Correction to project 2

profileIneedHelp9650
RISK_ASSESSMENT_SUMMARY_REPORTcollins_deki.docx.pdf

RISK ASSESSMENT SUMMARY REPORT 1

Collins Deki

University of Maryland University College

Executive Report on

Risk Assessment Summary Report

August 26, 2018

Prepared by: Collins Deki, CISO

For: Maria Sosa, CIO

RISK ASSESSMENT SUMMARY REPORT 2

Table of Content

Executive Summary ……………………………………………………………………………3

Relevant external/environmental factors..…………………………………………………....4

Prioritized Risks and Response Matrix……………………………………………………….7

Recommended Risk Management Strategies and Technologies………………………..10

Risk Management Implementation Recommendations……………………………………11

Reference………………………………………………………………………………………21

RISK ASSESSMENT SUMMARY REPORT 3

Executive Summary

The purpose of this risk assessment report is to inform or educate the leadership of this

organization the cyber-attack risk that the organization faces. The assessment report will give an

overview of the organization’s information system, discuss the threats that the organization faces,

show the results of a recently conducted vulnerability assessment on the company’s information

system, proffer solutions on how to mitigate these risks and give recommendations accordingly.

Risk assessment critically examines the workplace and identifies processes, situations and things

that could pose a threat to the company; especially the employee, and finally analyze the severity

of the impact on the company. The importance of risk assessment cannot be over emphasized

because it enables the organization to detect threats in a timely manner and mitigate them.

Relevant external/environmental factors: There are different practices that industries

adopt to mitigate vulnerabilities and all threats according to their business needs. The following

are some of the external sources and standard best practices that some industries adopt in order to

mitigate vulnerabilities in the network and ensure business continuity.

1.) Secure configurations for network devices: A control system is a network device or set of

devices used to manage, command, direct, or regulate the behavior of other devices or

systems (Sans, 2015). They also implement policies that require devices that have been

taken out of the network to be scanned before gaining access back to the network. This

eliminates the issue of malwares getting into the network. 2.) Implementation of password protocol policy that requires users to protect their password.

Implementing this policy can be achieved with a well-documented training and

explanations so that everyone understands their role in the security structure of the

system. Establishing essential security practice and policies for employees is one of the

RISK ASSESSMENT SUMMARY REPORT 4

top ten security tips for small businesses (CITG, 2014). Organizations use this type of

policy to train their employees on password safety. Training for employees should occur

within the first week of joining the organization and reiterated quarterly if not monthly.

Training should include proper internet browsing techniques, common phishing

techniques, email spam and how to spot malware scams. It also provide the user with

skills that will be relevant outside the work environment. Employees who have not

undergone security training are likely to become a weak point, or may even introduce

vulnerabilities into the organization (Barwick, 2012). 3.) Closing unused open ports and the use of firewall that monitors open and closed ports is

one of the best practices. Open ports can cause a whole lot of problems ranging from

malware attacks or replication, exploiting vulnerabilities in other programs in the system

and could be the cause of downtime due to a denial of service (DOS) attack on the open

port. Open ports are the doorways to your network (Acunetix, 2014). 4.) Organizations also ensure that their employees are properly trained on how to handle

their devices while outside the network to prevent information from being stolen or

unauthorized access. They also ensure proper data encryption on devices such as laptops

and cellphone by procuring an endpoint encryption software and blocking every unused

ports. 5.) Organizations use varous types of intrusion detection system (IDS) to monitor traffic

going on the network and also search for suspicious activitites and threats. An IDS

application is very important in modern enterprise because it keeps an eye on any

malicious activities within the network. This is one of the best practices that industries

use to avert threats to the system. 6.) Another best practice in the business world is regular or a daily conference call with the

security teams and a business team representative to always review new vulnerabilities,

RISK ASSESSMENT SUMMARY REPORT 5

virus activity, malicious activity, and other critical security issues. Also, it is important to

have a well-documented process for reviewing new vulnerabilities as they come out.

Prioritized Risk Response Matrix

RISK ASSESSMENT SUMMARY REPORT 6

Assets Threat Risk Probabi lity

Mitigation Strategies

Potential Response

Prioritiza tion of Response s

Personal Computers

Theft/ Unattended device

Loss of important informatio n

High Encrypt the hard drive of personal computers. Revised Accepted use policy, standard, and guideline.

Report to the incident manageme nt team. Ensure that encryption is updated. Investigate

High

Organizatio n’s Workstatio ns

Vandalism, Unauthorize d physical access

Loss or damage of company asset

Medium Secure workstation with padlocks Revised policy and security measures for protecting company asset.

Report to the incident manageme nt team, the security team investigate

Low

Portable gadgets such as Mobile Phones or Tablets

Misuse of information systems

Unauthoriz ed access to the network and access to company’s informatio n or risk of being compromis ed Can easily be stolen

High Enroll portable devices for Mobile device management to enable a network administrato r to remotely push security policies and updates without any action by the user. Enable VPN environment

Investigate network log activities to illegal activities Ensure proper policy& Guideline is in place. Enforce Policy as and follow guidelines as stated. Ensure the devices are encrypted as stipulated by the policy in case it is stolen

High

Servers Damages resulting from penetration testing

Attacker to lunch denial-of- service (DoS) attacks

High firewall protection along with the protection from a DMZ Revised group Policy

Check configurati ons, Update patches. Investigate with tools like IDS,

High

RISK ASSESSMENT SUMMARY REPORT 7

Recommended Risk Management Strategies and Technologies

The risk associated with the threat from an outsider cannot be compared with that from

an insider because more harm is associated with the insider threat. In view of this, a robust

cybersecurity policy should be created and deployed to the network. These cybersecurity policies

should include;

• Enforcement of minimum password strength policy • The use of multi-factor authentication • Blocking users access to an unsafe and/or irrelevant websites • Disabling ports used for removable storage device in every computer in the

organization • Blocking unauthorized software from being downloaded • Disabling hyperlinks in emails to mitigate phishing scam • Automatic update for new patches and antivirus • Running a scan on the non-organization computer before giving access to the network • Enforcement of the strict use of Access Control Lists (ACLs) to limit rogue access. • Ensuring the devices are encrypted as stipulated by the policy in case it is stolen • Monthly educating and training employees on the new policy and cybersecurity best

practices to prevent social engineering. • Regularly deploy current cybersecurity trends to the web portal and educate

employees too. • Always ensure that software that are being purchased run on current security

environment and encryption protocols • Any user that violate the company’s security policy should be held accountable • Create a rapid incident management team that would swing into action when there is

an attack Cyber insurance is something that the organization should consider purchasing as this creates a

robust cybersecurity and business structure for the company. This is solely to transfer risk and not

deal with much financial loss in severe cases.

RISK ASSESSMENT SUMMARY REPORT 8

With these few recommendations, the organization would be well prepared for any attack and

the growing cybersecurity threats. This would also help the organization to maintain the

confidentially, integrity and availability of their system and curb financial expenditure on issues

like security (Rouse, 2018).

Risk Management Implementation Recommendations

There are different practices that industries adopt to mitigate vulnerabilities and all

threats. Some organizations use traditional scanning to detect vulnerabilities, but this approach

often fails because of the issues associated with a large amount of data. In light of this, different

industries explore different strategies that best suits their business.

One way to implement these recommendations is to ensure the security administration

team gives users access to their job role only. It is essential to determine the positions of all the

employees and grant their permissions accordingly with ACLs. Along with managing users by

their role, the data will also be protected by the need to know and least privileged access. The

goal of this security plan will be to have security in layers. These security controls can be

bypassed. However, the goal is to slow the attacker long enough to detect it.

Finally, an effective approach to risk management includes the processes of identifying

vulnerabilities and threats which should be a continuous process, evaluation of risks which gives

an idea of the threat that will have more impact on the organization, strategic mitigation of this

risk and effective monitoring and control processes (WorkCover, 2017).

RISK ASSESSMENT SUMMARY REPORT 9

.

Reference

ACUNETIX. (2014, April 23). Danger: Open Ports – Trojan is as Trojan does. Retrieved August 30,

2017, from http://www.acunetix.com/blog/articles/danger-open-ports-trojan-trojan/

Barwick, H. (2018). Security threats explained: Internal negligence. Retrieved from

http://www.computerworld.com.au/article/427471/security_threats_explained_internal_negligen

ce/

Bellovin, S., & Cheswick, W. (2018). Retrieved from

http://archives.cse.iitd.ernet.in/~sbansal/csl865/readings/bellovin-cheswick.pdf

Brackin, c. (2003). Vulnerability Management: Tools, Challenges, and Best Practices. [online] Sans.org.

Available at: https://www.sans.org/reading-room/whitepapers/threats/vulnerability-management-

tools-challenges-practices-1267 [Accessed 18 Aug. 2018].

Casey, B. (2018). Identifying and preventing router, switch and firewall vulnerabilities. Retrieved from

https://searchsecurity.techtarget.com/tip/Identifying-and-preventing-router-switch-and-firewall-

vulnerabilities

CITG. (2014). Top 10 security tips for small businesses. CITG. Retrieved from http://citig.com/lack-

understanding-causing-virtualizations-slow-adoption/

Four steps to manage hazardous manual task risks in the workplace. (2018). Retrieved from

https://www.worksafe.qld.gov.au/news/2016/four-steps-to-manage-hazardous-manual-task-risks-

in-the-workplace

Pratt, M. (2018). What is an intrusion detection system (IDS)? A valued function with significant

challenges. Retrieved from https://www.csoonline.com/article/3255632/network-security/what-

RISK ASSESSMENT SUMMARY REPORT 10

is-an-intrusion-detection-system-ids-a-valued-capability-with-serious-management-

challenges.html

“Products & Services,” Cisco, 2016. [Online]. Available: http://www.cisco.com/c/en/us/products.

[Accessed: 22- Aug- 2018].https://whatis.techtarget.com/definition/Confidentiality-integrity-and-

availability-CIA

Sans. (2015). CSC 10 System Entity Relationship Diagram. Retrieved March 31, 2015 from

https://www.sans.org/critical-security-controls/control/10

Sans. (2015). Secure Configurations for Network Devices such as Firewalls, Routers, and Switches.

Retrieved July 31, 2017 from https://www.sans.org/critical-security-controls/control/10

Thomas, J. (2018). Cisco Router/Switch Common Security Vulnerabilities and Router/Switch

Hardening. Retrieved from http://www.omnisecu.com/ccna-security/cisco-router-switch-

security-vulnerabilities-and-hardening.php

  • Recommended Risk Management Strategies and Technologies