Cybersecurity and Risk Management
IT for Management: On-Demand Strategies for Performance, Growth, and
Sustainability Eleventh Edi+on
Turban, Pollard, Wood
Chapter 5
Cybersecurity and Risk Management Technology
Learning Objec>ves (1 of 5) 2 Copyright ©2018 John Wiley & Sons, Inc.
The Face and Future of Cyberthreats
Figure 5.1: Number of 2016 U.S. Data Breaches by Industry Sector. The number of cyberthreats in which data records have been stolen by hackers has increased at an alarming rate.
3
الشكل 1.5: عدد خروقات البيانات األمريكية لعام 2016 بحسب قطاع الصناعة. زاد عدد التهديدات السيبرانية التي سرقها املتسللون سجالت البيانات مبعدل ينذر باخلطر.
Cyberthreat Terminology • Cyberthreat is a threat posed by means of the Internet (a.k.a. cyberspace)
and the poten>al source of malicious aRempts to damage or disrupt a computer network, system, or applica>on.
• Vulnerability is a gap in IT security defenses of a network, system, or applica>on that can be exploited by a threat to gain unauthorized access.
• Incident is an a"empted or successful unauthorized access to a network, system, or applica>on; unwanted disrup>on or denial of service; unauthorized use of a system for processing or storage of data; changes to a system without the owner’s knowledge, instruc>on, or consent.
• Data Breach is the successful retrieval of sensi>ve informa>on by an individual, group, or soWware system.
4
تهديد اإلنترنت ميثل تهديدًا ميثله اإلنترنت (مثل الفضاء اإللكتروني) واملصدر احملتمل حملاوالت ضارة لتلف أو تعطيل شبكة • الكمبيوتر أو النظام أو التطبيق.
الثغرة األمنية هي فجوة في الدفاعات األمنية لتكنولوجيا املعلومات لشبكة أو نظام أو تطبيق ميكن استغالله عن طريق التهديد • بالوصول غير املصرح به.
احلادث هو محاولة الوصول غير املصرح به أو الناجحة إلى شبكة أو نظام أو تطبيق ؛ انقطاع غير مرغوب فيه أو رفض اخلدمة ؛ • االستخدام غير املصرح به لنظام معاجلة البيانات أو تخزينها ؛ التغييرات في النظام دون علم املالك أو تعليماته أو موافقته.
• Data Breach هو االسترجاع الناجح للمعلومات احلساسة من قِبل فرد أو مجموعة أو نظام برنامج.
Figure 5.2 The three objec>ves of data and informa>on systems security
5
2016 Biggest Data Breaches Worldwide Company Type of Breach Records Breached
Anthem Insurance Iden>ty theW—healthcare records
78.8 million
Turkish General Directorate
Iden>ty theW—malicious outsider (government agency)
50 million
Korean Pharmaceu>cal Info. Center
Iden>ty theW—malicious insider
43 million
U.S. Office of Personnel Management
Personally Iden>fiable Informa>on (PII) (government agency)
22 million
Experian Iden>ty theW—malicious outsider (credit bureau)
15 million
6
Major Sources of Cyberthreats (1 of 2) Uninten>onal cyberthreats can be caused by
o Human error (a majority of internal security issues)
• Poorly designed systems • Faulty programming • Neglec>ng to change passwords • Unaware users
o Environmental hazards • Natural disasters • Faulty HVAC systems
o Computer systems failure • Poor manufacturing or maintenance
7
ميكن أن يكون سبب التهديدات السيبرانية غير املقصودة
خطأ بشري (غالبية قضايا األمن الداخلي) • نظم سيئة التصميم § البرمجة اخلاطئة §
إهمال لتغيير كلمات املرور § يجهل املستخدمني §
خطر بيئي • الكوارث الطبيعية §
أنظمة التكييف املعيبة § فشل أنظمة الكمبيوتر •
سوء التصنيع أو الصيانة
Major Sources of Cyberthreats (2 of 2) • Some inten>onal forms of cyberthreats are: o Hacking o Phishing o Crimeware o Distributed Denial of Service (DDoS) o Insider and Privilege Misuse o Physical TheW
8
بعض األشكال املتعمدة من التهديدات السيبرانية هي: القرصنة • اخلداع •
برمجيات اجلرمية • (DDoS) احلرمان املوزع من اخلدمة • إساءة استخدام من الداخل واالمتياز •
السرقة اجلسدية •
Inten>onal Cyberthreats: Hacking • Hacking is broadly defined as inten>onally accessing a computer without authoriza>on
or exceeding authorized access. There are three types of hackers.
• White Hat: Computer security specialist who breaks into protected systems and network to test and assess their security.
• Black Hat: Person who aRempts to find computer security vulnerabili>es and exploit them for personal and/or financial gain, or other malicious reasons.
• Gray Hat: Person who may violate ethical standards or principles, but without the malicious intent ascribed to black hat hackers.
• Hack+vist: is short for hacker-ac>vist, or someone who performs hacking to promote awareness, or otherwise support a social, poli>cal, economic, or other cause.
9
يتم تعريف القرصنة على نطاق واسع على أنها الوصول إلى الكمبيوتر عن قصد دون إذن أو جتاوز الوصول املصرح به. هناك ثالثة • أنواع من املتسللني.
وايت هات: أخصائي أمن الكمبيوتر الذي يقتحم األنظمة والشبكات احملمية الختبار وتقييم أمانهم. • القبعة السوداء: الشخص الذي يحاول العثور على ثغرات أمنية للكمبيوتر واستغاللها لتحقيق مكاسب شخصية و / أو مالية أو •
ألسباب ضارة أخرى. غراي هات: الشخص الذي قد ينتهك املعايير أو املبادئ األخالقية ، ولكن دون النية اخلبيثة املنسوبة إلى املتسللني القبعة السوداء. •
• Hacktivist: اختصار للناشط من املتطفلني ، أو أي شخص يقوم بالقرصنة لتعزيز الوعي ، أو يدعم بطريقة أخرى قضية .اجتماعية أو سياسية أو اقتصادية أو غيرها
Inten>onal Cyberthreats: Spear Phishing • Spear phishers oWen target select groups of people with something in common
• Trick user into opening an infected email • Emails sent that look like the real thing • Confiden>al informa>on extracted through seemingly legi>mate website requests for passwords, user IDs, PINs, account numbers, and so on.
10
غالبًا ما يستهدف احملتالون على الرمح مجموعات مختارة من األشخاص الذين لديهم شيء مشترك • خداع املستخدم في فتح بريد إلكتروني مصاب •
أرسلت رسائل البريد اإللكتروني التي تبدو وكأنها الشيء احلقيقي • املعلومات السرية املستخرجة من خالل طلبات املوقع التي تبدو شرعية لكلمات املرور ومعرفات •
املستخدمني وأرقام التعريف الشخصية وأرقام احلسابات وما إلى ذلك.
Inten>onal Cyberthreats: Crimeware • Malware refers to hos>le or intrusive soWware, including computer
viruses, rootkits, worms, Trojan horses, ransomware, and other malicious programs used to disrupt computer or mobile opera>ons, gather sensi>ve informa>on, gain access to private computer systems.
• Spyware is tracking soWware that is not designed to inten>onally damage or disable a system but to monitor or track ac>vi>es.
• Adware is soWware that embeds adver>sement in the applica>on • Ransomware is a type of malware that is designed to block access to a
computer system un>l a sum of money has been paid.
11
تشير البرامج الضارة إلى برامج معادية أو تطفلية ، مبا في ذلك فيروسات الكمبيوتر ، واجلذور اخلفية ، والديدان ، وأحصنة • طروادة ، والفدية ، وغيرها من البرامج اخلبيثة املستخدمة لتعطيل عمليات الكمبيوتر أو الهاتف احملمول ، وجمع املعلومات
احلساسة ، والوصول إلى أنظمة الكمبيوتر اخلاصة. تقوم برامج التجسس بتتبع البرامج التي لم يتم تصميمها إلتالف نظام أو تعطيله عن قصد ولكن ملراقبة األنشطة أو •
تتبعها. ادواري هو برنامج يتضمن اإلعالن في التطبيق •
• Ransomware هو نوع من البرامج الضارة املصممة ملنع الوصول إلى نظام الكمبيوتر حتى يتم دفع مبلغ من املال.
Inten>onal Cyberthreats: Variants • Malware Reinfec>ons, Signatures, Muta>ons, and Variants o Malware is captured in backups or archives. Restoring the
infected backup or archive also restores the malware. o Malware infects removeable media, and could reinfect a host
years later when it accessed again. o Most an>virus (AV) soWware relies on signatures to iden>fy
and then block malware.
12
إعادة تثبيت البرامج الضارة والتوقيعات والطفرات واملتغيرات يتم التقاط البرامج الضارة في النسخ االحتياطي أو احملفوظات. استعادة النسخة االحتياطية املصابة أو •
األرشيف يعيد البرامج الضارة أيضًا. تصيب البرامج الضارة الوسائط القابلة للنقل ، وميكن أن تعيد مضيفها بعد سنوات عندما يتم الوصول إليها •
مرة أخرى. تعتمد معظم برامج مكافحة الفيروسات (AV) على التواقيع لتحديد البرامج الضارة ثم حظرها. •
Inten>onal Cyberthreats: Botnets • A botnet is a group of external aRacking en>>es and is a totally different aRack method/vector from malware, which is internal to the system.
• A group of infected computers, called zombies, can be controlled and organized into a network of zombies on the command of a remote botmaster (also called a bot herder).
13
الروبوتات هي مجموعة من الكيانات املهاجمة اخلارجية وهي طريقة / ناقل هجوم • مختلف متامًا عن البرامج الضارة ، والتي تعد داخلية للنظام.
ميكن التحكم في مجموعة من أجهزة الكمبيوتر املصابة ، والتي تسمى الزومبي ، • وتنظيمها في شبكة من الزومبي بأمر مسؤول الروبوتات عن بعد (وتسمى أيضًا رعاة
البوت).
Inten>onal Cyberthreats: Denial of Service ARacks (1-2) • Distributed Denial-of-Service (DDoS) crashes a network or website by bombarding it with traffic (i.e., requests for service) and effec>vely denies service to all those legi>mately using it, leaving it vulnerable to other threats
• Telephony Denial-of-Service (TDoS) floods a network with phone calls and keeps the calls up for long dura>ons to overwhelm an agent or circuit and prevent legi>mate callers, such as customers, partners, and suppliers, from using network resources
14
تعطل خدمة رفض اخلدمة املوزعة (DDoS) شبكة أو موقعًا إلكترونيًا عن طريق قصفها بحركة مرور • (مثل طلبات اخلدمة) وترفض اخلدمة فعليًا جلميع من يستخدمونها بشكل قانوني ، مما يجعلها عرضة
للتهديدات األخرى يغمر رفض اخلدمة الهاتفية (TDoS) شبكة مبكاملات هاتفية ويبقي املكاملات لفترات طويلة لتطغى • على وكيل أو دائرة ومنع املتصلني الشرعيني ، مثل العمالء والشركاء واملوردين ، من استخدام موارد الشبكة
Inten>onal Cyberthreats: Denial of Service ARacks (2-2) • Permanent Denial-of-Service (PDoS) prevents the target’s system or device from working. Instead of collec>ng data or providing some on-going perverse func>on, its objec>ve is to completely prevent the target’s device(s) from func>oning.
15
دائم رفض اخلدمة (PDoS) مينع نظام أو جهاز الهدف من العمل. بدالً من جمع • البيانات أو توفير بعض الوظائف الضارة اجلارية ، فإن هدفها هو منع جهاز (أجهزة)
الهدف متامًا من العمل.
Inten>onal Cyberthreats: Internal Threats • Internal threats from employees can be some of the most challenging to defend against
• Data tampering is a common means of internal aRack o Refers to an aRack during which someone enters false or
fraudulent data into a computer, or changes/deletes exis>ng data
o Data tampering is extremely serious because it may not be detected; the method oWen used by insiders and fraudsters
16
ميكن أن تكون التهديدات الداخلية من املوظفني من أكثر التحديات التي تواجه الدفاع عنها • يعد التالعب بالبيانات وسيلة شائعة للهجوم الداخلي •
يشير إلى الهجوم الذي يدخل خالله شخص ما بيانات كاذبة أو احتيالية إلى جهاز كمبيوتر ، أو يغير / § يحذف البيانات املوجودة
يعد التالعب بالبيانات خطيرًا للغاية ألنه قد ال يتم الكشف عنه ؛ الطريقة التي غالبا ما تستخدم من قبل § املطلعني واحملتالني
New ARack Vectors • AUack Vector is a path or means by which a hacker can gain access to a computer or network server in order to deliver a malicious outcome.
• Mobile devices and apps, social media, and cloud services introduce even more aRack vectors for malware, phishing, and hackers.
• Malicious (rogue) apps can serve up Trojan aRacks, other malware, or phishing aRacks.
• Found in Google Play Store for Andriod phones.
17
• Attack Vector هو طريق أو وسيلة ميكن للمتسلل من خاللها الوصول إلى جهاز كمبيوتر أو خادم .شبكة من أجل تقدمي نتيجة ضارة
تقدم األجهزة والتطبيقات احملمولة والوسائط االجتماعية واخلدمات السحابية املزيد من متجهات الهجوم للبرامج • الضارة والتصيد والقراصنة.
ميكن للتطبيقات الضارة (املارقة) أن تخدم هجمات طروادة أو غيرها من البرامج الضارة أو هجمات التصيد. • Andriod لهواتف Google Play وجدت في متجر •
The Face and Future of Cyberthreats Review 1. Define and give an example of an inten>onal threat and an uninten>onal threat. 2. Why might management not treat cyberthreats as a top priority? 3. Describe the differences between distributed denial-of-service (DDoS), telephony denial-of-
service (TDoS), and permanent denial-of-service (PDoS).
4. Why is social engineering a technique used by hackers to gain access to a network? 5. List and define three types of malware. 6. What are the risks caused by data tampering? 7. Define botnet and explain why they are dangerous. 8. Why is Ransomware on the rise? How might companies guard against ransomware aRacks?
18
حتديد وإعطاء مثال على تهديد مقصود وتهديد غير مقصود. .1 ملاذا قد ال تعامل اإلدارة التهديدات اإللكترونية كأولوية قصوى؟ .2
.(PDoS) ورفض اخلدمة الدائم (TDoS) ورفض اخلدمة الهاتفية (DDoS) صف االختالفات بني رفض اخلدمة املوزع .3 ملاذا تعتبر الهندسة االجتماعية تقنية يستخدمها املتسللون للوصول إلى الشبكة؟ .4
قائمة وحتديد ثالثة أنواع من البرامج الضارة. .5 ما هي اخملاطر الناجمة عن العبث البيانات؟ .6 حتديد الروبوتات وشرح سبب خطورة ذلك. .7
ملاذا Ransomware في االرتفاع؟ كيف ميكن للشركات حماية ضد هجمات الفدية؟ .8
Learning Objec>ves (2 of 5) 19
CyberaRack Targets and Consequences • Managers make the mistake of underes>ma>ng IT vulnerabili>es and threats, and appear detached from the value of confiden>al data (even high-tech companies).
• Targets for cyberaRacks include cri>cal infrastructure, theW of intellectual property, iden>ty theW, BYOD, and social media.
• These aRacks can be “high profile” or “under the radar”.
20
يخطئ املديرون في التقليل من أهمية نقاط الضعف والتهديدات املتعلقة بتكنولوجيا • املعلومات ، ويبدو أنهم منفصلني عن قيمة البيانات السرية (حتى شركات التكنولوجيا
الفائقة). تشمل أهداف الهجمات اإللكترونية البنية التحتية احليوية وسرقة امللكية الفكرية وسرقة •
الهوية و BYOD ووسائل التواصل االجتماعي. ميكن أن تكون هذه الهجمات "بارزة" أو "حتت الرادار". •
High Profile and Under the Radar ARacks
21 Copyright ©2018 John Wiley & Sons, Inc.
• Advanced Persistent Threats (APT) o Launched by aRacker through phishing to again access to enterprise’s
network o Designed for long-term espionage o Profit-mo>vated cybercriminals oWen operate in stealth mode to con>nue
long-term ac>vi>es
• Hackers and hack>vists, commonly with personal agendas, carry out high-profile aRacks to further their causes. o Anonymous and LulzSec are two hacker groups who have commiRed
daring data breaches, data compromises, data leaks, theWs, threats, and privacy invasions. (APT) التهديدات املستمرة املتقدمة
مت إطالقه بواسطة املهاجم من خالل اخلداع للوصول مرة أخرى إلى شبكة املؤسسة • مصممة للتجسس على املدى الطويل •
غالباً ما يعمل مجرمو اإلنترنت الذين يحفزهم الربح في وضع التخفي ملواصلة األنشطة الطويلة األجل • يقوم املتسللون واملتسللون ، عادةً باستخدام البرامج الشخصية ، بتنفيذ هجمات كبيرة لتعزيز أسبابهم.
تعد Anonymous و LulzSec مجموعتني من املتطفلني الذين ارتكبوا انتهاكات جريئة للبيانات ، وتسويات • البيانات ، وتسريبات البيانات ، والسرقة ، والتهديدات ، وغزوات اخلصوصية.
Cri>cal Infrastructure ARacks
Figure 5.3 U.S. Cri+cal Infrastructure Sectors. Cri>cal infrastructure is defined as systems and assets so vital to the country that their incapacity or destruc>on would have a debilita>ng effect.
22
الشكل 3.5 قطاعات البنية التحتية احلرجة في الواليات املتحدة. تُعرَّف البنية التحتية احليوية بأنها أنظمة وأصول حيوية جدًا للبلد ، بحيث يكون لعجزها أو تدميرها تأثير ضعيف.
TheW of Intellectual Property • Intellectual Property is a work or inven>on that is the result of crea>vity that has commercial value.
• Includes copyrighted property such as a blueprint, manuscript or a design, and is protected by law from unauthorized use by others.
• Intellectual property can represent more than 80% of a company’s value.
• Losing customer data to hackers can be costly and embarrassing but losing intellectual property, commonly known as trade secrets, could threaten a company’s existence.
23
امللكية الفكرية هي عمل أو اختراع ينتج عن اإلبداع ذي القيمة التجارية. • يشمل املمتلكات احملمية بحقوق الطبع والنشر مثل مخطط أو مخطوطة أو تصميم ، ويحميها القانون من •
االستخدام غير املصرح به من قبل اآلخرين. ميكن أن متثل امللكية الفكرية أكثر من 80 ٪ من قيمة الشركة. •
ميكن أن يكون فقدان بيانات العميل للمتسللني أمرًا مكلفًا ومحرجًا ، لكن فقدان امللكية الفكرية ، املعروف • باسم األسرار التجارية ، ميكن أن يهدد وجود الشركة.
Iden>ty TheW
• One of the worst and most prevalent cyberthreats is iden>ty theW. o Made worse by electronic sharing and databases o Businesses reluctant to reveal incidents in which their
customers’ personal financial informa>on may have been stolen, lost, or compromised
24
واحدة من أسوأ وأخطر التهديدات السيبرانية هي سرقة الهوية. تفاقمت بسبب املشاركة اإللكترونية وقواعد البيانات •
حتجم الشركات عن الكشف عن احلوادث التي قد تكون قد سُرقت فيها املعلومات • املالية الشخصية لعمالئها أو فقدتها أو تعرضتها للخطر
Bring Your Own Device (BYOD) • Bring Your Own Device (BYOD): employees providing their own
(mobile) devices for business purposes to reduce expenses through cut purchase and maintenance costs.
• Roughly 74% of U.S. organiza>ons are using or planning to use BYOD • Cuts business costs by not having to purchase and maintain
employees’ mobile devices • Security risk: mobile devices rarely have strong authen>ca>on, access
controls, and encryp>on even though they connect to mission-cri>cal data and cloud services. Could also be lost or stolen.
25
إحضار اجلهاز اخلاص بك (BYOD): املوظفون الذين يوفرون أجهزتهم اخلاصة (املتنقلة) ألغراض • العمل لتقليل النفقات من خالل خفض تكاليف الشراء والصيانة.
BYOD ما يقرب من 74 ٪ من املنظمات األمريكية تستخدم أو تخطط الستخدام • يخفض تكاليف العمل بعدم االضطرار إلى شراء وصيانة األجهزة احملمولة للموظفني •
مخاطر األمان: نادراً ما تتمتع األجهزة احملمولة مبصادقة قوية ، وعناصر حتكم في الوصول ، وتشفير على • الرغم من اتصالها بالبيانات املهمة واخلدمات السحابية املهمة. ميكن أن تضيع أو سرقت.
Social Media ARacks • Social networks and cloud compu>ng increase vulnerabili>es by
providing a single point of failure and aRack for organized criminal networks.
• FBI: social media-related events have quadrupled over the past five years.
• Pricewaterhouse Coopers found that more than one in eight enterprises has suffered at least one security breach due to a social media-related cyberaRack.
• Facebook scams were the most common form of malware distributed in 2015.
26
الشبكات االجتماعية واحلوسبة السحابية تزيد من نقاط الضعف من خالل توفير نقطة واحدة من الفشل • والهجوم للشبكات اإلجرامية املنظمة.
• FBI: تضاعفت الفعاليات املرتبطة بالوسائط االجتماعية أربعة أضعاف خالل السنوات اخلمس املاضية. وجدت برايس ووترهاوس كوبرز أن أكثر من شركة واحدة من بني ثماني شركات عانت من خرق أمني واحد •
على األقل بسبب هجوم إلكتروني متصل بالوسائط االجتماعية. كانت حيل Facebook أكثر أشكال البرامج الضارة انتشارًا في عام 2015. •
Networks and Services Increase Exposure to Risk • Time-to-exploita>on is the elapsed >me between when vulnerability is discovered
and when it is exploited o Launched by aRacker through phishing to again access to enterprise’s network o Designed for long-term espionage o Profit-mo>vated cybercriminals oWen operate in stealth mode to con>nue
long-term ac>vi>es
• Hackers and hack>vists, commonly with personal agendas, carry out high-profile aRacks to further their causes. o Anonymous and LulzSec are two hacker groups who have commiRed daring
data breaches, data compromises, data leaks, theWs, threats, and privacy invasions.
27
وقت االستغالل هو الوقت املنقضي بني اكتشاف الثغرة األمنية ومتى يتم استغاللها مت إطالقه بواسطة املهاجم من خالل اخلداع للوصول مرة أخرى إلى شبكة املؤسسة •
مصممة للتجسس على املدى الطويل • غالباً ما يعمل مجرمو اإلنترنت الذين يحفزهم الربح في وضع التخفي ملواصلة األنشطة الطويلة األجل •
يقوم املتسللون واملتسللون ، عادةً باستخدام البرامج الشخصية ، بتنفيذ هجمات كبيرة لتعزيز أسبابهم. تعد Anonymous و LulzSec مجموعتني من املتطفلني الذين ارتكبوا انتهاكات جريئة للبيانات ، وتسويات •
البيانات ، وتسريبات البيانات ، والسرقة ، والتهديدات ، وغزوات اخلصوصية.
CyberaRack Targets and Consequences Review 1. What is a cri>cal infrastructure? 2. List three types of cri>cal infrastructures. 3. How do social network and cloud compu>ng increase vulnerability? 4. Why are patches and service packs needed? 5. Why is it important to protect intellectual property? 6. How are the mo>ves of hack>vists and APTs different? 7. Explain why data on laptops and computers need to be encrypted. 8. Explain how iden>ty theW can occur.
28
ما هي البنية التحتية احليوية؟ .1 اذكر ثالثة أنواع من البنى التحتية احليوية. .2
كيف الشبكة االجتماعية واحلوسبة السحابية تزيد من الضعف؟ .3 ملاذا هناك حاجة إلى بقع وحزم اخلدمة؟ .4
ما أهمية حماية امللكية الفكرية؟ .5 كيف هي دوافع املتسللني و APTs مختلفة؟ .6
اشرح سبب احلاجة إلى تشفير البيانات املوجودة على أجهزة الكمبيوتر احملمولة وأجهزة الكمبيوتر. .7 اشرح كيف ميكن أن حتدث سرقة الهوية. .8
Learning Objec>ves (3 of 5) 29
Cyber Risk Management • Risk is the probability of a threat successfully exploi>ng a vulnerability
and the es>mated cost of the loss or damage. • Factors leading to an increased risk of cyberaRack:
o Interconnected, interdependent, wirelessly networked business environment
o Smaller, faster, cheaper computers and storage devices o Decreasing skills necessary to be computer hacker o Interna>onal organized crime taking over cybercrime o Lack of management support
30
اخلطر هو احتمال وجود تهديد ينجح في استغالل الثغرة والتكلفة املقدرة للخسارة أو الضرر. • العوامل التي تؤدي إلى زيادة خطر الهجوم اإللكتروني: •
بيئة عمل مترابطة ومترابطة وشبكة السلكية § أجهزة كمبيوتر وأجهزة تخزين أصغر وأسرع وأرخص § انخفاض املهارات الالزمة ليكون القراصنة الكمبيوتر §
اجلرمية املنظمة الدولية التي تتعامل مع اجلرمية السيبرانية § نقص الدعم اإلداري §
IT Defenses • Some essen>al defenses organiza>ons can ins>tute to defend again cyberaRacks o An>virus SoWware: designed to detect malicious codes and prevent users
from downloading them. o Intrusion Detec>on Systems (IDSs): scans for unusual or suspicious traffic
(passive defense) o Intrusion Preven>on Systems (IPSs): is designed to take immediate ac>on
—such as blocking specific IP addresses—whenever a traffic-flow anomaly is detected (ac>ve defense)
• Security is an ongoing, unending process
31
ميكن لبعض مؤسسات الدفاع األساسية أن تدافع عن الهجمات اإللكترونية مرة أخرى • برنامج مكافحة الفيروسات: مصمم للكشف عن الرموز الضارة ومنع املستخدمني من تنزيلها. §
أنظمة كشف التسلل (IDS): تقوم مبسح بحثًا عن حركة مرور غير عادية أو مشبوهة (دفاع سلبي) § أنظمة منع التطفل (IPS): مت تصميمها التخاذ إجراء فوري - مثل حظر عناوين IP محددة - كلما مت اكتشاف §
حدوث خلل في تدفق حركة املرور (دفاع نشط) األمن هو عملية مستمرة ال تنتهي •
Figure 5.7 Basic IT security concepts
32
Security Defenses for Mobiles • Biometric Control is an automated method of verifying the iden>ty of
a person, based on physical or behavioral characteris>cs o The most common biometrics are a thumbprint or fingerprint, voice
print, re>nal scan, and signature. • Mobile biometrics can significantly improve the security of physical
devices and provide stronger authen>ca>on for remote access or cloud services.
• Voice biometrics are an effec>ve authen>ca>on solu>on across a wide range of consumer devices including smartphones, tablets, and TVs.
33
• Biometric Control هي طريقة آلية للتحقق من هوية الشخص ، بناءً على اخلصائص الفيزيائية أو السلوكية القياسات احليوية األكثر شيوعًا هي بصمة اإلبهام أو بصمة اإلصبع والطباعة الصوتية واملسح الشبكي والتوقيع.
القياسات احليوية املتنقلة ميكن أن حتسن بشكل كبير من أمن األجهزة املادية وتوفر مصادقة أقوى للوصول عن بعد أو • اخلدمات السحابية.
القياسات احليوية الصوتية هي حل مصادقة فعال عبر مجموعة واسعة من األجهزة االستهالكية مبا في ذلك الهواتف • الذكية واألجهزة اللوحية وأجهزة التلفزيون.
Addi>onal IT Defenses: Do-Not-Carry Rules • U.S. companies, government agencies, and organiza>ons may impose rules that assume mobile technologies will inevitably be compromised. o Only “clean” devices are allowed to be brought inside o Devices are forbidden from connec>ng while abroad o Some individuals carry no electronics on trips for compliance
34
قد تفرض الشركات األمريكية والوكاالت احلكومية واملؤسسات قواعد تفترض أن التقنيات احملمولة ستتعرض للخطر.
يُسمح فقط بدخول األجهزة "النظيفة" إلى الداخل • يحظر على األجهزة االتصال أثناء التواجد في اخلارج •
بعض األفراد ال يحملون إلكترونيات في رحالت لالمتثال •
Business Con>nuity Planning • Business con+nuity refers to maintaining business func>ons or restoring them quickly when there is a major disrup>on o A business con>nuity plan covers business processes, assets,
human resources, business partners o Keeps the business running aWer a disaster occurs o Covers fires, earthquakes, floods, power outages, malicious
aRacks, and other types of disasters
35
تشير استمرارية العمل إلى احلفاظ على وظائف العمل أو استعادتها بسرعة عند حدوث اضطراب كبير تغطي خطة استمرارية العمل العمليات التجارية واألصول واملوارد البشرية وشركاء األعمال •
يحافظ على سير العمل بعد حدوث كارثة • يغطي احلرائق والزالزل والفيضانات وانقطاع التيار الكهربائي والهجمات اخلبيثة وأنواع أخرى من •
الكوارث
Cyber Risk Management Review
1. Explain why it is becoming more important for organiza>ons to make cyber risk management a high priority?
2. Name four U.S. Government Regula>ons that relate to cyber risk management.
3. What is the purpose of Rogue Applica>on Monitoring? 4. Why is a mobile kill switch or remote wipe capability an
important part of managing cyber risk? 5. Why does an organiza>on need to have a business con>nuity
plan? 6. Name the three essen>al cybersecurity defenses. 7. Name three IT defenses. 8. Why do companies impose do-not-carry rules?
36
Learning Objec>ves (4 of 5) 37
Defending Against Fraud • Crime o Violent crime involves physical threat or harm o Nonviolent crime uses decep>on, confidence, and trickery by
abusing the power of their posi>on or by taking advantage of the trust ignorance, or laziness of others, otherwise known as fraud.
• Fraud o Occupa>onal fraud refers to the deliberate misuse of the
assets of one’s employer for personal gain.
38
جرمية اجلرمية العنيفة تنطوي على تهديد أو أذى جسدي •
تستخدم اجلرمية الالعنفية اخلداع والثقة واخلداع من خالل استغالل قوة مركزهم أو االستفادة من جهل الثقة أو • كسل اآلخرين ، واملعروف باسم االحتيال.
تزوير يشير االحتيال املهني إلى سوء االستخدام املتعمد ألصول صاحب العمل لتحقيق مكاسب شخصية. •
Occupa>onal Fraud Preven>on and Detec>on (1-2) • Corporate Governance o Enterprise-wide approach greatly increases the preven>on and detec>on of fraud
• Intelligent Analysis o Forms insider profiling to find wider paRerns of criminal networks.
39
حوكمة الشركات النهج على نطاق املؤسسة يزيد إلى حد كبير من منع والكشف عن االحتيال •
حتليل ذكي أشكال التنميط من الداخل للعثور على أمناط أوسع من الشبكات اإلجرامية. •
Occupa>onal Fraud Preven>on and Detec>on (2-2) • Anomaly Detec>on o Audit trails from key systems and personnel records used to detect anomalous paRers, such as excessive hours worked, devia>ons in paRerns of behavior, copying huge amounts of data, aRempts to override controls, unusual transac>ons, and inadequate documenta>on about a transac>on.
40
إكتشاف عيب خلقي مسارات التدقيق من النظم الرئيسية وسجالت املوظفني املستخدمة للكشف عن •
األنواع الشاذة ، مثل ساعات العمل املفرطة ، واالنحرافات في أمناط السلوك ، ونسخ كميات هائلة من البيانات ، ومحاوالت جتاوز الضوابط ، واملعامالت غير املعتادة ،
وعدم كفاية الوثائق املتعلقة باملعاملة
Internal Controls (IC) • A process to ensure that sensi>ve data are protected and accurate designed to achieve: o Reliability of financial repor>ng, to protect investors o Opera>onal efficiency o Compliance with laws, regula>ons, and policies o Safeguarding of assets
41
عملية للتأكد من أن البيانات احلساسة محمية ودقيقة مصممة لتحقيق: موثوقية التقارير املالية ، حلماية املستثمرين •
كفاءة العملية • االمتثال للقوانني واللوائح والسياسات •
حماية األصول •
Cyber Defense Strategies • The major objec>ves of Defense Strategies are:
o Preven>on and deterrence o Detec>on o Contain the Damage (damage control) o Recovery o Correc>on o Awareness and compliance
• Audi>ng can provide an addi>onal layer of safeguards.
42
األهداف الرئيسية الستراتيجيات الدفاع هي: الوقاية والردع •
كشف • حتتوي على الضرر (السيطرة على الضرر) •
التعافي • تصحيح •
الوعي واالمتثال • ميكن أن يوفر التدقيق طبقة إضافية من اإلجراءات الوقائية.
Defending Against Fraud Review 1. What defenses help prevent occupa>onal fraud? 2. What level of employee commits the most occupa>onal fraud? 3. What is the purpose of internal controls? 4. What federal law requires effec>ve internal controls? 5. Explain the concepts of Intelligence Analysis and Anomaly Detec>on. 6. Name the major categories of general controls. 7. Explain authen>ca>on and name two methods of authen>ca>on. 8. What are the six major objec>ves of a defense strategy?
43
ما هي الدفاعات التي تساعد في منع االحتيال املهني؟ .1 ما هو مستوى املوظف الذي يرتكب معظم عمليات االحتيال املهني؟ .2
ما هو الغرض من الضوابط الداخلية؟ .3 ما القانون الفيدرالي الذي يتطلب ضوابط داخلية فعالة؟ .4
شرح مفاهيم حتليل الذكاء والكشف عن الشذوذ. .5 اسم الفئات الرئيسية من الضوابط العامة. .6 اشرح املصادقة واسمي طريقتني للمصادقة. .7
ما هي األهداف الستة الرئيسية الستراتيجية الدفاع؟ .8
44
Frameworks, Standards, and Models • Current Frameworks and standards have been developed to address compliance: o Enterprise Risk Management (ERM) o Control Objec>ves for Informa>on and Related Technology
(COBIT) o Industry Standards, for example, Payment Card Industry Data
Security Standard (PCI DSS)
45
مت تطوير األطر واملعايير احلالية ملعاجلة االمتثال: (ERM) إدارة مخاطر املؤسسات •
(COBIT) أهداف التحكم للمعلومات والتكنولوجيا ذات الصلة • (PCI DSS) معايير الصناعة ، على سبيل املثال ، معيار أمان بيانات بطاقة الدفع •
Enterprise Risk Management Framework (ERM) • Risk-based approach to managing an enterprise • Developed by the CommiRee of Sponsoring Organiza>ons of the Treadway Commission (COSO) ERM
• Integrates internal control, the Sarbanes-Oxley Act mandates, and strategic planning
• Consists of eight components, listed in Table 5.13
46
النهج القائم على اخملاطر إلدارة املشاريع • Treadway (COSO) ERM التي وضعتها جلنة املنظمات الراعية للجنة • يدمج الرقابة الداخلية وتفويضات قانون ساربينز أوكسلي والتخطيط االستراتيجي •
يتكون من ثمانية مكونات ، مذكورة في اجلدول 13.5 •
Figure 5.11 COBIT 5 Principles COBIT 5 is the leading framework for the governance and security of IT
47
الشكل 11.5 مبادئ COBIT 5 ميثل COBIT 5 اإلطار الرئيسي حلوكمة تكنولوجيا املعلومات وأمنها
Industry Standards: Payment Card Industry Data Security Standard (PCI DSS) • Created by Visa, MasterCard, American Express, and Discover • Requires merchants and card payment providers to make certain their Web applica>ons are secure
• Improves customers’ trust in e-commerce • Increase the Web security of online merchants • Penal>es for noncompliance are severe
48
Discover و American Express و MasterCard و Visa مت إنشاؤها بواسطة • يتطلب التجار ومقدمي بطاقات الدفع للتأكد من أن تطبيقات الويب اخلاصة بهم آمنة •
يحسن ثقة العمالء في التجارة اإللكترونية • زيادة أمان الويب للتجار عبر اإلنترنت •
العقوبات لعدم االمتثال شديدة •
Figure 5.12 IT security defense-in-depth model.
49
Frameworks, Standards, and Models Review 1. Who created the Enterprise Risk Management Framework (ERM)? What is its
purpose?
2. What are the 5 principles of COBIT 5? Explain. 3. Why do industry groups have their own standards for cybersecurity? Name one
standard.
4. Are measurements of direct costs sufficient to reflect total damage sustained by a cyberaRack?
5. What 4 components comprise the IT Security Defense-in-Depth model? 6. What are the 4 steps in the IT Security Defense-in-Depth IT security model? 7. Explain why frameworks, standards, and models are important parts of a cybersecurity
program.
50
من الذي أنشأ إطار عمل إدارة مخاطر املؤسسات (ERM)؟ ما هو الغرض منه؟ .1 ما هي املبادئ 5 من COBIT 5؟ يشرح. .2
ملاذا مجموعات الصناعة لديها معاييرها اخلاصة لألمن السيبراني؟ اسم معيار واحد. .3 هل قياسات التكاليف املباشرة كافية لتعكس األضرار الكلية التي حلقت بالهجوم اإللكتروني؟ .4
ما املكونات األربعة التي تشتمل على منوذج الدفاع األمني في تقنية املعلومات؟ .5 ما هي اخلطوات األربع في منوذج أمان تكنولوجيا املعلومات اخلاص بالدفاع األمني؟ .6 اشرح سبب كون األطر واملعايير والنماذج أجزاء مهمة من برنامج األمن السيبراني. .7