Case Study Analysis: Evaluating Risk Focused on Industry
Submission Ide: 7d645084-08c0-401d-8bf8-337b1f21be05
87% SIMILARITY SCORE 2 CITATION ITEMS 31 GRAMMAR ISSUES 0 FEEDBACK COMMENT Internet Source 0% Institution 87%
Felicitas Amana
Case Study Analysis: Evaluating Risk Focused on Industry
Summary
1736 Words
Potentially missing comma: 2021 2021,
Running head: INDUSTRY 1
Internet Security Threat Report
Felicitas Amana
Grand Canyon University
Instructor Name: Kelly Wibbenmeyer
MIS-657: Information Security Fundamentals
November 23, 2021
INDUSTRY 2
Overview
Threat Trend Summary
Student: Submitted to Grand Canyon University…
comprise of: comprise of comprise
Spelling mistake: Trustwave Trustee
Spelling mistake: Trustwave Trustee
2
Internet security is most challenging for global security, and it is more damaging to the
community and people than any other kind of threats such as terrorism. However, many of
common people do not understand that internet security threats and their damages which comprise
of hacking of websites, personal devices connected with internet, hospitals data, hotels booking,
travel, stealing people's information and identity, accessing organization's secret business data,
government secret information, financial scams and markets, other country infrastructure and
company intelligence and attacking on cloud-based software and services. Trustwave Holdings
Inc., company conducts research, prepare and release to the public every year on global security
and threat trend. Trustwave objective is to protect the clients from security risks by giving
awareness on security threats, statistics, and graphs. Threat trend report have information like who
are the attackers, why they attack, how they attack, what information they seek and future risk
trend etc. Executive summary reports include: compromised information, hacking of the emails,
website hacking, exploits, malicious threats, database, in addition to security of the networks
(Berry and Berry, 2018).
INDUSTRY 3
Threat Trend Graph
IT environment compromised trends:
Data compromised in industry:
Figure 1
3
INDUSTRY
4
Email Threat Trend
Figure 2
Malware threat trends
Figure 3
INDUSTRY 5
majority (most, usually) wh...: Majority Most
Checks that a sente...: submission Submission
Redundant phrase: some of the some
comma between indep...: asset and asset, and
verb acquire (get, develop): acquired get
comprises of: comprises of comprises
Student: Submitted to Grand Canyon University…
comprises of: comprises of comprises
5
Figure 4
Threat Definition
Threat is an attack on objects, people who intention to harm and danger to assets and
objects can be persons or organizations or countries. In the context of information technology,
threat refers to serious harm to the IT system and can cause serious damage to various fields
including software and network systems. Threats are possible vulnerabilities to run into attacks on
organization's applications, software services, networks and many other formats. Threats can put
organizations at risk, all vulnerabilities have to be fixed to avoid attackers to enter into their system
to damage and steal the data. Majority of information security threats involve many exploits and
threat includes viruses, spams, malware, Trojans, hackers and for example hacker can access into
organization's applications and induce viruses, break into network to gather information and threat
can be many forms including email attachment which has virus to spread into company network
on downloading attachment, hijacking application on any form (Biron, et.al, 2020, August).
INDUSTRY 6
submission and entered into company database to gain information and this is referred as SQL
Injection vulnerability and cross site scripting, open new window, password share etc.
Exploit is a software program that developed to attack on asset to take vulnerability control
and main object of exploits are to gain access on asset of organization and some of the examples
are gaining access to organization database to gather information and this is called data breach.
Exploits also attack on application vulnerability to gain remote access and run soft malware
software and attacks on operating systems. Exploits can be software or social scams by disclosing
the sensitive information of people or organization.
Identifying the Risk
Having the risk identified is one among the phases from the process of risk management
therefore, during this step, risks will be identified those harm or prevent the program, organization
to reaching its goals and risk identification includes documenting and communicating the concerns
for further steps. Risk identification process is identifying threats and vulnerabilities for given asset
and they are having the risk articulated, as well as rating the acquired risk exposure on a specific
scale. The phase of Risk assessment mainly comprises of: Risk Analysis, which is basically the
procedure that focuses on rating the probability of the unplanned happenings in addition to the
severity that is expected of the occurrence (Moon, et.al, 2018).
Organization assets include application servers, database systems, customer personal
information, sensitive vendor information and for every available asset it comprises of the sources
of information comprising of various systems, resources, applications, or browsers that can be
comprising of: comprising of comprising
Use an m-dash.: - —
Word repetition: High High High
6
impacted. Common assets for any organization are; software components, hardware components,
available information, the end-users, interfaces, supporting team, firm’s mission, criticality,
INDUSTRY 7
6
necessities, security regulations, architecture of the security as well as the network, information
storage safety, flow of data, controls of security as well as the physical security surrounding.
INDUSTRY 7
Risk Identification Table
Risk Id
Risk Title/Asset
Vulnerability Threat Impact Severity Likelihood Risk Value
R01 Servers Server rooms are getting older and air conditioning systems may fail.
Servers failure due to overheating in server room -High
Every service including websites, email etc. will become unavailable for hours - Critical
High High High
R02 Application Security Malicious Website Medium Medium- Potential
Word repetition: Medium Medium Medium
Use an m-dash.: – —
Word repetition: Low Low Low
Word repetition: Low Low Low
Word repetition: Low Low Low
Spelling mistake: sql SQL
Word repetition: Medium Medium Medium
Word repetition: Low Low Low
Word repetition: L L L
7
Websites- Critical to business
Firewall is enabled and has proper mitigation -Low
human interference -High
resources will become unavailable- Medium
Regular and frequent verification done
loss of thousands of dollars loss per hour time of down- Medium
R03 Network servers
Server rooms are higher floors of the building-Low
Natural disasters – Floods High
All servers will become unavailable Low
Low Final floods in the region where organization happened years ago- Low
Low
R04 Files, documents and database
Authorization s are configured properly, auditing of IT software is in implemented and back-up taken regularly- Low
Accidental Human interference, accidental file deletion, intentional attacks-High
Critical data might get lost but can it is recoverable from the backup -Medium
Low Low
R04 Applications software and network update
Application security measures taken care by fixing the sql
Unauthorized access to the applications by attacking through SQL
Applications can be hacked and gain control to the
High Medium Medium
INDUSTRY 8
8
injections with prepared statements than statements and have server side validation -Low
Injection, cross site scripting- High
database to retrieve sensitive data of clients- Medium
R05 Operating system update
Operating systems upgrade time to time and set auto reminder from the vendors -Low
Allow malicious virus software into the network systems and then interfere the business workflow and corrupt the systems which were working fine.
All systems running under that operating system stop working and behave strange -High
Low Low Medium
Probability and Impact Matrix Tool
Im pa ct
H
M
L
L M H
Probability
as per (as, in ac...: as per in accordance wi...
Passive voice: are considered to be
Possible typo: organizations
obtain (get): obtained get
Three successive sentences begin ...: Impact
Spelling mistake: Zeebaree Prepare
INDUSTRY 9
9
High Medium Low
Matrix No Value
Using probability and impact matrix table, determined the risk rankings and as per the
above two tables, organization servers are at high risk and critical to the company when air-
conditioning system failed in server rooms and for this risk likelihood is high when equipment is
older and impact also critical on servers so risk item categorized as high. Natural disaster risk
considered as low because probability is very rare low and impact also low because servers are not
in ground level. Risk for application websites and network servers considered as Medium because
the probability of threat attack medium and impact on the business also considered Medium.
Operating system update risk considered as low because likelihood is very low and impact would
be high on business.
Risk Measured
Organization risks are measured using various tools and one of them is probability and
impact matrix and risk is equal to probability of risk that is likelihood of incident occurrence
multiply by the threat impact to the company. As showing in the above table there are various
threats that organization can face in their daily business and some of them listed in the table with
risk title, threat type, vulnerability and impact to the organization and respective risk value
calculated based on the likelihood and impact values. Likelihood of occurrence can be a numerical
value with percentage of occurrence from 1 to 100. In this case, probability considered as category
of high, medium and low to assess the threat occurrence and probability calculated
INDUSTRY 10
based on each exploitable vulnerability taking into account, source of threat and existing and
effectiveness of organization controls.
Impact analysis of each threat identified with factors that are considered to be the
organizations system mission, inclusive of procedures adhered to by the organization, criticality
of the system which is determined by the worth of the information to the institution in addition to
sensitivity of the system as well as the data it has. Impact analysis obtained from existing
documents like BIA which uses qualitative or quantitative analysis to determine the impact caused
by data compromise, email attack, malware, web attack, application security, database, and
network security etc. of organization assets. Impact to the organization due to this attack can be
loss of data, confidentiality, availability, and integrity. As with probability of occurrence, the
impact on the organization can be high, medium, or low (Zeebaree, et.al, 2020).
Costs Associated for Threat Impact
in the case of (abou...: in the case of about
Spelling mistake: compliances compliance
10
Due to impact of each threat, there is amount of cost incurred to the organization to retain
the service back to normal and mainly for high risks involve more financial damage to the
organization and for example in the case of server failure due to air-conditioning outdated and this
case the probability is 75% and impact to the company i.e. server restore cost is
$500,000.000 then risk value for the company is 0.75*500,000.00 = $375,000.00.
Risk Control Recommendations
Based on risk level of each threat to the organization, risk mitigation actions to be taken by
the senior management of the organization and must follow some basic guidelines depends on the
level of risk. For example, high risk ones, corrective measures should be developed as early stage
as possible to avoid the risk. Medium risks can be taken care with proper measurable in the
allowable time and for low level risks, management can decide to accept the risk or
INDUSTRY 11
11
develop corrective actions if time permitted. Each mitigated risk to be considered cost benefit,
company policies, compliances, operational, regulations and feasibility.
INDUSTRY 13
13
References
Berry, C. T., & Berry, R. L. (2018). An initial assessment of small business risk management
approaches for cyber security threats. International Journal of Business Continuity and
Risk Management, 8(1), 1-10.
https://www.inderscienceonline.com/doi/abs/10.1504/IJBCRM.2018.090580
Biron, K., Bazzaza, W., Yaqoob, K., Gawanmeh, A., & Fachkha, C. (2020, August). A big data
fusion to profile CPS security threats against operational technology. In 2020 IEEE 21 st
International Symposium on” A World of Wireless, Mobile and Multimedia
Networks”(WoWMoM) (pp. 397-402). IEEE.
https://ieeexplore.ieee.org/abstract/document/9217658/
Moon, S. Y., Park, J. H., & Park, J. H. (2018). Authentications for Internet of Things Security:
Threats, Challenges and Studies. Journal of Internet Technology, 19(2), 349-358.
https://jit.ndhu.edu.tw/article/view/1655
Zeebaree, S., Ameen, S., & Sadeeq, M. (2020). Social media networks security threats, risks and
recommendation: A case study in the kurdistan region. International Journal of
Innovation, Creativity and Change, 13, 349-365.
https://www.researchgate.net/profile/Subhi-
Zeebaree/publication/348930053_Social_Media_Networks_Security_Threats_Risks_and
_Recommendation_A_Case_Study_in_the_Kurdistan_Region/links/6017c23545851517
ef2eb05b/Social-Media-Networks-Security-Threats-Risks-and-Recommendation-A-
Case-Study-in-the-Kurdistan-Region.pdf