2014 Sources: Forbes (online), May 21,2014; The Telegraph, May 22,2104

eBay SuffersMassive Security Breach, All Users Must Change Their Passwords

eBay publicly admit[ed] hackers had stolen the names, email and postal addresses, phone numbers and dates of birth  of its 233 million users.

8/23/2017

18

Source: New York Times, Jan 10, 2014

Average cost in a breach: $158 per record ($221 in US)

Source: Ponemon Institute, “2016 Cost of Data Breach  Study: Global Analysis”, June 2016

Source: Wall Street Journal, Feb 26, 2014

Source: http://www.darkreading.com

8/23/2017

19

Journey : Connecting to Internet

Booking an airline ticket via. internet

Flow of Information

User

Home Wireless Router

User Laptop

Internet Service Provider Cable

Google Server

Airline1 Server Airline 2 Server Airline X Server

Internet

Internet

8/23/2017

20

Points that are vulnerable to leak information

User

Home Wireless Router

User Laptop

Internet Service Provider Cable

Google Server

Airline1 Server Airline 2 Server Airline X Server

Internet

Internet

Points that are vulnerable to leak information

User

Home Wireless Router

User Laptop

Internet Service Provider Cable

Google Server

Airline1 Server Airline 2 Server Airline X Server

Internet

Internet

Almost everything

8/23/2017

21

Value of a compromised computer

Image Source: http://krebsonsecurity.com/

Value of a compromised email

Image Source: http://krebsonsecurity.com/

8/23/2017

22

How the access points are compromised

Phishing, Social Engineering

Malware, Viruses, Bots

Malware, Man in the Middle Attacks, Denial of Service

Attacks

Darknet, Malware, Advanced hacker networks

Malware, Denial of Service Attacks, Advanced

information threats and attacks

Cyberspace

Building Blocks of Cyberspace

Users of Cyberspace

Normal Users Malicious Users

Vulnerabilities Threats

Risks in Cyberspace

8/23/2017

23

Basic Terms

• Vulnerability

• Threat

• Attacks and Attackers

• Countermeasures or controls

From Security in Computing, Fifth Edition, by Charles P. Pfleeger, et al. (ISBN: 9780134085043). Copyright 2015 by Pearson Education, Inc. All rights reserved.

45

Vulnerability

A flaw or weakness in system security procedures, design, implementation, or internal controls that could be exercised (accidentally triggered or intentionally exploited) and result in a security breach or a violation of the system's security policy.

Source: http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf

8/23/2017

24

Classification of Vulnerabilities

• hardware • susceptibility to humidity • susceptibility to dust • susceptibility to soiling • susceptibility to unprotected storage

• software • insufficient testing • lack of audit trail • design flaw

Classification of Vulnerabilities (Contd.)

• network • unprotected communication lines

• insecure network architecture

• personnel • inadequate recruiting process

• inadequate security awareness

• physical site • area subject to flood

• unreliable power source

8/23/2017

25

Classification of Vulnerabilities (Contd.)

• organizational • lack of regular audits

• lack of continuity plans

• lack of security awareness

Types of Threats Threats

Natural causes

Benign intent

Malicious intent

Random

Examples: Fire, power failure

Human causes

Example: Impersonation

Directed

Example: Malicious code on a general web site

Example: Human error

50

8/23/2017

26

Threat Vectors • Routes that malicious attacks may take to get past the defenses

• Network – The perimeter of your network, usually protected by something like a firewall.

• User – Attackers often use social engineering and social networking to gather information and trick users into opening a pathway for an attack into a network.

• Email – Phishing attacks and malicious attachments target the email threat vector.

Threat Vectors (contd)

• Web Application – SQL Injection and Cross-Site Scripting are just two of the many attacks that take advantage of an inadequately protected Web Application threat vector.

• Remote Access – A corporate device using an unsecured wireless hotspot can be compromised and passed on to the corporate network.

• Mobile – Smart phones, tablets, and other mobile devices can be used as devices to pass malware and other attacks on to the corporate network. Additionally, mobile malware may be used to steal useful data from the mobile device.

8/23/2017

27

Advanced Persistent Threat (APT)

• Organized

• Directed

• Well financed

• Patient

• Silent

From Security in Computing, Fifth Edition, by Charles P. Pfleeger, et al. (ISBN: 9780134085043). Copyright 2015 by Pearson Education, Inc. All rights reserved.

53

Types of Attackers

Criminal- for-hire

Organized crime member

Individual

Hacker

Terrorist

Loosely connected

group

From Security in Computing, Fifth Edition, by Charles P. Pfleeger, et al. (ISBN: 9780134085043). Copyright 2015 by Pearson Education, Inc. All rights reserved.

54

8/23/2017

28

Attacker Profiles

Method—Opportunity--Motive

Opportunity

Motive

MethodFrom Security in Computing, Fifth Edition, by Charles P. Pfleeger, et al. (ISBN: 9780134085043). Copyright 2015 by Pearson Education, Inc. All rights reserved.

56

8/23/2017

29

Vulnerabilities Threats

Risks in Cyberspace

Dealing with risks

• Prevention • Deterring • Deflection • Mitigation • Detection • Recovery

8/23/2017

30

From Security in Computing, Fifth Edition, by Charles P. Pfleeger, et al. (ISBN: 9780134085043). Copyright 2015 by Pearson Education, Inc. All rights reserved.

59

Types of Harm

Modification Fabrication

InterruptionInterception

Controls/Countermeasures

Confidentiality

Integrity

Availability

T ech

n ical

P ro

ced u

ral

P h

y sical

Kind of Threat

Protects

Co nt

ro l T

yp e

D ire

ct ed

/n ot

M al

ic io

us /n

ot

H um

an /n

ot

60

8/23/2017

31

Different Types of Controls

61

Access Control Policy:

Who  What  How  Yes/No

Subject (who)

Object (what) Mode of access

(how)

From Security in Computing, Fifth Edition, by Charles P. Pfleeger, et al. (ISBN: 9780134085043). Copyright 2015 by Pearson Education, Inc. All rights reserved.

62

8/23/2017

32

Engineering

Science

Business

EducationFinance

Government

Law

A need for an integrated Multi-disciplinary

approach

Information Security

People

ProcessTechnology

8/23/2017

33

People

• PEBKAC – Problem Exists Between Keyboard and Chair

• Awareness • Motivation • Formal Education • Constant informational updates • Accessibility to threat mitigation and prevention

information

• Enforcement

Process

• Business Process improvements with an emphasis on Information security

• Governance of systems • Auditing secure practices • Assurance and Assessments • Monitoring • Business Continuity Process Improvements • Disaster Recovery • Best Practices • Constant updates to key knowledge areas

8/23/2017

34

Technology

• Hardware • Software • Networks • Algorithms • Design and engineer secure technologies for

• Information Storage • Information Transmission • Fault tolerance and dependable systems

Right now …

• http://map.norsecorp.com

• https://threatmap.fortiguard.com/

• http://www.digitalattackmap.com

• https://www.fireeye.com/cyber-map/threat- map.html

8/23/2017

35

Source: IBM Threat Intelligence Index 2017

Threat is not just to data anymore..

• In the news.. Malware caused outage to Ukrainian Powergrid

• an unauthorized intrusion (from 15:30 - 16:30L) that disconnected 7 substations (110 kV) and 23 (35 kV) substations leading to an outage for 80,000 customers.

Source: SANS.org

8/23/2017

36

Top Targeted Industries (2016)

• Finance

• Information and Communications

• Retail

• Manufacturing

• Healthcare

Cybersecurity spending will exceed $65 billion cumulatively over the next five years, from 2017 to 2021.

Source: Cybersecurity Ventures Inc., and Herjavec Group Inc.

Opportunities

8/23/2017

37

The cybersecurity workforce shortage, which has 1 million job openings in 2017, and is projected to reach at least 1.5 million by 2019.

Source: Cybersecurity Ventures Inc., and Herjavec Group Inc.

Opportunities

Thank you.

8/23/2017

38

https://www.dhs.gov/topic/cybersecurity

http://staysafeonline.org/

https://stopthinkconnect.org/

http://www.trendmicro.com/

http://www.mcafee.com/

http://www.proofpoint.com/

For Additional Information