8-10 pages
Round 4
Team Members:
Robert Antis
Terry Martin Brown
John Francis Hung Scott
Candy Anna Sigel
Jacqueline Ann Snyder
UMUC
CSEC 670
Turnitin Originality Score ______X%_____
1.0 Introduction
Following the recent success in thwarting the Laetis Trojan attack, Hytema was faced with a bigger threat in this round: a cyber-terrorist attack. Hytema, and the Federal government, were notified at the beginning of the week of attempts to attack the network and shut down all functionality. With high risk and high impact on the company if an act of cyber terrorism was successful, Hytema’s security team set off to best secure the network to defend against it. However, there was a catch involved – to do so while dealing with a smaller budget to work with and trying to cut spending at the same time.
2.0 Decision Goals and Rationale
For the members of Hytema’s security team, round four did not have much in the way of differing opinions on how to go about changing settings in their particular positions. It was also clear from the results of the previous round that a focus on improving downtime, customer satisfaction, and employee morale, should be made; but the chase to do so may have been too much to overcome this late in. Hytema continued the trend of small changes in the indicators in this round, both positive and negative, and last week’s debate seems to have had an impact on the choices that were made.
One of the members had a suggestion for the team to keep in mind as decisions were being made for this week’s event. That plan consisted of changing as many settings as possible to their highest levels. Considering the severity of a cyber-terrorist threat, this suggestion would be sound advice because Hytema does not want to fall victim to such a high risk event. Almost any setting being set too low could serve as an avenue that could be exploited and give the company unsatisfactory results. Furthermore, this could give the company some insulation against any downtrends, and accentuate any upward trends, based on the Federal government’s actions for this event. The other suggestion was more direct: completely disable all honeypots. The concern stems from the possibility that cyber terrorists could use the honeypots, and the tools hosted on them, against the network.
Nevertheless, the security team still had to deal with the same three indicators that have given it problems for weeks now, as well as a severely cut spending budget. This made it difficult to consider changing settings to their absolute maximum. Along the way, members of the team made some common sense compromises on certain settings in an attempt to reduce spending and attempt to improve the worst indicators.
3.0 Changes by Roles and Rationales
Chief Information Security Officer (CISO)
Changes this week:
1. Openness of breach notification was changed to only critical incidents, and the NSA and FBI would be notified of major security breaches.
2. In BCP, the number of power backup redundancy, backup sites, and redundant communication links were reduced to 1 each. The policy review frequency will now be every 12 months.
3. For the training areas, fund allocations for controls & encryption increased to 35%, while penetration testing & network vulnerabilities shares decreased to 15%.
4. Physical audits of equipment changed to occur once a year.
Rationale: In preparation for expected terrorist attacks, the Chief Information Security Officer (CISO) has made several changes. Due to the extreme damage a successful terrorist attack could do to Hytema, areas that could be relaxed without making it easier for the attackers to breach the system needed be identified. Quality assurance testing and vendor testing could not be downgraded so the BCP was selected to be reduced despite the risk. Citing the company’s dwindling profitability and its comprehensive backup consistency as of late, it was decided that those could be reduced in the short term until the threat has passed and other areas could be relaxed.
Expected Results: A decrease in disaster readiness due to lower numbers of redundancy systems, and in the Technical Security Index because of the increased physical audit period.
Security Engineer
Changes this week:
1. Reduction in Key distribution center spending from $25,000 to $23,000.
2. The strength of honeypot to deploy was changed to a pure research honeypot.
Rational: The warning of a cyber-terrorist attack on both Hytema and the Federal government is nothing to take lightly. Therefore, the Security Engineer thought it important to be on high alert for the event, while being mindful of a steep cut in the budget from last week. Reducing the spending on Kerberos servers actually cost Hytema money, showing that maxing out spending here early on was the right choice. However, reducing the KDC spending actually helped the bottom line; funding on this setting was reduced. Despite the suggestion for the group, the IDPS honeypot cannot be turned off, so the objective is to make it as conspicuous as possible. By making it a pure research honeypot, it wouldn’t entice attackers and does not have much in the way of services. This setting would make it less likely to be able to utilize in attacking the company or Federal government in any substantial way.
Expected Results: A slight increase in the downtime indicator, and a decrease in performance; the Technical Security Index score may have or may not have a fractional decrease.
Policy Manager
Changes this week:
1. Emergency bypass policy spending was decreased to $8,000
2. Privacy program investment spending decreased to $40,000
3. Allocation of funds for privacy training for employees was decreased to $29,500
4. The internal information sharing oversight and enforcement groups saw a reduction in members to 3 people.
Rationale: The sustained economic downturn, along with a declining company bottom line, has forced Hytema’s executive management to make some hard budget decisions and asked the security group to make concessions as well. After a review of the policies and policy budget, the Policy Manager reduced several spending areas by 20% or more. The affected areas are emergency bypass policy, privacy program investment spending, and privacy training spending for employees. While maximizing these areas is preferred, they are not as important as other security spending areas. Reducing the budget will increase Hytema’s profitability and prevent other security areas from having to make difficult decisions this round with a looming cyber-terrorist threat. Lastly, the number of people in groups to overlook and enforce internal information was reduced from 4 to 3. This change will not be a significantly increase the risk in the information sharing policy area.
Expected Results: A slight decrease in disaster readiness, productivity, and the Technical Security Index. Additionally, there may be little to no increase in customer satisfaction and employee morale.
Changes this week:
1. The frequency of antivirus scans was increased to multiple times a day.
2. Hiring by average experience in years increased to 9 years.
Rationale: With the cyber-terrorist threat looming, the IA Analyst has upped the number of virus scans per day to increase security. Authorized Software and Backup Policies remain in their highest security settings to protect against the impending attacks. She also increased the IT team experience from 5 years to 9 years, opting to have a more experienced team to handle the cyber-terrorist attack. The IA Analyst also re-enabled forced employee rotation and forced employee vacation to quell a possible insider threat from performing a cyber-terrorist attack, and in general. Finally, patch management and physical security remain at heightened security measures.
Expected Results: A decrease in productivity, and an increase in the Technical Security Index.
Database Engineer
Changes this week:
1. Forced password changes were changed to take place every 30 days.
2. Degree of information sharing on attacks set to low.
Rationale: This week, due to the cyber-terrorism threat, the Database Engineer made some significant changes to help prevent a potential attack. First is the change in the frequency of password changes from 60 days to 30 to reduce the chances of old passwords being used to access network assets. A lowering of disclosure on information sharing to not divulge any information on a potential attack was also made to keep sensitive information in-house.
Expected Results: Slight decrease in productivity and disaster readiness, with an increase in the Technical Security Index and profitability.
4.0 Lessons Learned and Next Round Strategy
Hytema successfully defended itself against this round’s cyber-terrorism threat. The company managed to keep a high level of security, while being mindful of the reduced budget. Despite our efforts, the company still saw decreases in employee morale and reputation, with another steady increase in downtime. Good news from this round came from Hytema increasing its contribution to the National Security Index with a max score of 200. We are pleased that Hytema’s security continued to strongly contribute to the nation’s overall security posture, despite the company’s issues. The company’s Security Index score increased from 128 to 146, which is a significant increase considering the necessary controls were in place, and the changes made to cut spending. Still, the fact remains that Hytema still had problems that it could not overcome. Great security is fine, but it is never good if it drags the company down.
Hytema's continued to have problems with downtime, profitability and reputation in this round as well. While decreasing our high security settings a little bit, the downtime score increased from 144 to 155. Further still, our security measures cut into the company's ability to perform normally, continuing the downward trend in Hytema’s profitability. Profitability decreased again this round from 45 to 29. Still reeling from the economic downturn, and the effects of other sectors, profits are unacceptably low. This index needed to increase in order to keep Hytema an economically viable company, but the security team could not help despite our best efforts. Dealing with customers continue to be arduous, as our reputation and customer satisfaction scores decreased – down from 64 to 57, and from 58 to 48, respectively. A downward trend like this will be difficult to recover from for most companies.
The team learned about the challenges of cutting costs with an ailing budget, while keeping security high enough to stave off attacks. It’s a task that, for the most part, seems to be a losing battle, but there just have to be some ways to accomplish it. The CISO made changes to heighten certain settings to address the threat while cutting back elsewhere, while others sought to slightly decrease theirs to still safe levels. For instance, the Policy Manager and Security Engineer sought to reduce spending and available personnel to safe levels and keep security up. However, the IA Analyst sought to bring more experience into the security team and increase vulnerability scans, a somewhat necessary expense considering the round’s threat. Still, the fact remains that while the security team made the needed changes, it did not meet its overall goals, if those goals were to be a competitive and profitable company.