Project 4: System Development or Application Assurance Step 13: Write the Risk Analysis/Supply Chain Threats/Mitigation Report

profilereed662
Security101.pdf

Security 101

Hank N. Williams, PMP, CISSP, CISM, GLEG

1

Information Security 101

2

3

Information systems security is the protection

of information systems against unauthorized

access to or modification of information,

whether in storage, processing or transit, and

against the denial of service to authorized

users, including those measures necessary to

detect, document, and counter such threats.

Source: National Security Telecommunications and Information Systems Security Committee (NSTISSC) NSTISSI No. 4009 National Information Systems Security (INFOSEC) Glossary, 26 April 2010

Information Systems Security

4

• A discrete set of information resources

organized for the collection, processing,

maintenance, use, sharing, dissemination,

or disposition of information. – Note: Information systems also include specialized

systems such as industrial/process controls systems,

telephone switching and private branch exchange

(PBX) systems, and environmental control systems.

Source: National Security Telecommunications and Information Systems Security Committee (NSTISSC) NSTISSI No. 4009 National Information Systems Security (INFOSEC) Glossary, 26 April 2010

Information Systems

5

C-I-A Triad

The C-I-A Triad are security goals that are utilized to determine the

security classification of the system and corresponding security

controls.

6

Confidentiality

• “Preserving authorized restrictions on information

access and disclosure, including means for protecting

personal privacy and proprietary information…” [44

U.S.C., Sec. 3542]

• A loss of confidentiality is the unauthorized disclosure

of information.

• Unauthorized, unanticipated, or unintentional

disclosure could result in loss of public confidence,

embarrassment, or legal action against the

organization.

6

7

Integrity

• “Guarding against improper information modification

or destruction, and includes ensuring information

non-repudiation and authenticity…” [44 U.S.C., Sec.

3542]

• A loss of integrity is the unauthorized modification or

destruction of information.

• Continued use of the contaminated system or

corrupted data could result in inaccuracy, fraud, or

erroneous decisions.

7

8

Availability

• “Ensuring timely and reliable access to and use of

information…” [44 U.S.C., SEC. 3542]

• A loss of availability is the disruption of access to or

use of information or an information system.

• Loss of system functionality and operational

effectiveness, for example, may result in loss of

productive time, thus impeding the end users’

performance of their functions in supporting the

organization’s mission.

8

9

Information systems security is the protection

of information systems against unauthorized

access (confidentiality) to or modification of

(integrity) information, whether in storage,

processing or transit, and against the denial of

service (availability) to authorized users,

including those measures necessary to detect,

document, and counter such threats.

Source: National Security Telecommunications and Information Systems Security Committee (NSTISSC) NSTISSI No. 4009 National Information Systems Security (INFOSEC) Glossary, 26 April 2010

Information Systems Security

10

Key Risk Management Terms

• Vulnerability

– Weakness in an information system, system

security procedures, internal controls, or

implementation that could be exploited by a threat

source.

– Vulnerabilities may exist at any point in the

enterprise. Personnel, facilities, software,

hardware, network components, and

documentation are examples of vulnerability

locations.

11

Key Risk Management Terms

• Threat

– Any circumstance or event with the potential to

adversely impact organizational operations

(including mission, functions, image, or reputation),

organizational assets, individuals, other

organizations, or the Nation through an information

system via unauthorized access, destruction,

disclosure, modification of information, and/or

denial of service.

12

Key Risk Management Terms

• Threat Source

– The intent and method targeted at the intentional

exploitation of a vulnerability or a situation and

method that may accidentally exploit a

vulnerability.

– 4 Types

• Adversarial

• Accidental

• Structural

• Environmental

13

Key Risk Management Terms

• Threat Types

– ADVERSARIAL

• Individual

• Group

• Organization

• Nation-State

14

Key Risk Management Terms

• Threat Types (continued)

– ACCIDENTAL

• User

• Privileged User/Administrator

15

Key Risk Management Terms

• Threat Types (continued)

– STRUCTURAL

• Information Technology (IT) Equipment

• Environmental Controls

• Software

16

Key Risk Management Terms

• Threat Types (continued)

– ENVIRONMENTAL

• Natural or man-made disaster

• Unusual Natural Event (e.g., sunspots)

• Infrastructure Failure/Outage

17

Key Risk Management Terms

• Attack

– Type of incident involving the intentional act of

attempting to bypass one or more security controls

of an IS.

– Also referred to as Attack Vectors

– Examples include Phishing, Denial of Service,

Hacking, etc.

– Attacks are executed by Adversarial Threats.

18

Key Risk Management Terms

• Security Incident Examples

– Website is unavailable for 12 hours due to excessive web

traffic.

• Threat: Adversarial

• Vulnerability: Lack of traffic management solution

• Attack: Denial of Service Attack

– Extended power outage at data center due to system wide

blackout

• Threat: Environmental

• Vulnerability: Lack of backup power solution

• Attack: No attack since it is not an intentional event.

19

Key Risk Management Terms

• Likelihood of Occurrence

– In Information Assurance risk analysis, a weighted

factor based on a subjective analysis of the

probability that a given threat is capable of

exploiting a given vulnerability.

20

Key Risk Management Terms

• Impact

– The level of impact from a threat event is the

magnitude of harm that can be expected to result

from the consequences of unauthorized disclosure

of information, unauthorized modification of

information, unauthorized destruction of

information, or loss of information or information

system availability.

Impact levels

21

• Low

– The potential impact is low if—The loss of confidentiality,

integrity, or availability could be expected to have a limited

adverse effect on organizational operations, organizational

assets, or individuals.

– A limited adverse effect means that, for example, the loss

of confidentiality, integrity, or availability might: (i) cause a

degradation in mission capability to an extent and duration

that the organization is able to perform its primary

functions, but the effectiveness of the functions is

noticeably reduced; (ii) result in minor damage to

organizational assets; (iii) result in minor financial loss; or

(iv) result in minor harm to individuals.

Impact levels

22

• Moderate

– The potential impact is moderate if—The loss of

confidentiality, integrity, or availability could be expected to

have a serious adverse effect on organizational

operations, organizational assets, or individuals.

– A serious adverse effect means that, for example, the loss

of confidentiality, integrity, or availability might: (i) cause a

significant degradation in mission capability to an extent

and duration that the organization is able to perform its

primary functions, but the effectiveness of the functions is

significantly reduced; (ii) result in significant damage to

organizational assets; (iii) result in significant financial loss;

or (iv) result in significant harm to individuals that does not

involve loss of life or serious life threatening injuries.

Impact levels

23

• High

– The potential impact is high if—The loss of confidentiality,

integrity, or availability could be expected to have a severe

or catastrophic adverse effect on organizational

operations, organizational assets, or individuals.

– A severe or catastrophic adverse effect means that, for

example, the loss of confidentiality, integrity, or availability

might: (i) cause a severe degradation in or loss of mission

capability to an extent and duration that the organization is

not able to perform one or more of its primary functions; (ii)

result in major damage to organizational assets; (iii) result

in major financial loss; or (iv) result in severe or

catastrophic harm to individuals involving loss of life or

serious life threatening injuries.

24

Key Risk Management Terms

• Risk

– A measure of the extent to which an entity is

threatened by a potential circumstance or event,

and typically a function of 1) the adverse impacts

that would arise if the circumstance or event

occurs; and 2) the likelihood of occurrence.

25

Key Risk Management Terms

• Risk Assessment

– The process of identifying, prioritizing, and

estimating risks. This includes determining the

extent to which adverse circumstances or events

could impact an enterprise. Uses the results of

threat and vulnerability assessments to identify risk

to organizational operations and evaluates those

risks in terms of likelihood of occurrence and

impacts if they occur. The product of a risk

assessment is a list of estimated, potential impacts

and unmitigated vulnerabilities.

26

Key Risk Management Terms

So how do we determine risk?

Threat x Vulnerability = Likelihood

Likelihood x Impact = Risk

Likelihood of Threat Event Initiation or

Occurrence

Likelihood Threat Events Result in Adverse Impacts

Very Low Low Moderate High Very High

Very High Low Moderate High Very High Very High

High Low Moderate Moderate High Very High

Moderate Low Low Moderate Moderate High

Low Very Low Low Low Moderate Moderate

Very Low Very Low Very Low Low Low Low

Key Risk Management Terms

• 4 courses of action to respond to risk

– Risk Acceptance: No action

– Risk Avoidance: Abort the activity that creates the

risk

– Risk Mitigation: Implementing the appropriate risk-

reducing controls/countermeasures recommended

from the risk management process.

– Risk Sharing or Transfer: Shifting liability and

responsibility to another organization.

• Residual Risk: Portion of risk remaining after security

measures have been applied. 27

28

Key Risk Management Terms

• Defense in Depth

– Information Security strategy integrating people,

technology, and operations capabilities to establish

variable barriers across multiple layers and

missions of the organization.

– The Onion Model

29

Key Risk Management Terms

• What are some examples of Defense in Depth?

– Policies

– Perimeter Defense

– IDS

– GPOs

– Anti-virus

– ???

30

Key Risk Management Terms

• Countermeasures

– Actions, devices, procedures, techniques, or other

measures that reduce the vulnerability of an

information system. Synonymous with security

controls and safeguards.

31

Risk Management Framework (RMF)

• RMF provides a disciplined and structured process

that integrates information security and risk

management activities into the system development

life cycle and consists of 6 steps.

– Step 1: Categorize the information system

– Step 2: Select the baseline security controls

– Step 3: Implement the security controls

– Step 4: Assess the security controls

– Step 5: Authorize information system operation

– Step 6: Monitor the security controls

• NIST SP 800-37

32

Risk Management Framework (RMF)

The Risk Management Process

33

The Risk Management Process

• Framing Risk

– Risk Assumptions

– Risk Constraints

– Risk Tolerance

– Priorities and tradeoffs

34

The Risk Management Process

• Assessing Risk to identify:

– Threats to organization

– Vulnerabilities internal and external to organization

– Harm (consequences/impact)

– Likelihood

35

The Risk Management Process

• Responding to Risk:

– Developing alternative courses of action.

– Evaluating the alternative courses of action.

– Determining appropriate courses of action.

– Implementing risk responses based on selected

courses of action.

36

The Risk Management Process

• Monitoring Risk:

– Verify that planned risk response measures are

implemented.

– Determine the ongoing effectiveness of risk

response measures.

– Identify risk-impacting changes to organizational

information systems and the environments in

which the systems operate.

37

Multi-tiered Risk Management Approach

38

Multi-tiered Risk Management Approach

• Tier One – Organization View

– Governance

– Risk Executive Function

– Risk Management Strategy

– Investment Strategies

39

Multi-tiered Risk Management Approach

• Tier Two – Mission/Business Process View

– Risk-Aware Mission/Business Processes

– Enterprise Architecture

– Information Security Architecture

40

Multi-tiered Risk Management Approach

• Tier Three – Information Systems View

– Integrating security into the SDLC

41

42

Questions?