Correction to project 2
RISK ASSESSMENT SUMMARY REPORT 1
Collins Deki
University of Maryland University College
Executive Report on
Risk Assessment Summary Report
August 26, 2018
Prepared by: Collins Deki, CISO
For: Maria Sosa, CIO
RISK ASSESSMENT SUMMARY REPORT 2
Table of Content
Executive Summary ……………………………………………………………………………3
Relevant external/environmental factors..…………………………………………………....4
Prioritized Risks and Response Matrix……………………………………………………….7
Recommended Risk Management Strategies and Technologies………………………..10
Risk Management Implementation Recommendations……………………………………11
Reference………………………………………………………………………………………21
RISK ASSESSMENT SUMMARY REPORT 3
Executive Summary
The purpose of this risk assessment report is to inform or educate the leadership of this
organization the cyber-attack risk that the organization faces. The assessment report will give an
overview of the organization’s information system, discuss the threats that the organization faces,
show the results of a recently conducted vulnerability assessment on the company’s information
system, proffer solutions on how to mitigate these risks and give recommendations accordingly.
Risk assessment critically examines the workplace and identifies processes, situations and things
that could pose a threat to the company; especially the employee, and finally analyze the severity
of the impact on the company. The importance of risk assessment cannot be over emphasized
because it enables the organization to detect threats in a timely manner and mitigate them.
Relevant external/environmental factors: There are different practices that industries
adopt to mitigate vulnerabilities and all threats according to their business needs. The following
are some of the external sources and standard best practices that some industries adopt in order to
mitigate vulnerabilities in the network and ensure business continuity.
1.) Secure configurations for network devices: A control system is a network device or set of
devices used to manage, command, direct, or regulate the behavior of other devices or
systems (Sans, 2015). They also implement policies that require devices that have been
taken out of the network to be scanned before gaining access back to the network. This
eliminates the issue of malwares getting into the network. 2.) Implementation of password protocol policy that requires users to protect their password.
Implementing this policy can be achieved with a well-documented training and
explanations so that everyone understands their role in the security structure of the
system. Establishing essential security practice and policies for employees is one of the
RISK ASSESSMENT SUMMARY REPORT 4
top ten security tips for small businesses (CITG, 2014). Organizations use this type of
policy to train their employees on password safety. Training for employees should occur
within the first week of joining the organization and reiterated quarterly if not monthly.
Training should include proper internet browsing techniques, common phishing
techniques, email spam and how to spot malware scams. It also provide the user with
skills that will be relevant outside the work environment. Employees who have not
undergone security training are likely to become a weak point, or may even introduce
vulnerabilities into the organization (Barwick, 2012). 3.) Closing unused open ports and the use of firewall that monitors open and closed ports is
one of the best practices. Open ports can cause a whole lot of problems ranging from
malware attacks or replication, exploiting vulnerabilities in other programs in the system
and could be the cause of downtime due to a denial of service (DOS) attack on the open
port. Open ports are the doorways to your network (Acunetix, 2014). 4.) Organizations also ensure that their employees are properly trained on how to handle
their devices while outside the network to prevent information from being stolen or
unauthorized access. They also ensure proper data encryption on devices such as laptops
and cellphone by procuring an endpoint encryption software and blocking every unused
ports. 5.) Organizations use varous types of intrusion detection system (IDS) to monitor traffic
going on the network and also search for suspicious activitites and threats. An IDS
application is very important in modern enterprise because it keeps an eye on any
malicious activities within the network. This is one of the best practices that industries
use to avert threats to the system. 6.) Another best practice in the business world is regular or a daily conference call with the
security teams and a business team representative to always review new vulnerabilities,
RISK ASSESSMENT SUMMARY REPORT 5
virus activity, malicious activity, and other critical security issues. Also, it is important to
have a well-documented process for reviewing new vulnerabilities as they come out.
Prioritized Risk Response Matrix
RISK ASSESSMENT SUMMARY REPORT 6
Assets Threat Risk Probabi lity
Mitigation Strategies
Potential Response
Prioritiza tion of Response s
Personal Computers
Theft/ Unattended device
Loss of important informatio n
High Encrypt the hard drive of personal computers. Revised Accepted use policy, standard, and guideline.
Report to the incident manageme nt team. Ensure that encryption is updated. Investigate
High
Organizatio n’s Workstatio ns
Vandalism, Unauthorize d physical access
Loss or damage of company asset
Medium Secure workstation with padlocks Revised policy and security measures for protecting company asset.
Report to the incident manageme nt team, the security team investigate
Low
Portable gadgets such as Mobile Phones or Tablets
Misuse of information systems
Unauthoriz ed access to the network and access to company’s informatio n or risk of being compromis ed Can easily be stolen
High Enroll portable devices for Mobile device management to enable a network administrato r to remotely push security policies and updates without any action by the user. Enable VPN environment
Investigate network log activities to illegal activities Ensure proper policy& Guideline is in place. Enforce Policy as and follow guidelines as stated. Ensure the devices are encrypted as stipulated by the policy in case it is stolen
High
Servers Damages resulting from penetration testing
Attacker to lunch denial-of- service (DoS) attacks
High firewall protection along with the protection from a DMZ Revised group Policy
Check configurati ons, Update patches. Investigate with tools like IDS,
High
RISK ASSESSMENT SUMMARY REPORT 7
Recommended Risk Management Strategies and Technologies
The risk associated with the threat from an outsider cannot be compared with that from
an insider because more harm is associated with the insider threat. In view of this, a robust
cybersecurity policy should be created and deployed to the network. These cybersecurity policies
should include;
• Enforcement of minimum password strength policy • The use of multi-factor authentication • Blocking users access to an unsafe and/or irrelevant websites • Disabling ports used for removable storage device in every computer in the
organization • Blocking unauthorized software from being downloaded • Disabling hyperlinks in emails to mitigate phishing scam • Automatic update for new patches and antivirus • Running a scan on the non-organization computer before giving access to the network • Enforcement of the strict use of Access Control Lists (ACLs) to limit rogue access. • Ensuring the devices are encrypted as stipulated by the policy in case it is stolen • Monthly educating and training employees on the new policy and cybersecurity best
practices to prevent social engineering. • Regularly deploy current cybersecurity trends to the web portal and educate
employees too. • Always ensure that software that are being purchased run on current security
environment and encryption protocols • Any user that violate the company’s security policy should be held accountable • Create a rapid incident management team that would swing into action when there is
an attack Cyber insurance is something that the organization should consider purchasing as this creates a
robust cybersecurity and business structure for the company. This is solely to transfer risk and not
deal with much financial loss in severe cases.
RISK ASSESSMENT SUMMARY REPORT 8
With these few recommendations, the organization would be well prepared for any attack and
the growing cybersecurity threats. This would also help the organization to maintain the
confidentially, integrity and availability of their system and curb financial expenditure on issues
like security (Rouse, 2018).
Risk Management Implementation Recommendations
There are different practices that industries adopt to mitigate vulnerabilities and all
threats. Some organizations use traditional scanning to detect vulnerabilities, but this approach
often fails because of the issues associated with a large amount of data. In light of this, different
industries explore different strategies that best suits their business.
One way to implement these recommendations is to ensure the security administration
team gives users access to their job role only. It is essential to determine the positions of all the
employees and grant their permissions accordingly with ACLs. Along with managing users by
their role, the data will also be protected by the need to know and least privileged access. The
goal of this security plan will be to have security in layers. These security controls can be
bypassed. However, the goal is to slow the attacker long enough to detect it.
Finally, an effective approach to risk management includes the processes of identifying
vulnerabilities and threats which should be a continuous process, evaluation of risks which gives
an idea of the threat that will have more impact on the organization, strategic mitigation of this
risk and effective monitoring and control processes (WorkCover, 2017).
RISK ASSESSMENT SUMMARY REPORT 9
.
Reference
ACUNETIX. (2014, April 23). Danger: Open Ports – Trojan is as Trojan does. Retrieved August 30,
2017, from http://www.acunetix.com/blog/articles/danger-open-ports-trojan-trojan/
Barwick, H. (2018). Security threats explained: Internal negligence. Retrieved from
http://www.computerworld.com.au/article/427471/security_threats_explained_internal_negligen
ce/
Bellovin, S., & Cheswick, W. (2018). Retrieved from
http://archives.cse.iitd.ernet.in/~sbansal/csl865/readings/bellovin-cheswick.pdf
Brackin, c. (2003). Vulnerability Management: Tools, Challenges, and Best Practices. [online] Sans.org.
Available at: https://www.sans.org/reading-room/whitepapers/threats/vulnerability-management-
tools-challenges-practices-1267 [Accessed 18 Aug. 2018].
Casey, B. (2018). Identifying and preventing router, switch and firewall vulnerabilities. Retrieved from
https://searchsecurity.techtarget.com/tip/Identifying-and-preventing-router-switch-and-firewall-
vulnerabilities
CITG. (2014). Top 10 security tips for small businesses. CITG. Retrieved from http://citig.com/lack-
understanding-causing-virtualizations-slow-adoption/
Four steps to manage hazardous manual task risks in the workplace. (2018). Retrieved from
https://www.worksafe.qld.gov.au/news/2016/four-steps-to-manage-hazardous-manual-task-risks-
in-the-workplace
Pratt, M. (2018). What is an intrusion detection system (IDS)? A valued function with significant
challenges. Retrieved from https://www.csoonline.com/article/3255632/network-security/what-
RISK ASSESSMENT SUMMARY REPORT 10
is-an-intrusion-detection-system-ids-a-valued-capability-with-serious-management-
challenges.html
“Products & Services,” Cisco, 2016. [Online]. Available: http://www.cisco.com/c/en/us/products.
[Accessed: 22- Aug- 2018].https://whatis.techtarget.com/definition/Confidentiality-integrity-and-
availability-CIA
Sans. (2015). CSC 10 System Entity Relationship Diagram. Retrieved March 31, 2015 from
https://www.sans.org/critical-security-controls/control/10
Sans. (2015). Secure Configurations for Network Devices such as Firewalls, Routers, and Switches.
Retrieved July 31, 2017 from https://www.sans.org/critical-security-controls/control/10
Thomas, J. (2018). Cisco Router/Switch Common Security Vulnerabilities and Router/Switch
Hardening. Retrieved from http://www.omnisecu.com/ccna-security/cisco-router-switch-
security-vulnerabilities-and-hardening.php
- Recommended Risk Management Strategies and Technologies