Personal Data Classification and Controls (1000 words essay )
8/23/2017
15
C-I-A Triad
• Confidentiality
• Integrity
• Availability
• Sometimes two other desirable characteristics: • Authentication
• Nonrepudiation 29
Confidentiality
The information that is classified as private should remain secret. The secrecy should be enforced at each level of data processing and should prevent unauthorized disclosure
The threats to confidentiality include stealing of confidential information such as Social Security Numbers, Protected Health Information, trade secrets etc.,
8/23/2017
16
Integrity
Integrity of information is assured when the accuracy and reliability of information is maintained and also controlling the unauthorized access to the information.
For example: Bank Accounts or Salary Information. A software defect in a pay-roll software may add zeroes inadvertently thus making the salary figures to $30,000 instead of $3,000, thus affecting the integrity of the data.
Availability
Availability of ensures reliable and timely access of information to authorized individuals. All the devices, hardware, software and networks, shall provide with adequate level of performance to provide the availability of information.
One of the key challenges of information security is malicious personnel targeting the availability of information.
For example: Ransomware Hackers encrypt the medical records of a patient making it unavailable, threatening to destroy it permanently if the ransom is not paid
8/23/2017
17
Personal health information is 50 times more valuable on the black market than financial information, and stolen patient health records can fetch as much as $60 per record.
Source: Cybersecurity Ventures Inc., and Herjavec Group Inc.
$ value
Source: Gizmo, Feb 12, 2014
Source: New York Times, Feb 11, 2014
Source: Financial Times Limited, Feb 25, 2014 Sources: Forbes (online), May 21,2014; The Telegraph, May 22,2104
eBay SuffersMassive Security Breach, All Users Must Change Their Passwords
eBay publicly admit[ed] hackers had stolen the names, email and postal addresses, phone numbers and dates of birth of its 233 million users.
8/23/2017
18
Source: New York Times, Jan 10, 2014
Average cost in a breach: $158 per record ($221 in US)
Source: Ponemon Institute, “2016 Cost of Data Breach Study: Global Analysis”, June 2016
Source: Wall Street Journal, Feb 26, 2014
Source: http://www.darkreading.com
8/23/2017
19
Journey : Connecting to Internet
Booking an airline ticket via. internet
Flow of Information
User
Home Wireless Router
User Laptop
Internet Service Provider Cable
Google Server
Airline1 Server Airline 2 Server Airline X Server
Internet
Internet
8/23/2017
20
Points that are vulnerable to leak information
User
Home Wireless Router
User Laptop
Internet Service Provider Cable
Google Server
Airline1 Server Airline 2 Server Airline X Server
Internet
Internet
Points that are vulnerable to leak information
User
Home Wireless Router
User Laptop
Internet Service Provider Cable
Google Server
Airline1 Server Airline 2 Server Airline X Server
Internet
Internet
Almost everything
8/23/2017
21
Value of a compromised computer
Image Source: http://krebsonsecurity.com/
Value of a compromised email
Image Source: http://krebsonsecurity.com/
8/23/2017
22
How the access points are compromised
Phishing, Social Engineering
Malware, Viruses, Bots
Malware, Man in the Middle Attacks, Denial of Service
Attacks
Darknet, Malware, Advanced hacker networks
Malware, Denial of Service Attacks, Advanced
information threats and attacks
Cyberspace
Building Blocks of Cyberspace
Users of Cyberspace
Normal Users Malicious Users
Vulnerabilities Threats
Risks in Cyberspace
8/23/2017
23
Basic Terms
• Vulnerability
• Threat
• Attacks and Attackers
• Countermeasures or controls
From Security in Computing, Fifth Edition, by Charles P. Pfleeger, et al. (ISBN: 9780134085043). Copyright 2015 by Pearson Education, Inc. All rights reserved.
45
Vulnerability
A flaw or weakness in system security procedures, design, implementation, or internal controls that could be exercised (accidentally triggered or intentionally exploited) and result in a security breach or a violation of the system's security policy.
Source: http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf
8/23/2017
24
Classification of Vulnerabilities
• hardware • susceptibility to humidity • susceptibility to dust • susceptibility to soiling • susceptibility to unprotected storage
• software • insufficient testing • lack of audit trail • design flaw
Classification of Vulnerabilities (Contd.)
• network • unprotected communication lines
• insecure network architecture
• personnel • inadequate recruiting process
• inadequate security awareness
• physical site • area subject to flood
• unreliable power source
8/23/2017
25
Classification of Vulnerabilities (Contd.)
• organizational • lack of regular audits
• lack of continuity plans
• lack of security awareness
Types of Threats Threats
Natural causes
Benign intent
Malicious intent
Random
Examples: Fire, power failure
Human causes
Example: Impersonation
Directed
Example: Malicious code on a general web site
Example: Human error
50
8/23/2017
26
Threat Vectors • Routes that malicious attacks may take to get past the defenses
• Network – The perimeter of your network, usually protected by something like a firewall.
• User – Attackers often use social engineering and social networking to gather information and trick users into opening a pathway for an attack into a network.
• Email – Phishing attacks and malicious attachments target the email threat vector.
Threat Vectors (contd)
• Web Application – SQL Injection and Cross-Site Scripting are just two of the many attacks that take advantage of an inadequately protected Web Application threat vector.
• Remote Access – A corporate device using an unsecured wireless hotspot can be compromised and passed on to the corporate network.
• Mobile – Smart phones, tablets, and other mobile devices can be used as devices to pass malware and other attacks on to the corporate network. Additionally, mobile malware may be used to steal useful data from the mobile device.
8/23/2017
27
Advanced Persistent Threat (APT)
• Organized
• Directed
• Well financed
• Patient
• Silent
From Security in Computing, Fifth Edition, by Charles P. Pfleeger, et al. (ISBN: 9780134085043). Copyright 2015 by Pearson Education, Inc. All rights reserved.
53
Types of Attackers
Criminal- for-hire
Organized crime member
Individual
Hacker
Terrorist
Loosely connected
group
From Security in Computing, Fifth Edition, by Charles P. Pfleeger, et al. (ISBN: 9780134085043). Copyright 2015 by Pearson Education, Inc. All rights reserved.
54
8/23/2017
28
Attacker Profiles
Method—Opportunity--Motive
Opportunity
Motive
MethodFrom Security in Computing, Fifth Edition, by Charles P. Pfleeger, et al. (ISBN: 9780134085043). Copyright 2015 by Pearson Education, Inc. All rights reserved.
56
8/23/2017
29
Vulnerabilities Threats
Risks in Cyberspace
Dealing with risks
• Prevention • Deterring • Deflection • Mitigation • Detection • Recovery
8/23/2017
30
From Security in Computing, Fifth Edition, by Charles P. Pfleeger, et al. (ISBN: 9780134085043). Copyright 2015 by Pearson Education, Inc. All rights reserved.
59
Types of Harm
Modification Fabrication
InterruptionInterception
Controls/Countermeasures
Confidentiality
Integrity
Availability
T ech
n ical
P ro
ced u
ral
P h
y sical
Kind of Threat
Protects
Co nt
ro l T
yp e
D ire
ct ed
/n ot
M al
ic io
us /n
ot
H um
an /n
ot
60
8/23/2017
31
Different Types of Controls
61
Access Control Policy:
Who What How Yes/No
Subject (who)
Object (what) Mode of access
(how)
From Security in Computing, Fifth Edition, by Charles P. Pfleeger, et al. (ISBN: 9780134085043). Copyright 2015 by Pearson Education, Inc. All rights reserved.
62
8/23/2017
32
Engineering
Science
Business
EducationFinance
Government
Law
A need for an integrated Multi-disciplinary
approach
Information Security
People
ProcessTechnology
8/23/2017
33
People
• PEBKAC – Problem Exists Between Keyboard and Chair
• Awareness • Motivation • Formal Education • Constant informational updates • Accessibility to threat mitigation and prevention
information
• Enforcement
Process
• Business Process improvements with an emphasis on Information security
• Governance of systems • Auditing secure practices • Assurance and Assessments • Monitoring • Business Continuity Process Improvements • Disaster Recovery • Best Practices • Constant updates to key knowledge areas
8/23/2017
34
Technology
• Hardware • Software • Networks • Algorithms • Design and engineer secure technologies for
• Information Storage • Information Transmission • Fault tolerance and dependable systems
Right now …
• http://map.norsecorp.com
• https://threatmap.fortiguard.com/
• http://www.digitalattackmap.com
• https://www.fireeye.com/cyber-map/threat- map.html
8/23/2017
35
Source: IBM Threat Intelligence Index 2017
Threat is not just to data anymore..
• In the news.. Malware caused outage to Ukrainian Powergrid
• an unauthorized intrusion (from 15:30 - 16:30L) that disconnected 7 substations (110 kV) and 23 (35 kV) substations leading to an outage for 80,000 customers.
Source: SANS.org
8/23/2017
36
Top Targeted Industries (2016)
• Finance
• Information and Communications
• Retail
• Manufacturing
• Healthcare
Cybersecurity spending will exceed $65 billion cumulatively over the next five years, from 2017 to 2021.
Source: Cybersecurity Ventures Inc., and Herjavec Group Inc.
Opportunities
8/23/2017
37
The cybersecurity workforce shortage, which has 1 million job openings in 2017, and is projected to reach at least 1.5 million by 2019.
Source: Cybersecurity Ventures Inc., and Herjavec Group Inc.
Opportunities
Thank you.
8/23/2017
38
https://www.dhs.gov/topic/cybersecurity
http://staysafeonline.org/
https://stopthinkconnect.org/
http://www.trendmicro.com/
http://www.mcafee.com/
http://www.proofpoint.com/
For Additional Information