Case Study Analysis: Evaluating Risk Focused on Industry

profileLoic@1313
ReportPDF1-fa.pdf

Submission Ide: 7d645084-08c0-401d-8bf8-337b1f21be05

87% SIMILARITY SCORE 2   CITATION ITEMS 31   GRAMMAR ISSUES 0   FEEDBACK COMMENT Internet Source   0% Institution   87%

Felicitas Amana

Case Study Analysis: Evaluating Risk Focused on Industry

Summary

 1736 Words  

 Potentially missing comma: 2021  2021,

Running head: INDUSTRY 1

Internet Security Threat Report

Felicitas Amana

Grand Canyon University

Instructor Name: Kelly Wibbenmeyer

MIS-657: Information Security Fundamentals

November 23, 2021

INDUSTRY 2

Overview

Threat Trend Summary

 Student: Submitted to Grand Canyon University…

 comprise of: comprise of  comprise

 Spelling mistake: Trustwave  Trustee

 Spelling mistake: Trustwave  Trustee

2

Internet security is most challenging for global security, and it is more damaging to the

community and people than any other kind of threats such as terrorism. However, many of

common people do not understand that internet security threats and their damages which comprise

of hacking of websites, personal devices connected with internet, hospitals data, hotels booking,

travel, stealing people's information and identity, accessing organization's secret business data,

government secret information, financial scams and markets, other country infrastructure and

company intelligence and attacking on cloud-based software and services. Trustwave Holdings

Inc., company conducts research, prepare and release to the public every year on global security

and threat trend. Trustwave objective is to protect the clients from security risks by giving

awareness on security threats, statistics, and graphs. Threat trend report have information like who

are the attackers, why they attack, how they attack, what information they seek and future risk

trend etc. Executive summary reports include: compromised information, hacking of the emails,

website hacking, exploits, malicious threats, database, in addition to security of the networks

(Berry and Berry, 2018).

INDUSTRY 3

Threat Trend Graph

IT environment compromised trends:

Data compromised in industry:

Figure 1

3

INDUSTRY

4

Email Threat Trend

Figure 2

Malware threat trends

Figure 3

INDUSTRY 5

 majority (most, usually) wh...: Majority  Most

 Checks that a sente...: submission  Submission

 Redundant phrase: some of the  some

 comma between indep...: asset and  asset, and

 verb acquire (get, develop): acquired  get

 comprises of: comprises of  comprises

 Student: Submitted to Grand Canyon University…

 comprises of: comprises of  comprises

5

Figure 4

Threat Definition

Threat is an attack on objects, people who intention to harm and danger to assets and

objects can be persons or organizations or countries. In the context of information technology,

threat refers to serious harm to the IT system and can cause serious damage to various fields

including software and network systems. Threats are possible vulnerabilities to run into attacks on

organization's applications, software services, networks and many other formats. Threats can put

organizations at risk, all vulnerabilities have to be fixed to avoid attackers to enter into their system

to damage and steal the data. Majority of information security threats involve many exploits and

threat includes viruses, spams, malware, Trojans, hackers and for example hacker can access into

organization's applications and induce viruses, break into network to gather information and threat

can be many forms including email attachment which has virus to spread into company network

on downloading attachment, hijacking application on any form (Biron, et.al, 2020, August).

INDUSTRY 6

submission and entered into company database to gain information and this is referred as SQL

Injection vulnerability and cross site scripting, open new window, password share etc.

Exploit is a software program that developed to attack on asset to take vulnerability control

and main object of exploits are to gain access on asset of organization and some of the examples

are gaining access to organization database to gather information and this is called data breach.

Exploits also attack on application vulnerability to gain remote access and run soft malware

software and attacks on operating systems. Exploits can be software or social scams by disclosing

the sensitive information of people or organization.

Identifying the Risk

Having the risk identified is one among the phases from the process of risk management

therefore, during this step, risks will be identified those harm or prevent the program, organization

to reaching its goals and risk identification includes documenting and communicating the concerns

for further steps. Risk identification process is identifying threats and vulnerabilities for given asset

and they are having the risk articulated, as well as rating the acquired risk exposure on a specific

scale. The phase of Risk assessment mainly comprises of: Risk Analysis, which is basically the

procedure that focuses on rating the probability of the unplanned happenings in addition to the

severity that is expected of the occurrence (Moon, et.al, 2018).

Organization assets include application servers, database systems, customer personal

information, sensitive vendor information and for every available asset it comprises of the sources

of information comprising of various systems, resources, applications, or browsers that can be

 comprising of: comprising of  comprising

 Use an m-dash.: -  —

 Word repetition: High High  High

6

impacted. Common assets for any organization are; software components, hardware components,

available information, the end-users, interfaces, supporting team, firm’s mission, criticality,

INDUSTRY 7

6

necessities, security regulations, architecture of the security as well as the network, information

storage safety, flow of data, controls of security as well as the physical security surrounding.

INDUSTRY 7

Risk Identification Table

Risk Id

Risk Title/Asset

Vulnerability Threat Impact Severity Likelihood Risk Value

R01 Servers Server rooms are getting older and air conditioning systems may fail.

Servers failure due to overheating in server room -High

Every service including websites, email etc. will become unavailable for hours - Critical

High High High

R02 Application Security Malicious Website Medium Medium- Potential

 Word repetition: Medium Medium  Medium

 Use an m-dash.: –  —

 Word repetition: Low Low  Low

 Word repetition: Low Low  Low

 Word repetition: Low Low  Low

 Spelling mistake: sql  SQL

 Word repetition: Medium Medium  Medium

 Word repetition: Low Low  Low

 Word repetition: L L  L

7

Websites- Critical to business

Firewall is enabled and has proper mitigation -Low

human interference -High

resources will become unavailable- Medium

Regular and frequent verification done

loss of thousands of dollars loss per hour time of down- Medium

R03 Network servers

Server rooms are higher floors of the building-Low

Natural disasters – Floods High

All servers will become unavailable Low

Low Final floods in the region where organization happened years ago- Low

Low

R04 Files, documents and database

Authorization s are configured properly, auditing of IT software is in implemented and back-up taken regularly- Low

Accidental Human interference, accidental file deletion, intentional attacks-High

Critical data might get lost but can it is recoverable from the backup -Medium

Low Low

R04 Applications software and network update

Application security measures taken care by fixing the sql

Unauthorized access to the applications by attacking through SQL

Applications can be hacked and gain control to the

High Medium Medium

INDUSTRY 8

8

injections with prepared statements than statements and have server side validation -Low

Injection, cross site scripting- High

database to retrieve sensitive data of clients- Medium

R05 Operating system update

Operating systems upgrade time to time and set auto reminder from the vendors -Low

Allow malicious virus software into the network systems and then interfere the business workflow and corrupt the systems which were working fine.

All systems running under that operating system stop working and behave strange -High

Low Low Medium

Probability and Impact Matrix Tool

Im pa ct

H

M

L

L M H

Probability

 as per (as, in ac...: as per  in accordance wi...

 Passive voice: are considered to be

 Possible typo: organizations

 obtain (get): obtained  get

 Three successive sentences begin ...: Impact

 Spelling mistake: Zeebaree  Prepare

INDUSTRY 9

9

High Medium Low

Matrix No Value

Using probability and impact matrix table, determined the risk rankings and as per the

above two tables, organization servers are at high risk and critical to the company when air-

conditioning system failed in server rooms and for this risk likelihood is high when equipment is

older and impact also critical on servers so risk item categorized as high. Natural disaster risk

considered as low because probability is very rare low and impact also low because servers are not

in ground level. Risk for application websites and network servers considered as Medium because

the probability of threat attack medium and impact on the business also considered Medium.

Operating system update risk considered as low because likelihood is very low and impact would

be high on business.

Risk Measured

Organization risks are measured using various tools and one of them is probability and

impact matrix and risk is equal to probability of risk that is likelihood of incident occurrence

multiply by the threat impact to the company. As showing in the above table there are various

threats that organization can face in their daily business and some of them listed in the table with

risk title, threat type, vulnerability and impact to the organization and respective risk value

calculated based on the likelihood and impact values. Likelihood of occurrence can be a numerical

value with percentage of occurrence from 1 to 100. In this case, probability considered as category

of high, medium and low to assess the threat occurrence and probability calculated

INDUSTRY 10

based on each exploitable vulnerability taking into account, source of threat and existing and

effectiveness of organization controls.

Impact analysis of each threat identified with factors that are considered to be the

organizations system mission, inclusive of procedures adhered to by the organization, criticality

of the system which is determined by the worth of the information to the institution in addition to

sensitivity of the system as well as the data it has. Impact analysis obtained from existing

documents like BIA which uses qualitative or quantitative analysis to determine the impact caused

by data compromise, email attack, malware, web attack, application security, database, and

network security etc. of organization assets. Impact to the organization due to this attack can be

loss of data, confidentiality, availability, and integrity. As with probability of occurrence, the

impact on the organization can be high, medium, or low (Zeebaree, et.al, 2020).

Costs Associated for Threat Impact

 in the case of (abou...: in the case of  about

 Spelling mistake: compliances  compliance

10

Due to impact of each threat, there is amount of cost incurred to the organization to retain

the service back to normal and mainly for high risks involve more financial damage to the

organization and for example in the case of server failure due to air-conditioning outdated and this

case the probability is 75% and impact to the company i.e. server restore cost is

$500,000.000 then risk value for the company is 0.75*500,000.00 = $375,000.00.

Risk Control Recommendations

Based on risk level of each threat to the organization, risk mitigation actions to be taken by

the senior management of the organization and must follow some basic guidelines depends on the

level of risk. For example, high risk ones, corrective measures should be developed as early stage

as possible to avoid the risk. Medium risks can be taken care with proper measurable in the

allowable time and for low level risks, management can decide to accept the risk or

INDUSTRY 11

11

develop corrective actions if time permitted. Each mitigated risk to be considered cost benefit,

company policies, compliances, operational, regulations and feasibility.

INDUSTRY 13

13

References

Berry, C. T., & Berry, R. L. (2018). An initial assessment of small business risk management

approaches for cyber security threats. International Journal of Business Continuity and

Risk Management, 8(1), 1-10.

https://www.inderscienceonline.com/doi/abs/10.1504/IJBCRM.2018.090580

Biron, K., Bazzaza, W., Yaqoob, K., Gawanmeh, A., & Fachkha, C. (2020, August). A big data

fusion to profile CPS security threats against operational technology. In 2020 IEEE 21 st

International Symposium on” A World of Wireless, Mobile and Multimedia

Networks”(WoWMoM) (pp. 397-402). IEEE.

https://ieeexplore.ieee.org/abstract/document/9217658/

Moon, S. Y., Park, J. H., & Park, J. H. (2018). Authentications for Internet of Things Security:

Threats, Challenges and Studies. Journal of Internet Technology, 19(2), 349-358.

https://jit.ndhu.edu.tw/article/view/1655

Zeebaree, S., Ameen, S., & Sadeeq, M. (2020). Social media networks security threats, risks and

recommendation: A case study in the kurdistan region. International Journal of

Innovation, Creativity and Change, 13, 349-365.

https://www.researchgate.net/profile/Subhi-

Zeebaree/publication/348930053_Social_Media_Networks_Security_Threats_Risks_and

_Recommendation_A_Case_Study_in_the_Kurdistan_Region/links/6017c23545851517

ef2eb05b/Social-Media-Networks-Security-Threats-Risks-and-Recommendation-A-

Case-Study-in-the-Kurdistan-Region.pdf