Prepare an APT Policy

profilejessiebear932
p5_prepare_an_apt_policy_v2.docx

Project #5: Prepare a Policy to Combat Advanced Persistent Threats

Introduction

Advanced Persistent Threats (APT) have become an area of great concern for businesses and government organizations. APTs are used by attackers to gain entry into an organization’s networks and then remain inside by avoiding detection for extended periods of time during which information is harvested and exfiltrated. (See the infographic at http://www.symantec.com/theme.jsp?themeid=apt-infographic-1 )The threat agents for APTs are frequently software-based (malware) agents which can hide on servers and workstations for years before being activated. Since these agents are inside the defensive perimeter for the enterprise, they can be categorized as a type of insider threat. Many of the strategies to combat insider threats can also be used to detect and respond to APTs (see Nigel Wilson’s blog at https://nigesecurityguy.wordpress.com/2014/03/17/apt-strategy-guide/)

Table 5-1. Best Practices for Combating Advanced Persistent Threats (adapted from https://nigesecurityguy.wordpress.com/2013/11/08/apt-strategy-series/)

· Maintain a list of application systems at risk

· Create an APT checklist for assets at risk

· Focus on APT detection techniques and analysis tools

· Focus on incident response for APTs

· Create ready to use APT rapid response tactics

· Prepare an APT forensic response plan

· Increase use of external threat intelligence

· Focus on APTs in security awareness training

In earlier projects for this course, you developed IT security policies for a specific organization. You may use applicable information from those projects when preparing the deliverable (APT policy) for this assignment.

If you wish to change to a different organization for project #5, you must first obtain your instructor’s permission.

Your APT security policy will be used to implement best practices for combating APT threats against the information, information systems, and information infrastructure (e.g. networks, communications technologies, etc.) which are housed within the data center. These best practices should include both administrative actions and implementation of technology-based defensive measures (e.g. real-time monitoring, host-based intrusion detection / prevention, etc.).

Your policy is being written by you as the facility manager. In this role, you are also the information system owner (ISO) for all IT systems and networks within the data center. The information systems hosted in the data center are shown in Figure 5-1.

The primary audience for your policy is the Tier 1 staff responsible for day-to-day operations and maintenance in the data center. Your policy will be communicated to other personnel and to the senior managers who are ultimately responsible for the security of the organization and its IT assets. These managers include: CEO, CIO/CISO, and CSO.

Research:

1. Research the subject of APTs as threats to the security of the information, information systems, and information infrastructure within the data center. Here are three URLs to start with:

a. https://nigesecurityguy.wordpress.com/2013/11/08/apt-strategy-series/

b. https://nigesecurityguy.wordpress.com/2014/03/17/apt-strategy-guide/

c. https://nigesecurityguy.wordpress.com/category/governance/

Note: some APT reports can only be accessed after registration (provide contact information). You are not required to use these reports but, some of the better examples are:

a. http://www.secureworks.com/resources/articles/featured_articles/20120719-hcr/

b. http://www.isaca.org/Knowledge-Center/Research/ResearchDeliverables/Pages/Advanced-Persistent-Threats-Awareness-Study-Results.aspx

c. https://securityintelligence.com/media/2014-ponemon-study-economic-impact-advanced-persistent-threats-apts/

2. Use the list presented in Table 5-1 and the IT architecture shown in Figure 5-2 to identify the types of information, information systems and information infrastructures (networks) which may be targeted by APTs. Create a list of ten to fifteen specific areas of weakness or vulnerability (“risks”) which could be exploited by an APT to gain access to or harvest information from the IT resources shown in this diagram. Include software applications in your information systems category.

3. Assess / evaluate the potential harm that could occur if the identified weaknesses or vulnerabilities are exploited by an APT. Use this information to prioritize your list of risks. Document the risks, potential impacts, and response priorities in a risk register (See Table 5-2). You will include this risk register in your policy deliverable for this assignment.

4. Identify at least 10 control measures or mitigations which could be used to address the identified risks. Use Table 5-1 and NIST 800-53 as your starting points.

5. Identify 5 or more technologies which can be deployed to implement detection, prevention, and eradication of APTs.

Table 5-2. Risk Register

Risk Identifier

Description of the Risk (identify affected assets)

Response Priority (Most important = 1)

Sequence # or Brief title (<50 characters)

Split complex risk statements into multiple individual risks.

Figure 5-3. Data Center IT Architecture Diagram

Write:

1. Use the outline below to prepare your APT security policy for the data center. You must include 10 to 15 specific policy statements which address the prevention, detection, and eradication of Advanced Persistent Threats. You must also include your risk assessment and risk register (prepared earlier) containing 10 to 15 specific risks. Your mitigation strategies must include at least 5 technology-based countermeasures (technical controls) (including identification of 5 or more specific technologies).

I. Identification

a. Organization: [name]

b. Title of Policy:

c. Author: [your name]

d. Owner: [role, e.g. Data Center Manager]

e. Subject:

f. Review Date: [date submitted for grading]

g. Signatures Page: [authorized signers for the policy: CEO, CISO, Data Center Manager]

h. Distribution List

i. Revision History

II. Purpose

a. Provide a high level summary statement as to the policy requirements which are set forth in this document.

III. Scope

a. Summarize the information, information systems, and networks to be protected.

b. Identify who is required to comply with this policy. See the project description for categories of personnel and other individuals.

IV. Compliance

a. Identify the measures which will be taken to ensure compliance with this policy (e.g. audits, compliance reporting, exception reporting, etc.)

b. Identify the sanctions which will be implemented for compliance failures or other violations of this policy.

c. Include information about how to obtain guidance in understanding or interpreting this policy (e.g. HR, corporate legal counsel, etc.)

V. Terms and Definitions

VI. Risk Identification and Assessment

a. Using your risk register, present the findings of your risk assessment.

b. Using Table 5-1 and NIST 800-53 as starting points, identify control measures and protective solutions (technologies) which will be implemented to mitigate or otherwise address each risk or risk area (you may add a column to your risk register table or present in paragraph format).

VII. Policy

a. For each control measure, write a policy statement (“Shall” wording) which addresses the implementation of that control.

b. Include an explanatory paragraph for each policy statement.

2. Prepare a Table of Contents and Cover Page for your policy. Your cover page should include your name, the name of the assignment, and the date. Your Table of Contents must include at least the first level headings from the outline (I, II, III, etc.).

3. Prepare a Reference list (if you are using APA format citations & references) or a Bibliography and place that at the end of your file. (See Item #3 under Formatting.) Double check your document to make sure that you have cited sources appropriately.

Formatting:

1. Submit your policy as an MS Word document using your assignment folder.

2. Format your policy such that it presents a professional appearance. Use headings and outline formatting to organize information for clarity.

3. Cite sources using a consistent and professional style. You may use APA formatting for citations and references. Or, you may use another citation style including use of footnotes or end notes. (Citation requirements for policy documents are less stringent than those applied to research papers. But, you should still acknowledge your sources and be careful not to plagiarize by copying text verbatim.)

4. You are expected to write grammatically correct English in every assignment that you submit for grading. Do not turn in any work without (a) using spell check, (b) using grammar check, (c) verifying that your punctuation is correct and (d) reviewing your work for correct word usage and correctly structured sentences and paragraphs.

Rubric:

Top of Form

Criteria

Excellent

Outstanding

Acceptable

Needs Improvement

Needs Significant Improvement

Missing or Unacceptable

Policy Outline & Body

20 points

Provided an excellent IT Security Policy which clearly, concisely, and accurately presents all required information (see outline in assignment for sections, fields, and content requirements). Presentation of information is organized in a logical fashion and uses 3 or more tables to group related information for presentation. All required fields under each section are listed and filled in (e.g. Owner Name in ID Section has a name filled in.)

18 points

Provided an outstanding IT Security Policy which clearly and accurately presents all required information (see outline in assignment for sections, fields, and content requirements). Presentation of information is organized in a logical fashion and uses 2 or more tables to group related information for presentation. All required fields under each section are listed and filled in (e.g. Owner Name in ID Section has a name filled in.) One or two fields may have been missing or not filled in.

16 points

Provided an acceptable IT Security Policy which presents required information (see outline in assignment for sections and content requirements). Presentation of information is organized in a logical fashion. Required information is provided in the listed fields under each section (e.g. Owner Name in ID section has a name filled in.) Three or fewer fields were missing or not filled in.

14 points

Provided an IT Security Policy which presents most of the required information (see outline in assignment for sections and content requirements). Presentation of information was lacking in organization and/or fewer than 5 fields were missing or not filled in.

9 points

Attempted to provide an IT security policy but content was substantially lacking. Fewer than five required sections were presented.

0 points

The submission did not contain an IT security policy.

Risk Identification, Assessment, and Presentation (Risk Register)

20 points

Provided an excellent risk identification, assessment, and prioritization for APT threats against the data center. Risk identification included at least fifteen (15) specific risks. The risk assessment clearly and concisely addressed the potential negative impacts of APTs upon the confidentiality, integrity, and availability of information, information systems, and information infrastructure in the data center.

Risk Register table containing all identified risks was included in the Risk section of the policy. Table was complete, concise, and accurate.

Appropriately used information from 3 or more authoritative sources.

18 points

Provided an outstanding risk identification, assessment, and prioritization for APT threats against the data center. Risk identification included at least ten (10) specific risks. The risk assessment clearly and concisely addressed the potential negative impacts of APTs upon the confidentiality, integrity, and availability of information, information systems, and information infrastructure in the data center.

Risk Register table containing all identified risks was included in the Risk section of the policy. Table was complete and accurate.

Appropriately used information from 2 or more authoritative sources.

16 points

Provided an acceptable risk identification, assessment, and prioritization for APT threats against the data center. Risk identification included at least seven (7) specific risks. The risk assessment clearly and concisely addressed the potential negative impacts of APTs upon the confidentiality, integrity, and availability of information, information systems, and information infrastructure in the data center.

Risk Register table containing all identified risks was included in the Risk section of the policy. Table was complete.

Appropriately used information from one or more authoritative sources.

14 points

Provided a risk register that included 5 or more risks. The risk assessment addressed two or more potential negative impacts of APTs which were relevant to the data center's environment. Security controls and mitigation measures were mentioned.

Risk Register table containing all identified risks was included in the Risk section of the policy. Table was complete, concise, and accurate.

Appropriately used information from authoritative sources.

11 points

Attempted to provide a risk assessment for APTs. Risk register provided but was incomplete.

Mentioned information from authoritative sources

0 points

Required content was missing or unacceptable.

Policy Section: Implementing APT Best Practices

15 points

Addressed seven or more recommended best practices for APT prevention, detection, and eradication. These best practices include (but are not limited to): (a) Maintaining a list of application systems at risk (b) Creating an APT checklist for assets at risk (c) Focusing on APT detection techniques and analysis tools (d) Focusing on incident response for APTs (e) Creating ready to use APT rapid response tactics (f) Preparing an APT forensic response plan (g) Increasing use of external threat intelligence (h) Focusing on APTs in security awareness training.

Provided an excellent set of policy statements which will ensure that the selected best practices are implemented.

Policy statement(s) and supporting explanations are clear, concise, and accurate.

Used and cited at least three authoritative sources.

14 points

Addressed six or more recommended best practices for APT prevention, detection, and eradication. These best practices include (but are not limited to): (a) Maintaining a list of application systems at risk (b) Creating an APT checklist for assets at risk (c) Focusing on APT detection techniques and analysis tools (d) Focusing on incident response for APTs (e) Creating ready to use APT rapid response tactics (f) Preparing an APT forensic response plan (g) Increasing use of external threat intelligence (h) Focusing on APTs in security awareness training.

Provided an outstanding set of policy statements which will ensure that the selected best practices are implemented.

Policy statement(s) and supporting explanations are clear and accurate.

Used and cited at least two authoritative sources.

13 points

Addressed five or more recommended best practices for APT prevention, detection, and eradication. These best practices include (but are not limited to): (a) Maintaining a list of application systems at risk (b) Creating an APT checklist for assets at risk (c) Focusing on APT detection techniques and analysis tools (d) Focusing on incident response for APTs (e) Creating ready to use APT rapid response tactics (f) Preparing an APT forensic response plan (g) Increasing use of external threat intelligence (h) Focusing on APTs in security awareness training.

Provided an acceptable set of policy statements which will ensure that the selected best practices are implemented.

Policy statement(s) and supporting explanations are appropriate.

Used and cited one or more authoritative sources.

11 points

Named three or more recommended best practices for APT prevention, detection, and eradication.

Provided policy statement or statements which will ensure that the selected best practices are implemented.

Policy statement(s) and supporting explanations are appropriate.

Used and cited authoritative sources.

9 points

Mentioned best practices for APT prevention, detection, and eradication.

Attempted to provide a policy statement or statements requiring implementation of best practices..

0 points

Section was missing or did not contain required / relevant information.

Policy Section: Protective Technologies

10 points

Identified 5 or more technologies which could be used to combat APT threats through improvements in detection, prevention, and eradication. Integrated these technologies into policy statements in a clear, concise, and accurate manner.

8.5 points

Identified 4 or more technologies which could be used to combat APT threats through improvements in detection, prevention, and eradication. Integrated these technologies into policy statements in a clear and accurate manner.

7 points

Identified 3 or more technologies which could be used to combat APT threats through improvements in detection, prevention, and eradication. Integrated these technologies into policy statements in an appropriate manner.

6 points

Mentioned at least one technology which could be used to combat APT threats through improvements in detection, prevention, or eradication.

4 points

Attempted to present information about technology-based solutions for combating APTs.

OR, this section was not well supported by information from authoritative sources.

0 points

Section was missing or did not contain required / relevant information.

Policy Section: Policy Statements to Implement Controls and Best Practices

10 points

Presented 15 or more policy statements to require implementation of best practices, security controls, and technical counter measures (technologies) to combat APTs in the data center.

Policy statement(s) and supporting explanations are clear, concise, and accurate.

Used and cited at least three authoritative sources.

8.5 points

Presented 12 or more policy statements to require implementation of best practices, security controls, and technical counter measures (technologies) to combat APTs in the data center.

Policy statement(s) and supporting explanations are clear and accurate.

Used and cited at least two authoritative sources.

7 points

Presented 10 or more policy statements to require implementation of best practices, security controls, and technical counter measures (technologies) to combat APTs in the data center.

Policy statement(s) and supporting explanations are appropriate.

Used and cited authoritative sources.

6 points

Presented 5 or more policy statements to require implementation of best practices, security controls, and technical counter measures (technologies) to combat APTs in the data center.

Policy statement(s) and supporting explanations may be lacking in details and/or relevant information.

Mentioned at least one authoritative source.

4 points

Attempted to present a policy statement or statements about implementing measures to combat APTs.

OR, this section was not well supported by information from authoritative sources.

0 points

Section was missing or did not contain required / relevant information.

Crediting Sources

5 points

Work credits all sources used in a professional manner using APA format citations/references, foot notes with publication information, or end notes with publication information. Provides a Bibliography or "Works Cited" if not using APA format. Publication information is sufficient to retrieve all listed resources.

4 points

Work credits all sources used in a professional manner using APA format citations/references, foot notes with publication information, or end notes with publication information. Provides a Bibliography or "Works Cited" if not using APA format. One or two minor inconsistencies or errors in format. Publication information is sufficient to retrieve all listed resources.

3 points

Work credits all sources used in a professional manner using APA format citations/references, foot notes with publication information, or end notes with publication information. Provides a Bibliography or "Works Cited" if not using APA format.Fewer than five inconsistencies or errors in format. Publication information is sufficient to retrieve all listed resources.

2 points

Work credits most sources used in a professional manner.Fewer than ten inconsistencies or errors in format. Publication information is not sufficient to retrieve one or two of the required resources.

1 point

Work attempts to credit sources is unprofessional in appearance and/or publication information is not sufficient to retrieve three or more resources.

0 points

Not included or no submission.

Professionalism Part I: Organization & Appearance

5 points

Submitted work shows outstanding organization and the use of color, fonts, titles, headings and sub-headings, etc. is appropriate to the assignment type.

4 points

Submitted work has minor style or formatting flaws but still presents a professional appearance. Submitted work is well organized and appropriately uses color, fonts, and section headings (per the assignment’s directions).

3 points

Organization and/or appearance of submitted work could be improved through better use of fonts, color, titles, headings, etc. OR Submitted work has multiple style or formatting errors. Professional appearance could be improved.

2 points

Submitted work has multiple style or formatting errors. Organization and professional appearance need substantial improvement.

1 point

Submitted work meets minimum requirements but has major style and formatting errors. Work is disorganized and needs to be rewritten for readability and professional appearance.

0 points

Submitted work is poorly organized and formatted. Writing and presentation are lacking in professional style and appearance. Work does not reflect college level writing skills. Or, no submission.

Professionalism Part II: Execution

15 points

No formatting, grammar, spelling, or punctuation errors.

14 points

Work contains minor errors in formatting, grammar, spelling or punctuation which do not significantly impact professional appearance.

13 points

Errors in formatting, spelling, grammar, or punctuation which detract from professional appearance of the submitted work.

11 points

Submitted work has numerous errors in formatting, spelling, grammar, or punctuation. Work is unprofessional in appearance.

4 points

Submitted work is difficult to read / understand and has significant errors in formatting, spelling, grammar, punctuation, or word usage.

0 points

Submitted work is poorly executed OR does not reflect college level work. Or, no submission

Overall Score

Excellent 90 or more

Outstanding 80 or more

Acceptable 70 or more

Needs Improvement 56 or more

Needs Significant Improvement 36 or more

Missing or Unacceptable Work 0 or more

Bottom of Form