Project 4: System Development or Application Assurance Step 13: Write the Risk Analysis/Supply Chain Threats/Mitigation Report
Security 101
Hank N. Williams, PMP, CISSP, CISM, GLEG
1
Information Security 101
2
3
Information systems security is the protection
of information systems against unauthorized
access to or modification of information,
whether in storage, processing or transit, and
against the denial of service to authorized
users, including those measures necessary to
detect, document, and counter such threats.
Source: National Security Telecommunications and Information Systems Security Committee (NSTISSC) NSTISSI No. 4009 National Information Systems Security (INFOSEC) Glossary, 26 April 2010
Information Systems Security
4
• A discrete set of information resources
organized for the collection, processing,
maintenance, use, sharing, dissemination,
or disposition of information. – Note: Information systems also include specialized
systems such as industrial/process controls systems,
telephone switching and private branch exchange
(PBX) systems, and environmental control systems.
Source: National Security Telecommunications and Information Systems Security Committee (NSTISSC) NSTISSI No. 4009 National Information Systems Security (INFOSEC) Glossary, 26 April 2010
Information Systems
5
C-I-A Triad
The C-I-A Triad are security goals that are utilized to determine the
security classification of the system and corresponding security
controls.
6
Confidentiality
• “Preserving authorized restrictions on information
access and disclosure, including means for protecting
personal privacy and proprietary information…” [44
U.S.C., Sec. 3542]
• A loss of confidentiality is the unauthorized disclosure
of information.
• Unauthorized, unanticipated, or unintentional
disclosure could result in loss of public confidence,
embarrassment, or legal action against the
organization.
6
7
Integrity
• “Guarding against improper information modification
or destruction, and includes ensuring information
non-repudiation and authenticity…” [44 U.S.C., Sec.
3542]
• A loss of integrity is the unauthorized modification or
destruction of information.
• Continued use of the contaminated system or
corrupted data could result in inaccuracy, fraud, or
erroneous decisions.
7
8
Availability
• “Ensuring timely and reliable access to and use of
information…” [44 U.S.C., SEC. 3542]
• A loss of availability is the disruption of access to or
use of information or an information system.
• Loss of system functionality and operational
effectiveness, for example, may result in loss of
productive time, thus impeding the end users’
performance of their functions in supporting the
organization’s mission.
8
9
Information systems security is the protection
of information systems against unauthorized
access (confidentiality) to or modification of
(integrity) information, whether in storage,
processing or transit, and against the denial of
service (availability) to authorized users,
including those measures necessary to detect,
document, and counter such threats.
Source: National Security Telecommunications and Information Systems Security Committee (NSTISSC) NSTISSI No. 4009 National Information Systems Security (INFOSEC) Glossary, 26 April 2010
Information Systems Security
10
Key Risk Management Terms
• Vulnerability
– Weakness in an information system, system
security procedures, internal controls, or
implementation that could be exploited by a threat
source.
– Vulnerabilities may exist at any point in the
enterprise. Personnel, facilities, software,
hardware, network components, and
documentation are examples of vulnerability
locations.
11
Key Risk Management Terms
• Threat
– Any circumstance or event with the potential to
adversely impact organizational operations
(including mission, functions, image, or reputation),
organizational assets, individuals, other
organizations, or the Nation through an information
system via unauthorized access, destruction,
disclosure, modification of information, and/or
denial of service.
12
Key Risk Management Terms
• Threat Source
– The intent and method targeted at the intentional
exploitation of a vulnerability or a situation and
method that may accidentally exploit a
vulnerability.
– 4 Types
• Adversarial
• Accidental
• Structural
• Environmental
13
Key Risk Management Terms
• Threat Types
– ADVERSARIAL
• Individual
• Group
• Organization
• Nation-State
14
Key Risk Management Terms
• Threat Types (continued)
– ACCIDENTAL
• User
• Privileged User/Administrator
15
Key Risk Management Terms
• Threat Types (continued)
– STRUCTURAL
• Information Technology (IT) Equipment
• Environmental Controls
• Software
16
Key Risk Management Terms
• Threat Types (continued)
– ENVIRONMENTAL
• Natural or man-made disaster
• Unusual Natural Event (e.g., sunspots)
• Infrastructure Failure/Outage
17
Key Risk Management Terms
• Attack
– Type of incident involving the intentional act of
attempting to bypass one or more security controls
of an IS.
– Also referred to as Attack Vectors
– Examples include Phishing, Denial of Service,
Hacking, etc.
– Attacks are executed by Adversarial Threats.
18
Key Risk Management Terms
• Security Incident Examples
– Website is unavailable for 12 hours due to excessive web
traffic.
• Threat: Adversarial
• Vulnerability: Lack of traffic management solution
• Attack: Denial of Service Attack
– Extended power outage at data center due to system wide
blackout
• Threat: Environmental
• Vulnerability: Lack of backup power solution
• Attack: No attack since it is not an intentional event.
19
Key Risk Management Terms
• Likelihood of Occurrence
– In Information Assurance risk analysis, a weighted
factor based on a subjective analysis of the
probability that a given threat is capable of
exploiting a given vulnerability.
20
Key Risk Management Terms
• Impact
– The level of impact from a threat event is the
magnitude of harm that can be expected to result
from the consequences of unauthorized disclosure
of information, unauthorized modification of
information, unauthorized destruction of
information, or loss of information or information
system availability.
Impact levels
21
• Low
– The potential impact is low if—The loss of confidentiality,
integrity, or availability could be expected to have a limited
adverse effect on organizational operations, organizational
assets, or individuals.
– A limited adverse effect means that, for example, the loss
of confidentiality, integrity, or availability might: (i) cause a
degradation in mission capability to an extent and duration
that the organization is able to perform its primary
functions, but the effectiveness of the functions is
noticeably reduced; (ii) result in minor damage to
organizational assets; (iii) result in minor financial loss; or
(iv) result in minor harm to individuals.
Impact levels
22
• Moderate
– The potential impact is moderate if—The loss of
confidentiality, integrity, or availability could be expected to
have a serious adverse effect on organizational
operations, organizational assets, or individuals.
– A serious adverse effect means that, for example, the loss
of confidentiality, integrity, or availability might: (i) cause a
significant degradation in mission capability to an extent
and duration that the organization is able to perform its
primary functions, but the effectiveness of the functions is
significantly reduced; (ii) result in significant damage to
organizational assets; (iii) result in significant financial loss;
or (iv) result in significant harm to individuals that does not
involve loss of life or serious life threatening injuries.
–
Impact levels
23
• High
– The potential impact is high if—The loss of confidentiality,
integrity, or availability could be expected to have a severe
or catastrophic adverse effect on organizational
operations, organizational assets, or individuals.
– A severe or catastrophic adverse effect means that, for
example, the loss of confidentiality, integrity, or availability
might: (i) cause a severe degradation in or loss of mission
capability to an extent and duration that the organization is
not able to perform one or more of its primary functions; (ii)
result in major damage to organizational assets; (iii) result
in major financial loss; or (iv) result in severe or
catastrophic harm to individuals involving loss of life or
serious life threatening injuries.
24
Key Risk Management Terms
• Risk
– A measure of the extent to which an entity is
threatened by a potential circumstance or event,
and typically a function of 1) the adverse impacts
that would arise if the circumstance or event
occurs; and 2) the likelihood of occurrence.
25
Key Risk Management Terms
• Risk Assessment
– The process of identifying, prioritizing, and
estimating risks. This includes determining the
extent to which adverse circumstances or events
could impact an enterprise. Uses the results of
threat and vulnerability assessments to identify risk
to organizational operations and evaluates those
risks in terms of likelihood of occurrence and
impacts if they occur. The product of a risk
assessment is a list of estimated, potential impacts
and unmitigated vulnerabilities.
26
Key Risk Management Terms
So how do we determine risk?
Threat x Vulnerability = Likelihood
Likelihood x Impact = Risk
Likelihood of Threat Event Initiation or
Occurrence
Likelihood Threat Events Result in Adverse Impacts
Very Low Low Moderate High Very High
Very High Low Moderate High Very High Very High
High Low Moderate Moderate High Very High
Moderate Low Low Moderate Moderate High
Low Very Low Low Low Moderate Moderate
Very Low Very Low Very Low Low Low Low
Key Risk Management Terms
• 4 courses of action to respond to risk
– Risk Acceptance: No action
– Risk Avoidance: Abort the activity that creates the
risk
– Risk Mitigation: Implementing the appropriate risk-
reducing controls/countermeasures recommended
from the risk management process.
– Risk Sharing or Transfer: Shifting liability and
responsibility to another organization.
• Residual Risk: Portion of risk remaining after security
measures have been applied. 27
28
Key Risk Management Terms
• Defense in Depth
– Information Security strategy integrating people,
technology, and operations capabilities to establish
variable barriers across multiple layers and
missions of the organization.
– The Onion Model
29
Key Risk Management Terms
• What are some examples of Defense in Depth?
– Policies
– Perimeter Defense
– IDS
– GPOs
– Anti-virus
– ???
30
Key Risk Management Terms
• Countermeasures
– Actions, devices, procedures, techniques, or other
measures that reduce the vulnerability of an
information system. Synonymous with security
controls and safeguards.
31
Risk Management Framework (RMF)
• RMF provides a disciplined and structured process
that integrates information security and risk
management activities into the system development
life cycle and consists of 6 steps.
– Step 1: Categorize the information system
– Step 2: Select the baseline security controls
– Step 3: Implement the security controls
– Step 4: Assess the security controls
– Step 5: Authorize information system operation
– Step 6: Monitor the security controls
• NIST SP 800-37
32
Risk Management Framework (RMF)
The Risk Management Process
33
The Risk Management Process
• Framing Risk
– Risk Assumptions
– Risk Constraints
– Risk Tolerance
– Priorities and tradeoffs
34
The Risk Management Process
• Assessing Risk to identify:
– Threats to organization
– Vulnerabilities internal and external to organization
– Harm (consequences/impact)
– Likelihood
35
The Risk Management Process
• Responding to Risk:
– Developing alternative courses of action.
– Evaluating the alternative courses of action.
– Determining appropriate courses of action.
– Implementing risk responses based on selected
courses of action.
36
The Risk Management Process
• Monitoring Risk:
– Verify that planned risk response measures are
implemented.
– Determine the ongoing effectiveness of risk
response measures.
– Identify risk-impacting changes to organizational
information systems and the environments in
which the systems operate.
37
Multi-tiered Risk Management Approach
38
Multi-tiered Risk Management Approach
• Tier One – Organization View
– Governance
– Risk Executive Function
– Risk Management Strategy
– Investment Strategies
39
Multi-tiered Risk Management Approach
• Tier Two – Mission/Business Process View
– Risk-Aware Mission/Business Processes
– Enterprise Architecture
– Information Security Architecture
40
Multi-tiered Risk Management Approach
• Tier Three – Information Systems View
– Integrating security into the SDLC
41
42
Questions?