TECHNOLOGY INFRASTRUCTURE
To protect information, it is essential first to know where it resides. The asset inventory
must
include the physical and logical elements of the information Technology infrastructure. It
should include the location, associated business processes, data classification, and
identified
threats and risks for each data element. This inventory should also include the key
characteristics of the information that needs to be protected, such as the type of
information
being inventoried, sensitivity ratings for the information and any other critical data points
the
organization has identified for its information
● Hardware asset
All of your servers,Desktop computers, laptops, notebooks, smart devices, routers,
firewalls,
and other hardware components. Network components such as cables, fibre, hotsports.
● Systems Software. Systems software includes computer programs and routines
controlling computer hardware, processing, and non-user functions. This category
includes the Operating Systems e.g., UNIX, Windows OS (Desktop & Server
versions),Telecommunications software and data management software.
● Applications Software. Applications software includes computer programs written to
support business functions such as the General Ledger, Payroll, Stock Systems, Order
Processing, financial, logistics, retail, property and construction, energy and other such
line-of-business functions, E-mail systems and internet/intranet applications.
● System interfaces
● Data and information
● Users of the IT system
● Objective/purpose of the systems
● System and data criticality
● System and data sensitivity
The physical elements of the asset inventory include the location and disposition of
equipment
(e.g., servers, routers and storage solutions), paper documents and physical storage
devices
associated with the organization’s data elements. The logical elements of the asset
inventory
include all of the organization’s electronic information assets, such as the data and
information,
operating systems, and applications.
12
The technology infrastructure elements support capture, storage, processing and
transmission
of data and information within an organization and also support critical processes within
an
organization. The following table represents example of technology elements used within
an
organization showing information resident in them and the risks that they expose
organizations
to.
Technology element
Data Contained/Services Provided
Risk
Cell phones
Phone numbers, e-mail addresses
Loss
Stolen
Improper disposal
Viruses
Phone numbers, email addresses, PDAs/IPADS/Iphones
mailing addresses, contact information,
Emails, databases, spreadsheets
Loss, stolen
Improper disposal,
Viruses, unauthorized access
Phone numbers, email addresses, Blackberries
contact information, Financial
information, e-mails
Loss, stolen, improper
disposal, viruses,
unauthorized access
Documents/ images, spreadsheets, Flash Drives
databases
Loss, stolen, improper
disposal, viruses,
unauthorized access
Documents/images, databases, financial Desktops/PC
information
Loss, stolen, improper
disposal, viruses,
unauthorized access
Any information that could be found in a Laptops/Notebooks
PC
Loss, stolen, improper
disposal, viruses,
unauthorized access
Servers
Services-
e-mail, web, printing,
internet,database services, documents,
Financial records, HRM data, Medical
data, Corporate data
Loss of services, stolen ,
unauthorized access
Operating systems,
Application and
utility software
Corporate Data,log data, support for
organizational processes and
transactions to ensure efficiency and
effectiveness in achieving strategic
objectives
Mis-configuration,
unauthorized modification,
viral attacks, malfunction,
loss of support services
Network
infrastructure(
[Link], switches,
firewalls, Hubs)
Connectivity services, secure
transmission of data
Loss of connectivity services,
unauthorized access, Mis
configuration, malfunction,
stolenControl Environment
The control environment sets the tone of an organization, influencing the control
consciousness
of its people. It is the foundation for all other components of internal control, providing
discipline and structure. This may be defined as the overall infrastructure within which
the
other control elements will function and establishes the conditions under which the rest of
the
Internal Controls will operate. Primary elements within this include the Organizational
Structure.
This defines individual managers’ responsibilities, sets limits of authority, and allows the
ensuring of appropriate segregation of duties. If the organizational structure is
inappropriate,
with excess powers granted to individuals or if poor segregation of duties exists, the
effectiveness of the individual controls may be weakened irreparably. It is impossible to
enforce, for example, division of duties within the computer system by using detailed
access
rights if one individual has been granted access rights across incompatible duties as part
of the
normal operating procedures.
The Control Framework includes the policies and procedures that describe the scope of a
function, its activities, interrelationships with other departments, as well as the external
influences of laws and regulations, customs, union agreements, and its competitive
environment.
The structures enforcing controls may be complex or simple. Large organizations tend to
have
highly structured control frameworks, while smaller organizations frequently use
personal
contact between employees.
ELEMENTS OF INTERNAL CONTROL
Control structures must be designed in order to ensure:
■ Segregation of duties. Controls to ensure that those who physically handle assets are
not
those who record asset movements. Nor are they the same people who reconcile those
records
nor even those who authorize such transactions. Within a modern computer system this is
normally achieved by a combination of user identification, user authentication, and user
authorization.
■ Competence and integrity of people. Underpinning the control system are the people
who
enforce it. In order for controls to be effective, those who exercise control must be
capable of
doing so and honest enough to consistently do so. This means that simply having users
follow
procedures is inadequate in a modern Information Systems environment, and a high
degree of
risk and control awareness is required in order to ensure that the controls function as
intended.
■ Appropriate levels of authority. A common mistake in control structures is the
granting of
too much authority within control boundaries. Authorities should only be granted on a
need-to
–have basis. If there is no need for a particular individual to have specific authorities,
they
34
should not be granted. Obviously this requires effort on the part of those individuals who
assign
authorities in identifying which levels of authority are in fact needed and which are
simply
desired. It is, unfortunately, still true in many sites that access control is limited to user
authentication and subsequent to such authentication the user will then have unrestricted
access into all functional areas within the IS.
Accountability. For all decisions, transactions, and actions taken, there must be controls
that
will allow the determination of who did what with an acceptable degree of confidence.
This
normally involves the use of control logs and audit trails. Simply maintaining such logs
and
records can be counterproductive because they can lull the organization into a false sense
of
security. For such records to be an effective control they must be scrutinized regularly
and
appropriate action taken to remedy any discrepancies noted.
■ Adequate resources. Controls that are attempted with inadequate resources will
typically fail
whenever they come under stress. Adequate resources include manpower, finance,
equipment,
materials, and methodologies. Management frequently underestimates cost of resources
to
implement controls and IS Auditors will commonly recommend controls giving no
thought to
the cost of such control and management’s lack of resources to implement.
■ Supervision and review. Adequate supervision of the appropriate type is fundamental
to the
implementation of sound internal control. It is unfortunately still true that in many cases
people
do not do what is expected, but only what is [Link] MANAGEMENT
The possibility that something could happen to damage, destroy, or interfere with the
integrity,
confidentiality or availability of an asset is known as Risk. Managing risk is therefore an
element of sustaining a secure environment. Risk management is a detailed process of
identifying factors that could damage or interfere with an asset, evaluating those factors
in light
of asset value and countermeasure cost, and implementing cost-effective solutions for
mitigating or reducing risk. The primary goal of risk management is to reduce risk to an
acceptable level. What that level actually is depends upon the organization, the value of
its
assets, the size of its budget, and many other factors. What is deemed acceptable risk to
one
organization may be a completely unreasonably high level of risk to another. It is
impossible to
design and deploy a totally risk-free environment; however, significant risk reduction is
possible, often with little effort.
Importance of Risk Management
Risk management helps organizations avoid heavy losses. These losses can be financial
or data
related losses.
Risk management is important for the following reasons:
• It protects organizations’ information assets.
• It protects business continuity and enables organizations to accomplish their business
objectives.
• It minimizes the effect of risk on organizations’ finances and earnings.
• It provides organizations with a sense of security.
• It helps organizations control IT systems-related mission risks.
• It enables organizations to maintain a balance between operational and financial costs.
• It helps organizations’ management identify suitable controls for implementing required
security measures.
Risk Terminology
Risk management employs a vast terminology that must be clearly understood, especially
in
implanting Internal Controls. This section defines and discusses all the important risk-
related
terminology:
Asset An asset is anything within an environment that should be protected. It can be a
computer file, a network service, a system resource, a process, a program, a product, an
IT
infrastructure, a database, a hardware device, furniture, product recipes/formulas,
personnel,
software, facilities, and so on. If an organization places any value on an item under its
control
5and deems that item important enough to protect, it is labeled an asset for the purposes
of risk
management and analysis.
The loss or disclosure of an asset could result in an overall security compromise, loss of
productivity, reduction in profits, additional expenditures, discontinuation of the
organization,
and numerous intangible consequences.
Asset valuation Asset valuation is a monetary value assigned to an asset based on actual
cost
and nonmonetary expenses. These can include costs to develop, maintain, administer,
advertise, support, repair, and replace an asset; they can also include more elusive values,
such
as public confidence, industry support, productivity enhancement, knowledge equity, and
ownership benefits..
Threats Any potential occurrence that may cause an undesirable or unwanted outcome
for an
organization or for a specific asset is a threat. Threats are any action or inaction that
could
cause damage, destruction, alteration, loss, or disclosure of assets or that could block
access to
or prevent maintenance of assets. Threats can be large or small and result in large or
small
consequences. They can be intentional or accidental. They can originate from people,
organizations, hardware, networks, structures, or nature. Threat agents intentionally
exploit
vulnerabilities. Threat agents are usually people, but they could also be programs,
hardware, or
systems. Threat events are accidental exploitations of vulnerabilities. Threat events
include fire,
earthquake, flood, system failure, human error (due to a lack of training or ignorance),
and
power outages.
Vulnerability The absence or the weakness of a safeguard or countermeasure is a
vulnerability.
In other words, a vulnerability is a flaw, loophole, oversight, error, limitation, frailty, or
susceptibility in the IT infrastructure or any other aspect of an organization. If a
vulnerability is
exploited, loss or damage to assets can occur.
Exposure Exposure is being susceptible to asset loss because of a threat; there is the
possibility
that a vulnerability can or will be exploited by a threat agent or event. Exposure doesn’t
mean
that a realized threat (an event that results in loss) is actually occurring (the exposure to a
realized threat is called experienced exposure). It just means that if there is a vulnerability
and a
threat that can exploit it, there is the possibility that a threat event, or potential exposure,
can occur.
Risk Risk is the possibility or likelihood that a threat will exploit a vulnerability to cause
harm to
an asset. It is an assessment of probability, possibility, or chance. The more likely it is
that a
threat event will occur, the greater the risk. Every instance of exposure is a risk. When
written
as a formula, risk can be defined as risk = threat + vulnerability. Thus, reducing either the
threat
agent or the vulnerability directly results in a reduction in risk. When a risk is realized, a
threat
agent or a threat event has taken advantage of a vulnerability and caused harm to or
disclosure
of one or more assets. The whole purpose of security is to prevent risks from becoming
realized
by removing vulnerabilities and blocking threat agents and threat events from
jeopardizing
assets. As a risk management tool, security is the implementation
of safeguards.
6Safeguards A safeguard, or countermeasure, is anything that removes a vulnerability or
protects against one or more specific threats. A safeguard can be installing a software
patch,
making a configuration change, hiring security guards, altering the infrastructure,
modifying
processes, improving the security policy, training personnel more effectively, electrifying
a
perimeter fence, installing lights, and so on. It is any action or product that reduces risk
through
the elimination or lessening of a threat or a vulnerability anywhere within an
organization.
Safeguards are the only means by which risk is mitigated or removed. It is important to
remember that a safeguard or countermeasure need not be the purchase of a new product;
reconfiguring existing elements or even removing elements from the infrastructure
are also valid safeguards.
Attack An attack is the exploitation of vulnerability by a threat agent. In other words, an
attack
is any intentional attempt to exploit a vulnerability of an organization’s security
infrastructure
to cause damage, loss, or disclosure of assets. An attack can also be viewed as any
violation or
failure to adhere to an organization’s security policy.
Breach A breach is the occurrence of a security mechanism being bypassed or thwarted
by a
threat agent. When a breach is combined with an attack, a penetration, or intrusion, can
result.
A penetration is the condition in which a threat agent has gained access to an
organization’s
infrastructure through the circumvention of security controls and is able to directly
imperil
assets.
7RISK ASSESSMENT PROCESS
Risk Assessment Methodology
The following steps are involved in the risk assessment process:
1. Assets characterization
2. Threat identification
3. Vulnerability identification
4. Control analysis
5. Likelihood determination
6. Impact analysis
7. Risk determination
8. Recommendations to control the threats
9. Results documentation
Step 1: Assets Characterization
In this step, the assets and systems are identified and their values are determined in order
to
set the scope of the risk assessment, to identify the risk to assets, a good knowledge of the
assets environment is necessary. The organization needs to collect the following
information:
• Organization’s tangible assets, including computer systems, networking devices, and
other
equipment
• Software assets
• System interfaces
• Data and information
• Users of the IT system
• Objective of the system
• System and data criticality
• System and data sensitivity
Step 2: Threat Identification
In this step, different threats and threat sources are identified. A threat source is any
incident
or occurrence with the potential to cause harm to the asset. A threat source does not
present a
risk if there is no vulnerability that can be exercised for that particular threat source.
The following threat sources are common:
• Human threats: Human threats are more difficult to predict and identify due to their
uncertain nature.
The following human threats are common:
• False data entry or deletion of data
• Inadvertent acts
• Eavesdropping
• Impersonation
• Shoulder surfing
• User abuse or fraud
• Theft, sabotage, vandalism, or physical intrusions
• Espionage
• Technical threats: These threats arise due to system misconfigurations and errors in
application development.
Though there are procedural solutions for most technical threats, the complexity in
current
evolving technologies and weak interrelations between various stakeholders in the field
make
them difficult to avoid. The following technical threats are common:
• Breaking passwords for unauthorized access to system resources
• Sniffing and scanning of network traffic
• Data/system contamination
• Malicious code infection
• Spam and mail frauds
• Phishing that may result in loss of confidential private information
• DDoS attacks
• Application coding errors
• Unauthorized modification of a database
• Session hijacking
• System and application errors or failures
Step 3: Vulnerability Identification
A vulnerability is any weakness in the operations or systems of an organization that
could be
exploited by a threat agent. The main objective of this step is to prepare a list of asset
vulnerabilities that could be exploited by the probable threat sources.
Step 4: Control Analysis
The organization analyzes the controls that are planned to be implemented or are already
implemented in order to reduce the probability of a threat. The following aspects are
included
in a control analysis:
Control methods: The following two methods must be incorporated to achieve security
control:
1. Technical controls: Technical controls are safeguards that are integrated into system
hardware, software, or firmware, such as access control mechanisms, identification and
authentication mechanisms,
encryption methods, and intrusion detection software.
2. Nontechnical controls: Nontechnical controls are management controls that include
operational procedures, security policies and personnel, and physical and environmental
security.
• Control categories: Technical and nontechnical control methods are classified into the
following two categories:
1. Preventive controls: These controls reduce the attempts made to violate security
policies and
thus include such controls as access control enforcement, authentication, and
encryption.2. Detective controls: These controls alert the administrator when violations or
attempts at
violations of security policies occur. They include controls such as checksums, audit
trails, and
intrusion detection methods.
Step 5: Likelihood Determination
This step determines the likelihood of the occurrence of a threat. The following factors
help in
deriving the overall likelihood rating:
• Motivation and capability of the threat source
• Nature of the vulnerability
• Efficiency and existence of current controls
Step 6: Impact Analysis
An impact analysis determines the impact that a threat could have on a system. To
perform an
impact analysis, it is necessary to know the system mission, system and data criticality,
and
system and data sensitivity. This information can be obtained from the following reports:
• Mission impact analysis report: Based on a qualitative or quantitative assessment of the
sensitivity and criticality of assets, a mission impact analysis prioritizes the impact levels
associated with the compromise of those assets.
• Asset criticality assessment: An asset criticality assessment identifies and prioritizes the
sensitive and critical information assets that support the critical missions of the
organization.
If these reports do not exist, the system and data sensitivity can be evaluated depending
upon
the
confidentiality, integrity, and availability of the information. The three qualitative
categories—
high, medium, and low.
During an impact analysis, qualitative and quantitative assessments are also taken into
account.
A qualitative impact analysis prioritizes the risks involved and thus identifies the
immediate
improvement areas. A quantitative impact analysis provides the impact’s magnitude
measurement, which in turn is used for a cost-benefit analysis of the recommended
controls.
Examples of impacts: Financial impacts:
Loss of revenue — short-term and long-term — e.g., the compromising of sensitive credit
card
information on an e-commerce site has an immediate short-term impact relative to
revenue
and a long-term impact related to reputation damage and loss of customers.
Expenses related to remediation — e.g., if data on systems are destroyed and the backups
do
not work, there will be cost associated with recovering data.
Loss of productivity — e.g., employees are not productive if they do not have e-mail for a
day.
Regulatory-related fines – e.g Breach of the constitution
Potential litigation — e.g., sensitive customer information was compromised.
Damage to the reputation of a company — e.g., defacement of a Web site.
Loss of customers — e.g., e-commerce site was unavailable
Step 7: Risk Determination
Risk determination is a crucial task in a risk assessment effort. It is a complex process
and
depends upon various tangible and intangible factors. Though it is generally difficult to
determine the exact level of risk to different organizational processes and assets, a careful
consideration of various risk determinants gives an overall perception of risks faced by
the
organization. Risk determination involves a consideration of the following factors:
• The probability of occurrence of an anticipated incident: An incident is the result of a
threat
source exploiting
system vulnerabilities.
• The tangible and intangible impact of an incident on organizational resources:
Tangible
impacts of an incident are easier to measure and can be represented by statistical analysis,
whereas intangible impacts such as loss of reputation and customer trust are difficult to
assess
and can be determined only as a perception.
• The control measures used to minimize impact: Selection and implementation of control
measures is based on risk determination and various management issues such as cost-
benefit
analysis and availability of resources.
Step 8: Recommendations to Control the Threats
Control recommendation and implementation is the main purpose of the whole risk
assessment
exercise. Risk assessment teams recommend the controls based on the likelihood, impact,
and
criticality of risk for a business [Link] assessment teams need to consider these
factors
when recommending risk control measures:
• The control should meet the basic principle of a cost-benefit ratio.
• Controls should be implementable within the organization’s ethics and security policy.•
The recommended solutions should be compatible with the organization’s existing
system.
• Controls must be within legislative and regulatory boundaries.
• The reliability of controls should be verified by using previous case studies and
preimplementation tests.
• The controls should not go against the safety requirements of personnel and resources.
The implementation of controls depends on many business and management issues.
Senior
management in the organization has to determine the effectiveness of controls based on
technical feedback and available case studies.
Step 9: Results Documentation
Each step of a risk assessment and the results should be properly documented.
Documentation
is critical to a risk assessment. An official, detailed, and clear risk assessment report helps
senior
management make decisions on policies, procedures, and system, operational, and
management changes.
The documentation should be well structured and include supporting information. It
should
provide miscellaneous information that could help senior management implement
mitigation
strategies and allocate resources to mitigate risks in order to reduce potential losses.
RISK ASSESSMENT SUMMARY