SEC440 Threat Assessment
Threat Assessment
SEC440 Threat Assessment
Name
Class
Date
Professor
Threat Assessment
In the information age it is essential to have the necessary security in place to ensure that private data is not stolen or lost. The threat assessment is conducted to ensure that any potential security gaps are identified as well as to ensure the necessary security measures are in place to prevent intrusion or damage to the information systems. As the chief security officer for the Information Technology (IT) department of Applebee’s Inc., understanding the potential threats will make them more effective in their role. The type of information that will be gathered in the threat assessment includes what needs to be protected, the potential threats or vulnerabilities faced by the organization, value to organization, and to identify ways to minimize damage or loss.
The outcome or objective of a threat and risk assessment is to provide recommendations that maximize the protection of confidentiality, integrity and availability while still providing functionality and usability (Bayne, 2002). In other words the assessment will identify gaps in security that must be addressed and provide the best practices for closing this security gap. The core areas in the risk assessment include the scope, collection of data, analysis of policies and procedures, threat and vulnerability analysis, and correlation and assessment of risk acceptability.
Risk management is an identification of risk by the management in a business or organization. When conducting the threat assessment principles of threat management will assist in identifying the impact of any recommendations, identify sources that will be used to implement suggested security changes, and minimize any threat to the company’s information systems. In this case the information system of Applebee’s will be assessed to determine f there are any threats or vulnerabilities to their information networks. Through risk management the risk can be first identified, avoided, the risk can be reduced, and the negative impact reduced. At Applebee’s there are thousands of customers and employees private information being stored as well as the operational information of the organization. It is essential in an organization this size has the necessary security measures in place to protect this information.
Scope
The objective of the threat assessment is to determine the weaknesses of a structure and determine how to protect that structure and its occupants from criminal intent (Mendoza, 2009). The scope is the content or what will be covered in the assessment. The scope explains what needs to be protected and will explain how the assessment will be conducted. In the case of Applebee’s the assessment will be conducted on the organizations information systems, which include the financial information of the company, customer information networks, and employee personal information.
The threat assessment will determine if current security measures that are being employed by Applebee’s are effective and if not in what areas need to be improved to reduce the potential threat. Based on the principles of risk management it is essential the management is involved in this process in order to alert the chief security officer on areas they recognize that could create a potential security threat.
Collecting Data
The next step in the risk assessment is the collection of data. Data is a key factor in determining what areas are vulnerable and what recommendations should be made. During the data collection process the policies and procedures will be collected, past and present security documents, interviews with key personnel, and important information on security systems and networks. This data will be collected from key IT personnel at Applebee’s and includes the type of operating system being used, services the organization is running, network applications, physical location of information systems, access controls, intrusion detection, firewalls, and networks surveying measures. The involvement of stakeholders is essential to ensuring the CO has all of the necessary information to perform an affective threat assessment.
Analyze the Policies and Procedures
The next core area of the threat assessment is to analyze the policies and procedures being employed by the company concerning their current information technology security. Current policies and procedures will provide crucial information to the Chief Security Officer on the level of compliance of employees as well as to assess their effectiveness. The CSO will assess the security standards that are currently in place as well as identify any potential areas that will require greater consideration. In risk management first understanding organizational objectives will assist the CSO in determining is employees are currently in compliance and determine if there are gaps in meeting these objectives.
For example one of Applebee’s main objectives is to create an environment where every customer feels like a member of the family and is made to feel welcome when they enter an Applebee’s restaurant. If customers fear their private information will be lost or stolen they will not dine at Applebee’s. In order to meet this goals the prove information of customers must be properly secured. In order to meet this objective there cannot be any failures to comply with policies or procedures and the policies and procedures being applied must be effective. The threat assessment will help the chief Security Officer determine if there needs to be better measures of enforcement or if the policies or procedures need to be reformed.
Threat and Vulnerability Analysis
In the vulnerability analysis the CSO will determine the current vulnerability of the organizations information systems by evaluating current security measures and asses current exposure to loss or damage. When assessing potential vulnerabilities in the information system network the Chief Security Officer will need to apply software, such as Nessus or SARA, to ensure the current safeguards are effective. The result of the various tools must be verified in order to accurately determine the reliability of the tools in use and to avoid protecting an area that in reality does not exist (Bayne, 2002). Penetration tests will also be conducted to determine strength of security measures. For example the test could attempt to penetrate they system through the company’s passwords.
The threat analysis will identify specific factors that could result in risk to the company’s information systems. These threats will include human and nonhuman threats that must be first identified before the assessment can be conducted. Potential threats to Applebee’s information systems include humans, such as employees or outside criminal threats. Potential nonhuman threats will include natural disasters, such as floods, hurricanes, tornadoes, or event out of the control of the security staff, such as fires or viruses. Once the threat is identified specific steps will need to be taken to reduce the threat and the vulnerabilities of the organizations information systems.
Based on principles of risk management identifying vulnerabilities or threats will require the involvement of stakeholders, good communication, understanding organizational objectives, and reporting any potential areas that could result in the information system being more vulnerable or reporting any potential threats. Risk Management has to be transparent and inclusive. It should take into account the human factors and ensure that each one knows it roles at each stage of the risk management process (Nathwani, 2001). In order for the CSO to identify risk or vulnerabilities they will need assistance for a support structure which is the management of the organization.
Analysis of Acceptable Risk
The analysis of acceptable risk refers to a process where the data that has been collected on the current policies and procedures is evaluated in order to determine their effectiveness. If the safeguard being employed have been effective in preventing intrusion, loss, or damage then the list of vulnerabilities would be fewer if the current security measures have been proven to be ineffective. During this evaluation the CSO will determine what potential risks or vulnerabilities are acceptable and what risk, threats, or vulnerabilities must be immediately addressed. The CSO is to use the findings from the vulnerability and risk assessment to determine what measures must be taken to reduce vulnerabilities and eliminate the threat.
Conclusion
The threat assessment provides the organization with essential information that will assist them in properly and effectively protecting private information stored on information systems. This includes protecting the financial and operational information of the organization, private customer records, and employee data. Once the threat assessment has been conducted the CSO as Applebee’s can take the necessary steps to ensure that the private information is not intruded upon and there is no unnecessary loss or damage. The threat assessment is a valuable tool that will assist the company indentifying threats and vulnerabilities.
If Applebee’s where to face a security incident where the private information of the organization, employee, or customer is breached the result would be a loss of trust by members of the public which will result in a loss of sales. Applebee’s goal is to create a neighborly environment in which customer’s are made to feel welcome. If customers fear their private information will be lost they will not dine at the restaurant. The threat assessment will allow Applebee’s to take the necessary security steps to ensure that any potential security threats have been addressed through effective security measures and the necessary prevention measures.
References
Bayne, J. (2002). An Overview of Threat and Risk Assessment. SANS Institute. Retrieved
December 16, 2012 from
http://www.sans.org/reading_room/whitepapers/auditing/overview-threat-risk-assessment
Mendoza, A. (2009). What is a Threat Assessment. Retrieved December 16, 2012 from
http://www.phoenix.edu/profiles/faculty/albert-mendoza/articles/what-is-threat-assessment
Nathwani, J. & Pandey, M. (2001). Principles for Managing Risk: A Search for Improving the
Quality of Decisions. Retrieved December 16, 2012 from
http://www.irr-neram.ca/pdf_files/Engelberg