Core Definitions and Risk Terminology
Risk: The likelihood that something bad will happen to an asset; it is
not always inherently negative, as some risks can lead to positive
results.
Threat: Something bad that might happen to an organization, such
as potential theft.
Threat Agent: The entity that realizes a threat (e.g., a thief is the
agent that realizes the threat of theft).
Vulnerability: Any exposure or weakness that could allow a threat
to be realized, such as a software bug or side effects like employees
using personal smartphones for corporate email.
Impact: The amount of harm or loss caused by a threat or
vulnerability being exploited.
Event vs. Incident: An event is a measurable occurrence impacting
business operations, whereas an incident is a specific event that
violates security policy.
Total Risk vs. Residual Risk: Total risk is the combination of threats,
vulnerabilities, and asset value; residual risk is the risk that remains
after mitigating controls have been applied.
The Risk Management Process
Risk management is a continuous, lifecycle-based focus for information
security. The process follows five key steps:
1. Identify Risks: Determining what could go wrong and interrupt
operational readiness.
2. Assess and Prioritize: Evaluating which risks are most serious for a
specific location or environment.
3. Plan Risk Response: Selecting the best strategy to address
prioritized risks.
4. Implement Risk Responses: Taking direct action to apply chosen
responses.
5. Monitor and Control: Ongoing measurement of risk responses to
ensure they perform as expected.
Risk Identification Methods
Organizations use several techniques to gather information on potential
risks:
Interviews: Often considered the best method for gathering detailed
information.
Brainstorming: Unstructured group input where participants should
feel free of criticism.
Surveys: Standardized questionnaires sent to people across different
areas of the organization.
Working Groups: Focused feedback from individuals in specific work
areas.
Checklists and Historical Information: Reviewing previously
encountered risks or documentation of past failures.
Risk Register: A central document containing risk descriptions,
impacts, probabilities, mitigation steps, and ranking.
Risk Assessment Methodologies
Organizations evaluate risks through two primary lenses:
Quantitative Risk Assessment: Uses hard, objective financial
data to assign dollar values to risks.
o Asset Value (AV): The value of tangible (buildings) or intangible
(reputation) assets.
o Exposure Factor (EF): The percentage of asset value lost in an
incident.
o Single Loss Expectancy (SLE): Calculated as AV × EF.
o Annualized Rate of Occurrence (ARO): The number of
incidents expected per year.
o Annualized Loss Expectancy (ALE): Calculated as SLE ×
ARO.
o Countermeasure Decision: A countermeasure should be
purchased if (Before ALE – After ALE – Cost of
Countermeasure) results in a positive savings value.
Qualitative Risk Assessment: Uses soft, subjective scenario-
based data to rank risks.
o Risks are judged on two scales: Probability/Likelihood (how
often it might happen) and Impact (degree of harm to
productivity or operations).
Risk Response Strategies
For Negative Risks:
o Reduce (Mitigate): Using administrative, technical, or physical
controls to lower risk.
o Transfer (Assign): Moving the risk to another entity, such as
through insurance.
o Accept: Deciding the cost of protection exceeds the asset value
and living with the risk.
o Avoid: Deciding not to take the risk (e.g., choosing not to
acquire a company with poor security).
For Positive Risks:
o Exploit: Taking advantage of an opportunity, such as marketing
training materials developed for a specific risk.
o Share: Using a third party to help capture an opportunity.
o Enhance: Increasing the probability of a positive impact.
o Accept: Taking no steps because the potential effects add value.
Security Controls and Safeguards
Controls are categorized by their function and phase in the security lifecycle:
Administrative Controls: Managing human activity through policies
and procedures.
Detective Controls: Identifying that a threat has already entered a
system (e.g., Intrusion Detection Systems).
Preventive Controls: Stopping threats from encountering a
vulnerability (e.g., Intrusion Prevention Systems).
Corrective Controls: Reducing the effects of a realized threat (e.g.,
reloading from backups).
Deterrent Controls: Discouraging actions that would violate policy.
Compensating Controls: Alternatives used when a straightforward
mitigation is unavailable.
Physical Security Controls
Specific physical protections include HVAC for environmental stability, fire
suppression, EMI shielding, mantraps (two sets of doors with an alcove),
biometrics, and protected cabling.
Threats, Attacks, and Perpetrators
Attack Categories:
o Fabrications: Deceptions to trick users.
o Interceptions: Eavesdropping or redirecting transmissions.
o Interruptions: Breaking a communication channel.
o Modifications: Altering data in files or during transmission.
Perpetrators:
o Black-hat hackers: Unauthorized access to prove skill or steal
data.
o White-hat (Ethical) hackers: Authorized professionals
performing penetration testing.
o Gray-hat hackers: Average hackers who may alternate
between ethical and malicious behavior.
o Crackers: Possess sophisticated skills and hostile intent; they
represent the greatest threat.
Attack Vectors:
o Social Engineering: Uses human deception (phishing, vishing,
whaling, dumpster diving, tailgating).
o Wireless Attacks: Includes bluejacking, packet sniffing, and evil
twins.
o Web Application Attacks: Includes SQL injection, buffer
overflows, and cross-site scripting (XSS).
Organizational Assets and Impacts
Intellectual Property (IP): The central asset for many organizations,
including drug formulas, engineering plans, and recipes.
Finances: Malicious attacks on financial assets represent a worst-case
scenario and physical loss.
Availability and Opportunity Cost: Downtime results in
opportunity cost, which is the money lost because customers cannot
access services (e.g., an airline losing ticket sales).
Reputation: A security breach can lead to a decline in net worth and
market capitalization due to negative public perception.
Key Concepts and Terms
Administrative control: A category of security controls that manage
human behavior, such as developing and enforcing policies and
procedures.
Asset: Anything of value to an organization, which can include
tangible items like buildings or intangible assets like brand reputation.
Brute-force password attack: An attack method where a software
program attempts all possible combinations of passwords or user
IDs to gain unauthorized access.
Corrective control: A control designed to reduce the effects of a
threat that has already been realized, such as reloading a system from
a backup.
Countermeasure: A specific action or tool, such as a fire sprinkler
system, used to mitigate or address a particular threat.
Credential harvesting: A stage of a malicious attack where hackers
attempt to gain unauthorized access by using stolen logon
credentials on public-facing web applications.
Detective control: A control that identifies when a threat has
already entered a system, such as an Intrusion Detection System
(IDS).
Deterrent control: A security measure intended to discourage
individuals from taking actions that would violate security policies.
Eavesdropping: Also known as sniffing; this occurs when a network
interface is set to promiscuous mode to copy and analyze data packets
passing by.
Ethical hacker: An authorized security professional, often called a
white-hat hacker, who identifies system weaknesses specifically to
fix them.
Event: A measurable occurrence that has an impact on business
operations.
Exploit: The act of using a vulnerability to gain unauthorized access
to or damage an IT asset.
Hacker: An individual who breaks into computer systems without
authorization, often to steal data or take control of a remote computer.
Hijacking: A type of attack where a perpetrator takes control of a
session between two machines and masquerades as one of the
participants.
Impact: The degree of risk, harm, or loss caused when a perpetrator
exploits a threat or vulnerability.
Incident: A specific event that violates or threatens to violate a
company's security policy, justifying the use of a countermeasure.
Intellectual property: A central organizational asset that includes
sensitive information like drug formulas, engineering plans, and
recipes.
Likelihood: Also referred to as the Annualized Rate of Occurrence
(ARO); it is a calculation of how many times a loss is expected to occur
in a year.
Loss expectancy: The monetary value an organization expects to
lose from a risk, calculated either per instance (Single Loss
Expectancy) or annually (Annualized Loss Expectancy).
Malicious attack: A successful threat against an IT infrastructure that
exploits a design, system, or application weakness.
Man-in-the-middle attack: A form of hijacking where an attacker
intercepts and potentially alters communication between two parties
by masquerading as both ends of the connection.
Opportunity cost: The amount of money lost because customers
cannot access services or employees cannot work due to system
downtime.
Phishing: A deception-based fraud where an attacker uses
fraudulent emails or instant messages to trick victims into
revealing private information.
Preventive control: A control that stops a threat from ever
encountering a vulnerability, such as an Intrusion Prevention System
(IPS).
Qualitative risk assessment: A subjective, scenario-based
approach that ranks risk impact using relative scales like "Likely" or
"Catastrophic".
Quantitative risk assessment: An objective approach that uses
numerically based (hard) financial data to assign a specific dollar
value to a risk.
Replay attack: An attack where data packets are captured and
retransmitted to produce an unauthorized effect.
Residual risk: The risk that remains after an organization has
deployed all chosen mitigating controls and countermeasures.
Risk management: The continuous process of identifying and
assessing risks and deciding on the best response to ensure business
continuity.
Safeguard: A control that specifically addresses gaps or
weaknesses in an organization's security posture.
Sniffing: Another term for eavesdropping; it involves capturing and
analyzing network traffic.
Social engineering: A technique that uses human deception to
trick authorized users into providing information or access to
unauthorized individuals.
Spoofing: An attack where a person or program disguises itself as a
trusted entity to gain access to a resource.
Technical control: Security measures consisting of computer
programs, such as identification systems, encryption, or audit logs.
Zero day: A vulnerability for which the software manufacturer has not
yet released a patch, leaving the system exposed to attack.
The Remote Access Domain connects a user's computer to the internal
network, typically via Broadband Internet, to support mobile workers and
teleworkers. Because this domain provides a bridge between the public
internet and a company's private resources, it faces several specific security
challenges.
According to the sources, the following are common threats and
vulnerabilities for this domain:
Common Threats
Brute-force password attacks: These attacks target access points
and private data by systematically trying numerous password
combinations.
Unauthorized remote access: Attackers attempt to gain entry to
protected organizational resources.
Data leakage: This involves the unauthorized exposure of information
through remote access channels or from lost storage devices.
Common Vulnerabilities
Delayed patching: Remote workstations or laptops often face a
vulnerability window—the time between a patch release and its
application—because they are not as easily managed as internal
systems.
Primary Threat Targets
Within the Remote Access Domain, perpetrators specifically target the
following components:
Public-facing IP devices.
Multi-factor authentication (MFA) systems.
Remote access tools and infrastructure used by mobile workers and
teleworkers.
Security controls are the safeguards or countermeasures an organization
uses to avoid, counteract, or minimize loss or system unavailability. The
sources categorize these controls based on their function and the phase of
the security life cycle they address.
Major Categories of Controls
Administrative Controls: These manage "the things people do" and
focus on the activity phase of security. They primarily involve
developing and ensuring compliance with policies and procedures.
Technical Controls: These consist of computer programs and
automated systems. Examples include identification systems,
encryption, and audit logs.
Physical Controls: These are tangible measures used to protect the
physical environment and IT infrastructure. Examples include guards,
locks, fences, and biometrics.
Activity Phase Controls
Activity phase controls can be either administrative or technical and
correspond to the life cycle of a security program.
Preventive Controls: These stop threats from coming into contact
with a vulnerability.
o Example: An Intrusion Prevention System (IPS) that is
configured to actively block an attack rather than just logging it.
Detective Controls: These identify that a threat has already landed
in or entered a system.
o Example: An Intrusion Detection System (IDS) that detects
attacks like port scans and logs the activity for analysis.
Corrective Controls: These reduce the effects of a threat once it has
been realized.
o Example: Reloading a system from a backup after it has
been infected with malware.
Deterrent Controls: These discourage actions that could result in a
security violation.
o Example: A system that presents a warning message to a
user before they perform an action that might violate policy,
giving them the choice to continue or stop.
Compensating Controls: These are implemented when a standard
risk-mitigating solution is not straightforward or available.
Physical Security Controls
The sources provide extensive examples of controls specifically designed to
maintain a secure physical IT environment:
Environmental Stability: HVAC (Heating, ventilating, and air
conditioning) to ensure proper airflow and temperature, and fire
suppression systems to extinguish different types of fires.
Access Control: Mantraps (two sets of doors with a small alcove
between them), proximity readers for smart cards, and biometrics
(access based on physical characteristics).
Surveillance and Deterrence: Video surveillance for monitoring,
guards to provide a human presence, and fencing or barricades to
deter intruders.
Hardware Protection: Locks on cabinets and doors, and protected
access (cabling) to restrict physical access to network connections.
NIST Control Categories
The National Institute of Standards and Technology (NIST) suggests three
overarching categories for controls:
Management Controls: Used to manage the entire risk process, such
as reviewing security controls.
Operational Controls: Controls that personnel implement and
manage, such as physical security and incident response.
Technical Controls: Security controls that the computer system
executes, such as audit trails and identification systems.
When calculating Annualized Loss Expectancy (ALE), the
foundation of the calculation—the Single Loss Expectancy (SLE)—is
always calculated for only one item, regardless of how many of those
items the organization owns.
The sources emphasize several key points regarding this calculation:
SLE is for a Single Item: Even if a problem states that a company
has hundreds of assets (such as 500 workstations), you always
calculate the loss for only one workstation when determining the SLE.
ALE Formula: The formula for ALE is SLE × ARO (Annualized Rate of
Occurrence).
Total Annual Loss: While the SLE is based on one item, the ALE
represents the total expected financial loss for the entire
organization over a year based on how many of those items are
expected to be lost or compromised during that time.
Example for Clarification: If an organization has 100 laptops and
each is worth $1,500, and they lose an average of six laptops per year:
The SLE is $1,500 (the value of one laptop).
The ARO is 6 (the number of incidents per year).
The ALE is $9,000 ($1,500 × 6), representing the total expected
annual loss for all such incidents across the company.
The result of the risk identification process is known as a risk register,.
A risk register serves as a central document that identifies and categorizes
various risks to ensure that the most significant ones are addressed.
According to the sources, a standard risk register should contain at least the
following information:
A description of the risk: A brief explanation of the potential threat
or event,.
The expected impact: The potential harm or loss to business
operations if the event occurs,.
The probability: The likelihood of the event actually occurring,.
Mitigation steps: The specific actions planned to reduce the risk,.
Contingency steps: The actions to be taken should the risk event be
realized,.
Risk rank: The priority level of the risk relative to others identified,.
The sources categorize malicious attacks into several groups based on their
methods, targets, and the way they are executed. Below is a detailed list of
these attacks and how they are accomplished.
Common Malicious Attacks
Brute-Force Password Attack: An attacker uses a software program
to systematically try all possible combinations of a likely password,
user ID, or security code until a match is found.
Dictionary Password Attack: A specialized software program tries
all the words from a dictionary file as potential passwords, relying on
the fact that many users make poor password choices.
Credential Harvesting and Stuffing: Hackers steal or obtain logon
IDs and passwords and then attempt to use those credentials on
multiple public-facing web applications to gain unauthorized access.
IP Address Spoofing: An attacker or program disguises itself by
presenting a false network address. This is often used to pretend to be
a trusted computer on a target's network to bypass security filters.
Hijacking: A perpetrator takes control of an active session between
two machines and masquerades as one of them.
o Man-in-the-Middle: An attacker uses a program to intercept,
control, or eavesdrop on a connection by masquerading as both
ends of the connection.
o Session Hijacking: The attacker takes over an existing
connection, often by gaining control of a network device like a
firewall to monitor and determine sequence numbers to drop
legitimate users and take their place.
Phishing: Fraudulent emails or instant messages are sent to trick
victims into revealing private information, such as credit card numbers
or birth dates.
o Spear Phishing: A targeted version of phishing aimed at a
specific individual or organization.
Pharming: Users are redirected to spoofed, malicious websites
through "DNS poisoning," where the domain name on a DNS server is
corrupted. This allows scammers to target large groups of people
simultaneously.
Replay Attack: Data packets are captured from a network and
retransmitted later to produce an unauthorized effect, such as using
authenticated packets to gain access to a system.
Eavesdropping (Sniffing): A host sets its network interface to
"promiscuous mode," allowing it to copy and analyze all data packets
passing by on that network segment without the users' knowledge.
Birthday Attack: A type of cryptographic attack that exploits the
"birthday problem" in probability theory to find collisions in one-way
hashes, making it easier to compromise a hashed password.
Social Engineering Attacks
These attacks rely on human deception rather than technical exploits.
Vishing: Performing a phishing attack via telephone to elicit personal
information through verbal persuasion.
Smishing: Phishing performed via SMS (text) messages to a mobile
device.
Whaling: Targeting high-value employees or executive users (the "big
fish").
Dumpster Diving: Searching through trash to find papers containing
sensitive or private data.
Tailgating: Following an authorized person closely enough to sneak
through a secure door or access point.
Shoulder Surfing: Looking over a person's shoulder while they are
typing on a computer or screen to steal credentials.
Wireless Network Attacks
Evil Twin: An attacker sets up a fake open or public wireless network
to use a packet sniffer on unsuspecting users who connect.
Bluejacking: Hacking and taking control of the Bluetooth wireless link
between a user's smartphone and a device like an earpiece.
Bluesnarfing: Sniffing communications traffic between Bluetooth-
connected devices.
Jamming/Interference: Sending radio frequencies on the same
frequency as wireless access points to disrupt their availability and
cause a denial of service.
War Driving: Physically driving around neighborhoods or business
complexes to locate and map wireless access points.
Web Application Attacks
SQL Injection: Injecting malicious Structured Query Language (SQL)
commands into a web application to manipulate and steal data from
the back-end database.
Cross-Site Scripting (XSS): Injecting malicious scripts into a web
application server to redirect attacks back to the client browser.
Buffer Overflow: Attempting to push more data into a memory buffer
than it can handle, creating a condition that can lead to system
crashes or the execution of malicious code.
Cross-Site Request Forgery (CSRF): Leveraging an authenticated
user session to send unauthorized and malicious requests to a target
website.
Zero Day: Exploiting a brand-new software vulnerability or bug for
which the manufacturer has not yet released a patch.
General Attack Categories
The sources also classify attacks into four broad functional categories:
Fabrications: Creating deceptions to trick users into performing an
action.
Interceptions: Eavesdropping on transmissions and redirecting them
for unauthorized use.
Interruptions: Causing a break in a communication channel to block
data transmission.
Modifications: Altering data either while it is in transmission or stored
in files.