IT Risk Management at ABC
Trend Limited Company
Informative Report
[Author name] [Date] [Course title]
Information Technology Risk
Management ABC Trend Limited
Company
Table of Contents
1 Introduction ............................................................................................................................. 2
2 Risks to the Trend Master Limited and its IS/IT ...................................................................... 3
3 Evaluation of risks .................................................................................................................... 4
3.1 Data Driven Risks .............................................................................................................. 4
3.2 Business-driven risks ........................................................................................................ 5
3.3 Event-Driven Risks: ........................................................................................................... 5
3.4 Consideration of Other Physical Risks .............................................................................. 6
4 Countermeasures .................................................................................................................... 7
5 Recommendation of measures to be taken to protect the business and priorities ............. 12
5.1 Developing Security Architecture: ................................................................................. 12
5.2 Patched Client side Software and Applications: ............................................................ 13
5.3 Security for Phishing and Targeted Attacks ................................................................... 13
5.4 Good Configuration Management ................................................................................. 13
IT Risk Management at Trend Masters Limited Page 1
5.5 Mobile Devices Management ........................................................................................ 13
5.6 Cloud Computing Protection .......................................................................................... 14
5.7 Removable Media Security ............................................................................................ 14
5.8 Botnets Security ............................................................................................................. 14
5.9 Zero Day Attack Security ................................................................................................ 14
5.10 Passwords Protection: ................................................................................................ 15
5.11 Physical Security ......................................................................................................... 15
5.12 Backup and Recovery.................................................................................................. 15
5.13 Proper Destruction ..................................................................................................... 15
5.14 Social Media................................................................................................................ 15
5.15 Social Engineering ....................................................................................................... 16
5.16 Security Measures against Natural Disasters ............................................................. 16
6 Bibliography ........................................................................................................................... 18
1 Introduction
TrendMaster Limited is providing data processing services to the major retailers for 2 years in a
converted barn. This help the retailers in making detailed analysis of customers spending on
products and services. A director with staff is currently managing this company. However, it is
IT Risk Management at Trend Masters Limited Page 2
now moving to new premises with additional staff because of increase in revenue and demand
of its services. A suitable location for data processing has been sought with 2 story office linked
with ring road of major town.
The objective of this study is to carry out following measures:
• Assess the risks related to TrendMaster Limited and to its Information technology or
Information Systems.
• Make Analysis and Evaluation of these identified risks
• Identifying and justifying the full range of countermeasures or alternatives related to
these risks will be considered.
• A detailed recommendations with appropriate solutions and Implementation schedule
will be discussed.
2 Risks to the Trend Master Limited and its IS/IT
Information Technology risks may raise a lot of threats with varying level of impact for Trend
Master Limited. These risks may be categorized into three categories.
1. Data-Driven Risks
2. Business-Driven Risks
3. Event-Driven Risks
IT Risk Management at Trend Masters Limited Page 3
(Hingarh & Ahmed, 2013)
3 Evaluation of risks
3.1 Data Driven Risks
Data-driven risks receive highest attention from information technology perspective.
These risks occur on frequent basis as compared to the other risks but the financial that
is faced by the entities is relatively low. Sometimes these risks may crossover with other
business driven risks like business viability and business continuity. However, the focus
of these risks will be at the data level or system. Usage of Social media technologies may
generate risks like brand protection, unauthorized access to the confidential data.
Increased usage of mobile devices may result in loss or release of critical business data.
IT Risk Management at Trend Masters Limited Page 4
Challenges for application development and ERP integration may take place. Malware
technologies are increasing continuously to theft and loss of critical information.
Malware technologies are leaving impacts upon hardware and productivity levels.
Constraints generated by end user computing may include misstatement of financial
statements, corruption or loss of data and unsupported decision making. Corporate
Espionage of Trend Master Limited may be compromised because of increase in more
specific targeted efforts done by mobile computing technologies. Poor governance of
Information technology may cause information security risks. Improper electronic
records management may cause in loss of data, storage, retention and forensic issues.
Increase in regulatory requirements for management and security of sensitive data may
generate regulatory penalties and increase in cost of compliance. (Hingarh & Ahmed,
2013)
3.2 Business-driven risks
These business driven risks attract directly the business operations and business continuity.
Board members of the Trend Master Limited will have more concern for these risks as they
planner of business strategy rather than data-driven risks. Social media technologies may
generate regulatory or legal [Link] IT Governance may cause failure to comply with
corporate IT controls and policies, impacts on operations, regulatory violations, and duplication
of efforts and increased in inefficiencies and costs. Improper cloud computing may cause
problems in administrative access, investigative support, long term viability and data
management issues like compliance, recovery and security. (Hingarh & Ahmed, 2013)
3.3 Event-Driven Risks:
These risks may disrupts the processes, workforce, applications, data or infrastructure of Trend
Master Limited. These risks will affect the business viability and business continuity. (Hingarh &
Ahmed, 2013)
IT Risk Management at Trend Masters Limited Page 5
3.4 Consideration of Other Physical Risks
• Fire
• Water
• Natural Disaster
• Environmental Disaster
• Failure or Disruption of the Power Supply
• Failure of Disruption of the Communication Networks
• Abuse of Authorizations, Identity Theft
• Unauthorized access to the Premises
Fire may cause severe damage to the buildings, people and information technology facilities.
Fire risk may raise because of keeping fire-roof doors open by using the wedges, storage of
combustible materials inappropriately, failure in meeting fire protections instructions and
standards, lack of fire detection and alarm systems, automatic fire extinguishers an inadequate
fire prevention facilities.
Water may damage the availability and integrity of the information that is stored in the digital
data storage media. Water may enter into the Trend Master Limited building or its rooms
because of sewage disposal, disruption in the supply of water, defect heat system, defect air
conditioning systems, defective sprinkler systems, water sabotage and water that was used in
the fire-fighting operation.
Natural Disaster may occur because of climatic, seismic, volcanic, phenomena, earthquakes,
floods, landslides, avalanches, tsunamis and volcanic eruptions. (Hingarh & Ahmed, 2013)
IT Risk Management at Trend Masters Limited Page 6
4 Countermeasures
• Risk countermeasures will help the IT Managers of Trend Masters Limited in protecting
IT Systems and data providing support to its mission. To minimize the information
technology risks on Trend Master Limited, it is essential to integrate the effective risk
management process in system development life cycle (SDLC). Phases of SDLC are
initiation, development or acquisition, implementation, operation or maintenance and
disposal. Risk management at initial phase will help in determining the requirements of
system and security concept. Risk Management at Development or Acquisition phase
will be useful in doing security analysis of the IT system and design architecture of the
system. Risk Management at implementation phase makes comparison between its
implementation and requirements. Risks identified in this comparison demands instant
decision prior system start working. Risk management activities at operation or
maintenance phase will help to manage risks occurring due to major changes if any. Risk
management activities at disposal phase ensure that hardware and software are
disposed of properly and system migration process is conducted in systematic and
secure manner.(Broad, 2013)
a) A systematic methodology for risk assessment& management consisting upon
following nine primary steps will be necessary:
b) System Characterization
c) Threat identification
d) Vulnerability Identification
e) Control Analysis
f) Likelihood Determination
g) Impact Analysis
h) Risk Determination
i) Control Recommendations
j) Results Documentation
IT Risk Management at Trend Masters Limited Page 7
(Gibson, 2011)
Explanation:
System characteristics step will determine the scope of efforts, boundaries of the IT system,
information and resources that will constitute the system. For successful risk assessment
efforts, it will be essential to provide all information regarding hardware, software, system
connectivity and responsible division. Information gathering techniques will be questionnaire,
on-site interviews, document review and usage of automated scanning tools.
A successful identification of threats demands consideration of threat sources and potential
vulnerabilities. Threat source may be any event or circumstance that may harm the IT
system. These threat sources may be human, natural or environmental. All potential threat
sources that may harm the IT systems and its processing environment are considered. For
instance, malicious attempt for gaining access to unauthorized access to the IT system and a
purposeful effort to circumvent the security of the system. (Gibson, 2011)
In Vulnerability identification step, a list of system vulnerabilities are developed. For
instance terminated employees ID are not removed from the system and they dial into the
network of Trend Master to access the proprietary data. However, the level of vulnerability
depends upon the nature of IT system. The search for vulnerabilities will focus on security
policies, planned security procedures, vendors security product analysis and system
requirement definitions if the IT system has not been designed yet. In case of
implementation of IT system, more specific information such as planned security features
explained in the security design documentation, will be considered to identify the
vulnerabilities. In case IT system is operational, an analysis of IT system security features,
security controls will be made to identify the vulnerabilities. Risk assessment personnel at
this step determine the security requirements of the IT system and determine either these
IT Risk Management at Trend Masters Limited Page 8
are met by existing security controls. Following table is describing the security criteria to
identify the vulnerabilities at Trend Master Limited.(Gibson, 2011)
IT Risk Management at Trend Masters Limited Page 9
(Gibson, 2011)
Control Analysis step will analyze of controls planned or implemented by the Trend Master
Limited. Preventive controls will inhibit in violating the security policies. These controls include
authentication, encryption and access control enforcement. Detective controls will warn
regarding violations of security policies. (Hall, 2011)
Likelihood Determination step will guide in determining the nature of vulnerability. If likelihood
level of vulnerability is high, it shows that controls are ineffective and demands immediate
attention. Medium level shows that threat source is capable and motivated but controls are in
place that may be bypass if vulnerability is successfully exercised. Low level shows source lack
of capability and motivation and there are at least chances for impede if vulnerability is
exercised successfully. (Hall, 2011)
Impact analysis step will determine the level of risk if user attempt to harm the data. This help
to design measures for the loss of integrity, loss of availability and loss of confidentiality. Risk
determination phase assess the level of risk by considering its likelihood, magnitude of the
impact and adequacy of planned security controls. Control recommendation step will eliminate
IT Risk Management at Trend Masters Limited Page 10
the risks of IT systems to acceptable level as identified in the previous steps. However, in
mitigation of risks, some factors such as effectiveness of recommended options, legislation and
regulation, organization policy and operational impact are considered. In final stage, an official
documentation will help the senior management to make decisions regarding wrongdoing,
policies, procedures, and budget and management changes. Consult diagrammatic view of this
risk management steps in Appendix. (Khosrowpour, 2002)
• Constant access to the vital data will demand well-planned data protection solution with
an effective backup and recovery service to ensure the business continuity and keeping
costs under controls of the Trend Master Limited.
(Khosrowpour, 2002)
• Holistic approach for data security and compliance is necessary to be developed as
shown below:
IT Risk Management at Trend Masters Limited Page 11
Discovering where sensitive data is located will help to protect the enterprise data from
authorized & unauthorized access. Classification and defining of data types will clarify the
structured and unstructured data. Monitoring and audit procedures will generate reports for
compliance, policy exceptions and assessment of database vulnerabilities. (Khosrowpour,
2002)
5 Recommendation of measures to be taken to
protect the business and priorities
5.1 Developing Security Architecture:
Trend Master Limited should develop the security architecture by hiring appropriate personnel.
It is recommended that IT team of Trend Masters should collaborate with third party
consultants. (Whitman, 2010)
IT Risk Management at Trend Masters Limited Page 12
5.2 Patched Client side Software and Applications:
Malicious actors may compromise and destroy the security system of Trend Master Limited.
Therefore, to reduce this risk it is essential to implement the robust patch management
program to identify the vulnerable software applications and updates for software security.
This will ensure security and protection from known threats. (Whitman, 2010)
5.3 Security for Phishing and Targeted Attacks
Hacker may gain access to the potential information of Trend Masters Limited through emails
containing malicious codes. To reduce vulnerability against this theft it is recommended that
Trend Master Limited should install professional enterprise level email security software.
Incoming and outgoing messages will be screened by this software to ensure that no spam
message is transmitted and security of the system is not compromised. Furthermore, Trend
Master Limited has to provide regular training regarding internet security to its staff. This will
guide and provide awareness to the staff about e-mail scams. (Whitman, 2010)
5.4 Good Configuration Management
Computers connected to the network and are not following the configuration management
policy are more vulnerable to attack. Therefore, Trend Master Limited has to establish the
configuration management policy to connect any hardware to the network including printers,
networking devices and computers. Furthermore, it is also recommended to implement the
Network Access Control Solution. This will prevent automatically access to the network for
devices that do not meet the network security policies. (Whitman, 2010)
5.5 Mobile Devices Management
The usage of mobile devices such as smart phones and laptops have developed the complicated
situations. Because these devices may be used to conduct operations outside the regular
IT Risk Management at Trend Masters Limited Page 13
network of Trend Master. Data encryption, anti-malware solutions and user authentications
should be developed. This is best protection strategy and ensures fair policy for the usage of
mobile devices and prevent any malicious activity. (Umar, 2004)
5.6 Cloud Computing Protection
Trend Master should ensure that benefits that are provided by the cloud computing companies
are complying with the information security requirements of the Trend Master Limited. A
regular assessment should be made regarding cost benefit analysis. (Buyya & Broberg, 2011)
5.7 Removable Media Security
To ensure the security of the removable media, Trend Master Limited should disable auto run
feature on the machines and proper training is to be provided to the staff for scanning the
removable devices before using the file. (Buyya & Broberg, 2011)
5.8 Botnets Security
Botnets are the network of compromised computers that hacker use for malicious purposes
and are criminal in nature. To reduce this risk, Trend Master should design strong security
architecture for defending the malicious botnet attack. Protection strategies in this regard will
to analyze the data sent over the network and to monitor the external connection and usage of
computer resources. (Buyya & Broberg, 2011)
5.9 Zero Day Attack Security
Trend Masters Limited should hire IT analyst having highly experience in technical vulnerability
assessment. Second option is to wait for the vendor who release the patch to fix the
vulnerability. It should contain latest software patches and should deploy the fixes as become
available by the developer. (Buyya & Broberg, 2011)
IT Risk Management at Trend Masters Limited Page 14
5.10 Passwords Protection:
Trend Master Limited should use professional password-generating program. In addition to
implement the procedures regarding strong passwords, training of staff is necessary for
maintaining security of passwords. More advanced authentication capabilities like multi-factor
authentication should be introduced. (Caloyannides, 2004)
5.11 Physical Security
Physical security is most important as this will prevent unauthorized access to the sensitive
data, resources and personnel. Physical security should be integral part of comprehensive
security program as this will ensure secure access to the dedicated computers, routers,
printers, server rooms and printers.(Caloyannides, 2004)
5.12 Backup and Recovery
Trend Masters Limited should design specific procedures and policies for data backup, storage
and retrieval of data. A lot of recovery tools and system backup software are available in the
market. (Caloyannides, 2004)
5.13 Proper Destruction
Policies should be established to destroy useless IT assets and media containing sensitive data.
Support of the several standard organizations providing guidelines to discard useless data
should be gained. (Caloyannides, 2004)
5.14 Social Media
Policies for social media should be developed to prevent the access to the social media
websites by using the resources and equipment of Trend Masters Limited. However, strong
IT Risk Management at Trend Masters Limited Page 15
anti-virus and spam filtering solution should be introduced if Trend Master Limited is allowing
access to the social media websites.(Caloyannides, 2004)
5.15 Social Engineering
Trend Masters Limited should provide users deep understanding regarding social engineering
threats and how to avoid. For instance, they are trained how to remain conscious if someone is
making inquiry regarding account information or technical information of the network.
(Caloyannides, 2004)
5.16 Security Measures against Natural Disasters
Backup of data in multiple areas, secured building, evaluation of security measures on regular
basis, resource management, emergency response plan and crises communication plan are
necessary to ensure business continuity plan of Trend Masters Limited. (Caloyannides, 2004)
IT Risk Management at Trend Masters Limited Page 16
Appendices
IT Risk Management at Trend Masters Limited Page 17
6 Bibliography
Broad, J. (2013). Risk management framework : a lab-based approach to securing information
systems. Amsterdam : Syngress, an imprint of Elsevie.
Buyya, R., & Broberg, J. (2011). Cloud computing : principles and paradigms. Hoboken, N.J. :
Wiley.
Caloyannides, M. A. (2004). Privacy protection and computer forensics. Boston : Artech House.
Gibson, D. (2011). Managing risk in information systems. Sudbury, MA : Jones & Bartlett
Learning.
Hall, J. A. (2011). Information technology auditing and assurance. Mason, Ohio :
Thomson/South-Western,.
Hingarh, V., & Ahmed, A. (2013). Understanding and Conducting Information Systems Auditing.
New York : Wiley.
Khosrowpour, M. (2002). Issues & trends of information technology management in
contemporary organizations. Hershey, PA : Idea Group Publishing.
Umar, A. (2004). Mobile computing and wireless communications : applications, networks,
platforms, architectures, and security. NGE Solutions.
Whitman, M. E. (2010). Principles of information security. Boston, MA : Course Technology.
IT Risk Management at Trend Masters Limited Page 18
IT Risk Management at Trend Masters Limited Page 19