1.
Risk Management:
Obj. 1.5: Explain the different threat actors, vectors and intelligence
sources:
* Risk: Risk is the likelihood of a threat actor taking
advantage of a vulnerability by using a threat against an IT asset.
* Asset: An asset is any part of an IT infrastructure that
has value
* Likelihood: Likelihood is the probability of assets being
damaged over time
* Threat Actors: A Threat Actor is anyone or anything with
the motive and resources to attack another's IT infrastructure
i.e. Hackers, Hacktivists,
Script kiddies, Insiders, Competitors, Shadow IT, Criminal syndicates, State
actors, Advanced persistent threat (APT)
* Vulnerabilities: A vulnerability is a weakness in an
asset
* Threat: A threat is an action that a threat actor can use
against a vulnerability to cause harm
* Remediation: Creating a system to identify and fix gaps
in the IT systems is essential to a successful cyber risk management program.
This process of identifying and
fixing problems is called cybersecurity remediation.
* Attack Vectors: Pathways to gain access to infrastructure
i.e. Weak configurations, Open firewall ports, Lack of user security awareness,
Lack of multifactor authentication,
Missing patches such as
Equifax hack(2017), Infected USB thumb drives such as Stuxnet worm(2010);
Supply-chain attack i.e.
Manufacturers, Contractors, Implementers, outsourced software development, Right-
to-audit clause
* Threat Intelligence Sources: Facilitate risk management.
Hardening can reduce incident response time.
Provide
cybersecurity insight such as Adversary tactics, techniques, and procedures(TTP).
Threat maps
such as geographical representations of malware
outbreaks([Link]).
Closed/proprietary intelligence. OSINT (Open-source intelligence): such as
Government reports, Media, Academic papers (Google Dorking).
File/code
repositories such as GitHub. Vulnerability databases: Common Vulnerabilities and
Exposures (CVEs).
Dark
Web/Dark Net: Tor network, Tor Web browser; Encrypted anonymous connections, Not
indexed by search engines,
Tor
encryption and anonymity: Journalists, Law enforcement, Government informants.
Automated
Indicator Sharing (AIS): Exchange of cybersecurity intelligence (CI) between
entities.
AIS uses a
specialised format called Structured Threat Information eXpression (STIX)
for
packaging-up the threat intelligence information that is understood among many
systems.
STIX is a
data exchange format for cybersecurity intelligence, to transmit that package
across a network,
Trusted
Automated eXchange of Intelligence Information (TAXII) is used: Like RSS feed for
threats,
Consists of
TAXII servers and clients, Real-time cyber intelligence feeds,
TAXII is
built-in to a lot of security monitoring tools to get up-to-date threat indicator
feeds automatically.
Obj. 5.2: Explain the importance of applicable regulations, standards,
or frameworks that impact organizational security posture:
* Risk Vectors:
> Mission-critical IT systems: Payment processing,
Human resources, Emergency Systems
> Sensitive data: Do we know what we have and where
it is?
> Third-party access to the systems and/or data
* Physical Risk Vectors:
> Access control vestibules (Mantraps) i.e. A
building where there are 2 or more entrance gates and when a person enters through
the first gate,
the first gate gets closed completely and then
only the second gate is opened. This is called a "Mantrap".
> Server room access
> Limit USB bootable devices: Enabled disk volume
encryption on the underlying disk.
* Risk Management Frameworks (RMFs):
> Center for Internet Security (CIS): Publishes
cybersecurity best practices
> National Institute of Standards and Technology
(NIST) in the United States: NIST Risk Management Framework/Cybersecurity Framework
(CSF)
> International Organization for
Standardization/International Electrotechnical Commision (ISO/IEC): Standards such
as 27001/27002/27701/31000.
All of theses are international standards that are related to IT
system and information security.
* Financial RMFs:
> Statement on Standards for Attestation Engagements
System and Organization Controls (SSAE SOC 2): Financial statement integrity,
Internal controls, Type 1 and Type 2
* RMFs:
> NIST Special Publication (SP) 800-30, Rev.1 is the
guide for Conducting Risk Assessments
* Data Privacy Regulations and Standards: There are some
international standards that apply to any organization in the world
dealing with certain types of data. And
then there are some that are jurisdictional, they apply only when data for example,
is stored within a certain country, only
certain laws would apply.
> General Data Protection Regulation (GDPR): These
data privacy rules would apply to the private information related to European Union
or EU citizens,
regardless of where that information is being processed or
gathered or shared.
> Health Insurance Portability and Accountability Act
(HIPAA) in the US: Designed to protect american patient medical information
> Payment Card Industry Data Security Standard (PCI
DSS) International: This applies to any organization that's dealing with cardholder
information,
whether it's debit cards or
credit cards like Visa or Master Card. By PCI DSS we get recommendations on how to
harden the environment and
protect cardholder
information without specifying exact configuration details.
* Types of Security Policies:
> Acceptable use policy (AUP): E-mail, Social media,
Web browsing
> Resource access policies: App or file access
> Account Policies: Account Hardening such as MFA
required or complex passwords
> Data retention policies: Often dictated by
regulations
> Change control and Asset management policies that
will apply to the IT team where there is a standard, repeatable,
definable process for implementing change
in a controlled manner.
Obj. Note:
RMFs provide guidance on identifying and managing
risk
Security regulations and standards such as GDPR,
HIPAA, PCI DSS are designed to protect sensitive data.
Organization security policies are designed to
protect assets.
Obj. 5.1: Compare and contrast various types of controls:
* Security Controls:
> Solution that mitigates threat, Example: Malware
scanner mitigates malware infections
> Implemented differently based on
platform/vendor/user: Network infrastructure devices Switches, routers, firewalls
* Security Control Categories:
> Managerial/administrative: Employee background
checks
> Operational: Periodic review of security policies
> Technical: Firewall rules configuration, Malware
scanners
* Security Control Types:
> Physical: Access control vestibules (Mantrap)
> Detective: Log analysis
> Corrective: Patching known vulnerabilities
> Deterrent: Device logon warning banners
> Compensating: Network isolation for Internet of
Things (IoT) devices
-> [Link] is a wbesite that allows to search for
vulnerable devices on the Internet.
* Cloud Security Control Documents:
> Cloud Security Alliance (CSA): Cloud Controls
Matrix (CCM)
Obj. 5.4: Summarize risk management processes and concepts:
* Risk Assessment:
> Prioritization of threats against assets and
determining what to do about it.
> Applicable to: Entire organization, A single
project or department or system
> Targets: Servers, Legacy systems, Intellectual
Property (IP), Software licensing
* Risk Assessment Process:
> Risk awareness: Cybersecurity intelligence sources
> Evaluate security controls: Inherent (current) and
residual risk
> Implement security controls
> Periodic review
* Risk Types:
> Environmental: Flood, Hurricane
> Person-made: Riots, Terrorism, Sabotage
> Internal: Malicious insider, Malware infections
> External: Distributed denial of service (DDoS)
* Risk Treatments:
> Mitigation/reduction: Security controls are
proactively put in place before undertaking the risk
> Transference/sharing: Some risk is transferred to a
third party in exchange for payment. Example: cybersecurity insurance
> Avoidance: Avoid an activity because the risks
outweigh potential gains
> Acceptance: The current level of risk is
acceptable. The risk falls within the organization's risk appetite.
* Quantitative Risk Assessment:
> Based on numeric values: Money
> Asset value (AV): What is that asset and how much
it costs?
> Exposure factor (EF): Percentage of asset value
loss when negative incident occurs.
> Single Loss Expectancy (SLE): How much loss is
experienced during one negative incident? SLE = AV X EF (Multiply asset value by
the exposure factor to get SLE)
Example: Asset value = $24,000, Exposure factor = 12.5%. $24,000(AV) X 0.125
(EF) = $3,000 (SLE).
Explanation: An E-commerce website that generates $24,000 of revenue
per day. So $24,000 is the value of that asset on daily basis.
Assume that the website got a risk of downtime whether due to a
malicious attack or some kind of failed hardware component, from past experiences,
it has been learned that on average, the website is down for about 3
Hours. So, take 3 Hours and divide it by 24 Hours of a day, 3/24 = 0.125 = 12.5%
EF.
To calculate SLE, $24,000 X 12.5% = $3,000 (SLE).
> Annualized rate of occurrence (ARO): Expected
number of yearly occurrences. Example: 2-3 times per year.
> Annualized loss expectancy (ALE): Total yearly cost
of bad things happening. To get ALE, multiply the SLE with the ARO. SLE X ARO = ALE
So, as per the example of E-commerce website $3000 (SLE) X 2 (ARO) = $6,000
(ALE).
We are calculating the ALE to compare that amount against how much we are
spending annually
for security controls to protect against that threat being realized against
the E-commerce website.
So, if the ALE is $6,000 then it makes sense to spend "$6,000 or less
annually" to protect that asset.
* Qualitative Risk Assessment:
> Based on subjective opinions regarding: Threat
likelihood, Impact of realized threat
> Threats are given a severity rating
* Risk Register:
> Organization should have one or more
> Centralized list of risks, severities,
responsibilities, and mitigations
> Generally considered qualitative: Severity or
impact ratings, Occasionally includes hard numbers(%,$)
* Risk Heat Map:
> Take risk severity levels and map visually by color
> Risk Register can be combined with Risk heat map
* Risk Matrix:
> Table of risk details
> Similar to a heat map but without colors
* Business Impact Analysis (BIA):
> Prioritize mission-critical processes: Payment
processing systems, Customer/patient records
> Assess risk: Identify sensitive data, Identify
single points of failure
* Business Impact:
> Financial: Fines, Loss of contracts
> Reputation
> Data loss: Breach notification, Escalation
requirements, Data Exfiltration
> Recovery point objective (RPO): Maximum tolerable
amount of data loss, Directly related to backup frequency
> Recovery time objective (RTO): Maximum tolerable
amount of downtime, Return systems and data to usable state
* Failed Component Impact:
> Mean time between failures (MTBF): Average time
between repairable component failures, Software patching
> Mean time to failure (MTTF): Average time between
Non-repairable component failures, Hard disks, switches, routers
> Mean time to repair (MTTR): Time required to repair
a failed component
* Locating Critical Resources:
> Data discovery and classification: Where is our
sensitive data?,
Privacy threshold assessment (PTA): First step before implementing solutions
related to sensitive data
> Impact on sensitive data: Privacy impact assessment
(PIA), Regulatory compliance
Obj Note:
A risk assessment strives to determine the likelihood
and impact of threats
A qualitative risk assessment is based on subjective
risk severity levels
A risk register is an up-to-date centralized list of
risks and their relative severities and mitigations
Risk heat maps and risk matrices are used to plot and
chart risk severity levels
BIA identifies how negative incidents will impact
business processes and sensitive data
MTBF, MTTF and MTTR are related to the impact of
failed components
The RTO defines the maximum tolerable amount of
downtime
RPO defines the maximum tolerable amount of data loss
Obj. 5.5: Explain privacy and sensitive data concepts in relation to
security:
* Data Classification:
> Government/military classification: Top secret,
Secret, Confidential
> Standard classification: PII (Personally
Identifiable Information), PHI (Protected Health Information), Proprietary,
Public/Private, Critical, Financial
* Data Privacy Standards:
> Ensure data privacy and breach notification
> Levy fines
> Protect intellectual property (IP)
> HIPAA is a data privacy standard designed to
safeguard medical information related to patients in US institutions
that deal with things like medical plans,
any kind of medical institution
> PCI DSS is used to protect credit card or
cardholder information.
> GDPR in European Union is a data privacy standard
for EU citizens.
* Data Classification Tools:
> Any method of applying metadata: Cloud resource
tagging
* Data Roles and Responsibilities:
> Owner: Legal data owner, Set policies on how data
will be managed
> Controller: Ensure data complies with applicable
regulations
> Processor: Handles data in accordance with privacy
guidelines
> Custodian/Steward: Responsible for managing data
(permissions, backup) in alignment with data owner policies
> Data privacy officer (DPO): Ensures data privacy
regulation compliance such as with GDPR
* Information Life Cycle:
> Security involved at every phase
> Data collection: Consent
> Implementation depends on regulations/standards
> Information Life Cycle Phases in GDPR: Collect,
Store, Process, Sharing, Archive/Delete
* Personally Identifiable Information (PII):
> One or more pieces of sensitive information that
can be traced back to an individual: Social security number, E-mail address,
Credit card number, Home address, Web
brower cookie containing sensitive session identifiers
* Protected Health Information (PHI):
> One or more pieces of sensitive medical information
that can be traced back to an individual: Health insurance plan number, Blood type,
Patient medical aliments
* Privacy-Enhancing Technologies:
> Anonymization
> The GDPR allows anonymized data collection and use
without user consent
> Anonymized data has limited marketing value
* Anonymization Techniques:
> Pseudo-anonymization: Replace PII with fake
identifiers
> Data minimization: Limit stored/retained sensitive
data
> Tokenization: A digital token authorizes access
instead of the original credentials.
> Data Masking: Hide sensitive data from unauthorized
users, Masked out credit card number digits on a receipt
* Data Sovereignty:
> Location of data and laws that apply to it: Where
did the data originate?, Where does the data reside?, Which laws/regulations apply
to the data?
Obj Note:
Data classification assigns labels to data to
facilitate management
Common data privacy standards include HIPAA, PCI DSS,
GDPR
Data owners determine data management policies
Data custodians apply data management policies
Obj. 2.7: Explain the importance of physical security controls:
* Data Destruction:
> Paper, film, magnetic, tape: Burning, Pulping,
Shredding (Pulverizing)
* Digital Data Destruction:
> Failed or decommisioned storage devices.
> Storage device end-of-life policies: Reuse?,
Donate?, Destroy?
* Digital Media Sanitization:
> Data is still recoverable: Deleted files,
repartitioned, or reformatted drives
> Disk wiping tools: SSD and HDD: Multiple pass disk
overwrites, HDD only: Degaussing
> Cryptographic Erasure: Destroy storage media
decryption key, Self-encrypting drives (SEDs)
Obj. 5.3: Explain the importance of policies to organizational
security:
* Personnel Management Policies:
> Standard Operating Procedure (SOP): Example: Proper
steps for sending sensitive data via E-mail
> Mandatory vacation, Job Role Rotation: Detection of
irregularities
> Separation of Duties (Multi-Person Control): Reduce
likelihood of internal fraud, Does not prevent collusion
* Employee/Contractor Hiring:
> Social media analysis
> Web search
> Background check: Criminal record, Unpaid fines,
Credit check, Interviews with friends-family and/or colleagues
* User Onboarding:
> Non-disclosure agreement (NDA): Proprietary
secrets, PII/PHI
> Security policy awareness: User sign-off
> User account and resource access
> Issue security badge, smart card
* User Habits:
> Clean desk policies
> Physical and digital document shredding: Mitigates
dumpster diving, data recovery
> Personally-owned devices: Mobile device management
(MDM), Bring your own device (BYOD)
* User Training:
> Ongoing, role-based
> Computer-based training (CBT)
> Gamification: Capture the flag contests
> Phishing campaigns/simulations: Lunch and learn,
Can be part of a penetration test
* User Offboarding:
> Termination letter
> Exit interview
> Return of equipment
> Knowledge transfer
> Account disablement vs. deletion
* Third-Party Risk Management:
> Measurement systems analysis (MSA)
> Data Loss Prevention (DLP) systems: Reduce
intentional/unintentional sensitive data exfiltration
* Supply-Chain Security Risks:
> Hardware and software vendors: End-of-service life
(EOL, EOSL) means no more patches or support
> Cloud service providers security compliance
> Contractors: Data privacy notices
> Company mergers and system linking
> Software developers using third-party components
* Agreement Types:
> Interconnection Security Agreement (ISA): Legal
review, regulatory compliance, Linking companies, partners, agencies, Vulnerability
scan results, Mandatory training/certification, Input from IT security
professionals
> Service Level Agreement (SLA): Contractual document
stating level of service, Guarantee service uptime, Consequences for not meeting
requirements
> Memorandum of Understanding (MOU): Broad terms of
agreement between parties
> Memorandum of Agreement (MOA): Detailed terms
between parties
> Business Partnership Agreement (BPA): Legal
document, Responsibilities, investment, decision-making
> Non-disclosure Agreement (NDA): Prevent sensitive
data disclosure to third parties