Project assignment :

profilenagiri
MSSecurityRiskManagementGuideThreats-Weaknesses-Countermeasures1.docx

Appendix B: Common Information Systems Assets

Asset Class

Overall IT Environment

Asset Name

Asset Rating

Highest level description of your asset

Next level definition (if needed)

Asset Value Rating

Tangible

Physical infrastructure

Data centers

5

Tangible

Physical infrastructure

Servers

3

Tangible

Physical infrastructure

Desktop computers

1

Tangible

Physical infrastructure

Mobile computers

3

Tangible

Physical infrastructure

PDAs

1

Tangible

Physical infrastructure

Cell phones

1

Tangible

Physical infrastructure

Server application software

1

Tangible

Physical infrastructure

End-user application software

1

Tangible

Physical infrastructure

Development tools

3

Tangible

Physical infrastructure

Routers

3

Tangible

Physical infrastructure

Network switches

3

Tangible

Physical infrastructure

Fax machines

1

Tangible

Physical infrastructure

PBXs

3

Tangible

Physical infrastructure

Removable media (tapes, floppy disks, CD-ROMs, DVDs, portable hard drives, PC card storage devices, USB storage devices, and so on.)

1

Tangible

Physical infrastructure

Power supplies

3

Tangible

Physical infrastructure

Uninterruptible power supplies

3

Tangible

Physical infrastructure

Fire suppression systems

3

Tangible

Physical infrastructure

Air conditioning systems

3

Tangible

Physical infrastructure

Air filtration systems

1

Tangible

Physical infrastructure

Other environmental control systems

3

Tangible

Intranet data

Source code

5

Tangible

Intranet data

Human resources data

5

Tangible

Intranet data

Financial data

5

Tangible

Intranet data

Marketing data

5

Tangible

Intranet data

Employee passwords

5

Tangible

Intranet data

Employee private cryptographic keys

5

Tangible

Intranet data

Computer system cryptographic keys

5

Tangible

Intranet data

Smart cards

5

Tangible

Intranet data

Intellectual property

5

Tangible

Intranet data

Data for regulatory requirements (GLBA, HIPAA, CA SB1386, EU Data Protection Directive, and so on.)

5

Tangible

Intranet data

U.S. Employee Social Security numbers

5

Tangible

Intranet data

Employee drivers' license numbers

5

Tangible

Intranet data

Strategic plans

3

Tangible

Intranet data

Customer consumer credit reports

5

Tangible

Intranet data

Customer medical records

5

Tangible

Intranet data

Employee biometric identifiers

5

Tangible

Intranet data

Employee business contact data

1

Tangible

Intranet data

Employee personal contact data

3

Tangible

Intranet data

Purchase order data

5

Tangible

Intranet data

Network infrastructure design

3

Tangible

Intranet data

Internal Web sites

3

Tangible

Intranet data

Employee ethnographic data

3

Tangible

Extranet data

Partner contract data

5

Tangible

Extranet data

Partner financial data

5

Tangible

Extranet data

Partner contact data

3

Tangible

Extranet data

Partner collaboration application

3

Tangible

Extranet data

Partner cryptographic keys

5

Tangible

Extranet data

Partner credit reports

3

Tangible

Extranet data

Partner purchase order data

3

Tangible

Extranet data

Supplier contract data

5

Asset Class

Overall IT Environment

Asset Name

Asset Rating

Highest level description of your asset

Next level definition (if needed)

Asset Value Rating

Tangible

Extranet data

Supplier collaboration application

3

Tangible

Extranet data

Supplier cryptographic keys

5

Tangible

Extranet data

Supplier credit reports

3

Tangible

Extranet data

Supplier purchase order data

3

Tangible

Internet data

Web site sales application

5

Tangible

Internet data

Web site marketing data

3

Tangible

Internet data

Customer credit card data

5

Tangible

Internet data

Customer contact data

3

Tangible

Internet data

Public cryptographic keys

1

Tangible

Internet data

Press releases

1

Tangible

Internet data

White papers

1

Tangible

Internet data

Product documentation

1

Tangible

Internet data

Training materials

3

Intangible

Reputation

5

Intangible

Goodwill

3

Intangible

Employee moral

3

Intangible

Employee productivity

3

IT Services

Messaging

E-mail/scheduling (for example, Microsoft Exchange)

3

IT Services

Messaging

Instant messaging

1

IT Services

Messaging

Microsoft Outlook® Web Access (OWA)

1

IT Services

Core infrastructure

Active Directory® directory service

3

IT Services

Core infrastructure

Domain Name System (DNS)

3

IT Services

Core infrastructure

Dynamic Host Configuration Protocol (DHCP)

3

IT Services

Core infrastructure

Enterprise management tools

3

IT Services

Core infrastructure

File sharing

3

IT Services

Core infrastructure

Storage

3

IT Services

Core infrastructure

Dial-up remote access

3

IT Services

Core infrastructure

Telephony

3

IT Services

Core infrastructure

Virtual Private Networking (VPN) access

3

IT Services

Core infrastructure

Microsoft Windows® Internet Naming Service (WINS)

1

Services

Other infrastructure

Collaboration services (for example, Microsoft SharePoint®)

Appendix C: Common Threats

Threat

Example

High level description of the threat

Specific example

Catastrophic incident

Fire

Catastrophic incident

Flood

Catastrophic incident

Earthquake

Catastrophic incident

Severe storm

Catastrophic incident

Terrorist attack

Catastrophic incident

Civil unrest/riots

Catastrophic incident

Landslide

Catastrophic incident

Avalanche

Catastrophic incident

Industrial accident

Mechanical failure

Power outage

Mechanical failure

Hardware failure

Mechanical failure

Network outage

Mechanical failure

Environmental controls failure

Mechanical failure

Construction accident

Non-malicious person

Uninformed employee

Non-malicious person

Uninformed user

Malicious person

Hacker, cracker

Malicious person

Computer criminal

Malicious person

Industrial espionage

Malicious person

Government sponsored espionage

Malicious person

Social engineering

Malicious person

Disgruntled current employee

Malicious person

Disgruntled former employee

Malicious person

Terrorist

Malicious person

Negligent employee

Malicious person

Dishonest employee (bribed or victim of blackmail)

Malicious person

Malicious mobile code

Appendix D: Vulnerabilties

Vulnerability Class

Vulnerability

Example

High level vulnerability class

Brief description of the vulnerability

Specific example (if applicable)

Physical

Unlocked doors

Physical

Unguarded access to computing facilities

Physical

Insufficient fire suppression systems

Physical

Poorly designed buildings

Physical

Poorly constructed buildings

Physical

Flammable materials used in construction

Physical

Flammable materials used in finishing

Physical

Unlocked windows

Physical

Walls susceptible to physical assault

Physical

Interior walls do not completely seal the room at both the ceiling and floor

Natural

Facility located on a fault line

Natural

Facility located in a flood zone

Natural

Facility located in an avalanche area

Hardware

Missing patches

Hardware

Outdated firmware

Hardware

Misconfigured systems

Hardware

Systems not physically secured

Hardware

Management protocols allowed over public interfaces

Software

Out of date antivirus software

Software

Missing patches

Software

Poorly written applications

Cross site scripting

Software

Poorly written applications

SQL injection

Software

Poorly written applications

Code weaknesses such as buffer overflows

Software

Deliberately placed weaknesses

Vendor backdoors for management or system recovery

Software

Deliberately placed weaknesses

Spyware such as keyloggers

Software

Deliberately placed weaknesses

Trojan horses

Software

Deliberately placed weaknesses

Software

Configuration errors

Manual provisioning leading to inconsistent configurations

Software

Configuration errors

Systems not hardened

Software

Configuration errors

Systems not audited

Software

Configuration errors

Systems not monitored

Media

Electrical interference

Communications

Unencrypted network protocols

Communications

Connections to multiple networks

Communications

Unnecessary protocols allowed

Communications

No filtering between network segments

Human

Poorly defined procedures

Insufficient incident response preparedness

Human

Poorly defined procedures

Manual provisioning

Human

Poorly defined procedures

Insufficient disaster recovery plans

Human

Poorly defined procedures

Testing on production systems

Human

Poorly defined procedures

Violations not reported

Human

Poorly defined procedures

Poor change control

Human

Stolen credentials

Page 3 Source: The Security Risk Management Guide Microsoft Corp.