0% found this document useful (0 votes)
11 views10 pages

Cyber Risk Management Essentials

CompTIA Security+ (SY0-601) Notes

Uploaded by

neyoxaw624
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
11 views10 pages

Cyber Risk Management Essentials

CompTIA Security+ (SY0-601) Notes

Uploaded by

neyoxaw624
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd

1.

Risk Management:

Obj. 1.5: Explain the different threat actors, vectors and intelligence
sources:

* Risk: Risk is the likelihood of a threat actor taking


advantage of a vulnerability by using a threat against an IT asset.
* Asset: An asset is any part of an IT infrastructure that
has value
* Likelihood: Likelihood is the probability of assets being
damaged over time
* Threat Actors: A Threat Actor is anyone or anything with
the motive and resources to attack another's IT infrastructure
i.e. Hackers, Hacktivists,
Script kiddies, Insiders, Competitors, Shadow IT, Criminal syndicates, State
actors, Advanced persistent threat (APT)
* Vulnerabilities: A vulnerability is a weakness in an
asset
* Threat: A threat is an action that a threat actor can use
against a vulnerability to cause harm
* Remediation: Creating a system to identify and fix gaps
in the IT systems is essential to a successful cyber risk management program.
This process of identifying and
fixing problems is called cybersecurity remediation.
* Attack Vectors: Pathways to gain access to infrastructure
i.e. Weak configurations, Open firewall ports, Lack of user security awareness,
Lack of multifactor authentication,
Missing patches such as
Equifax hack(2017), Infected USB thumb drives such as Stuxnet worm(2010);
Supply-chain attack i.e.
Manufacturers, Contractors, Implementers, outsourced software development, Right-
to-audit clause
* Threat Intelligence Sources: Facilitate risk management.
Hardening can reduce incident response time.
Provide
cybersecurity insight such as Adversary tactics, techniques, and procedures(TTP).
Threat maps
such as geographical representations of malware
outbreaks([Link]).

Closed/proprietary intelligence. OSINT (Open-source intelligence): such as


Government reports, Media, Academic papers (Google Dorking).
File/code
repositories such as GitHub. Vulnerability databases: Common Vulnerabilities and
Exposures (CVEs).
Dark
Web/Dark Net: Tor network, Tor Web browser; Encrypted anonymous connections, Not
indexed by search engines,
Tor
encryption and anonymity: Journalists, Law enforcement, Government informants.
Automated
Indicator Sharing (AIS): Exchange of cybersecurity intelligence (CI) between
entities.
AIS uses a
specialised format called Structured Threat Information eXpression (STIX)
for
packaging-up the threat intelligence information that is understood among many
systems.
STIX is a
data exchange format for cybersecurity intelligence, to transmit that package
across a network,
Trusted
Automated eXchange of Intelligence Information (TAXII) is used: Like RSS feed for
threats,
Consists of
TAXII servers and clients, Real-time cyber intelligence feeds,
TAXII is
built-in to a lot of security monitoring tools to get up-to-date threat indicator
feeds automatically.

Obj. 5.2: Explain the importance of applicable regulations, standards,


or frameworks that impact organizational security posture:

* Risk Vectors:

> Mission-critical IT systems: Payment processing,


Human resources, Emergency Systems
> Sensitive data: Do we know what we have and where
it is?
> Third-party access to the systems and/or data

* Physical Risk Vectors:

> Access control vestibules (Mantraps) i.e. A


building where there are 2 or more entrance gates and when a person enters through
the first gate,
the first gate gets closed completely and then
only the second gate is opened. This is called a "Mantrap".
> Server room access
> Limit USB bootable devices: Enabled disk volume
encryption on the underlying disk.

* Risk Management Frameworks (RMFs):

> Center for Internet Security (CIS): Publishes


cybersecurity best practices
> National Institute of Standards and Technology
(NIST) in the United States: NIST Risk Management Framework/Cybersecurity Framework
(CSF)
> International Organization for
Standardization/International Electrotechnical Commision (ISO/IEC): Standards such
as 27001/27002/27701/31000.

All of theses are international standards that are related to IT


system and information security.

* Financial RMFs:

> Statement on Standards for Attestation Engagements


System and Organization Controls (SSAE SOC 2): Financial statement integrity,
Internal controls, Type 1 and Type 2

* RMFs:

> NIST Special Publication (SP) 800-30, Rev.1 is the


guide for Conducting Risk Assessments
* Data Privacy Regulations and Standards: There are some
international standards that apply to any organization in the world
dealing with certain types of data. And
then there are some that are jurisdictional, they apply only when data for example,
is stored within a certain country, only
certain laws would apply.

> General Data Protection Regulation (GDPR): These


data privacy rules would apply to the private information related to European Union
or EU citizens,

regardless of where that information is being processed or


gathered or shared.
> Health Insurance Portability and Accountability Act
(HIPAA) in the US: Designed to protect american patient medical information
> Payment Card Industry Data Security Standard (PCI
DSS) International: This applies to any organization that's dealing with cardholder
information,
whether it's debit cards or
credit cards like Visa or Master Card. By PCI DSS we get recommendations on how to
harden the environment and
protect cardholder
information without specifying exact configuration details.

* Types of Security Policies:

> Acceptable use policy (AUP): E-mail, Social media,


Web browsing
> Resource access policies: App or file access
> Account Policies: Account Hardening such as MFA
required or complex passwords
> Data retention policies: Often dictated by
regulations
> Change control and Asset management policies that
will apply to the IT team where there is a standard, repeatable,
definable process for implementing change
in a controlled manner.

Obj. Note:

RMFs provide guidance on identifying and managing


risk

Security regulations and standards such as GDPR,


HIPAA, PCI DSS are designed to protect sensitive data.

Organization security policies are designed to


protect assets.

Obj. 5.1: Compare and contrast various types of controls:

* Security Controls:

> Solution that mitigates threat, Example: Malware


scanner mitigates malware infections
> Implemented differently based on
platform/vendor/user: Network infrastructure devices Switches, routers, firewalls
* Security Control Categories:

> Managerial/administrative: Employee background


checks
> Operational: Periodic review of security policies
> Technical: Firewall rules configuration, Malware
scanners

* Security Control Types:

> Physical: Access control vestibules (Mantrap)


> Detective: Log analysis
> Corrective: Patching known vulnerabilities
> Deterrent: Device logon warning banners
> Compensating: Network isolation for Internet of
Things (IoT) devices

-> [Link] is a wbesite that allows to search for


vulnerable devices on the Internet.

* Cloud Security Control Documents:

> Cloud Security Alliance (CSA): Cloud Controls


Matrix (CCM)

Obj. 5.4: Summarize risk management processes and concepts:

* Risk Assessment:

> Prioritization of threats against assets and


determining what to do about it.
> Applicable to: Entire organization, A single
project or department or system
> Targets: Servers, Legacy systems, Intellectual
Property (IP), Software licensing

* Risk Assessment Process:

> Risk awareness: Cybersecurity intelligence sources


> Evaluate security controls: Inherent (current) and
residual risk
> Implement security controls
> Periodic review

* Risk Types:

> Environmental: Flood, Hurricane


> Person-made: Riots, Terrorism, Sabotage
> Internal: Malicious insider, Malware infections
> External: Distributed denial of service (DDoS)

* Risk Treatments:

> Mitigation/reduction: Security controls are


proactively put in place before undertaking the risk
> Transference/sharing: Some risk is transferred to a
third party in exchange for payment. Example: cybersecurity insurance
> Avoidance: Avoid an activity because the risks
outweigh potential gains
> Acceptance: The current level of risk is
acceptable. The risk falls within the organization's risk appetite.

* Quantitative Risk Assessment:

> Based on numeric values: Money


> Asset value (AV): What is that asset and how much
it costs?
> Exposure factor (EF): Percentage of asset value
loss when negative incident occurs.
> Single Loss Expectancy (SLE): How much loss is
experienced during one negative incident? SLE = AV X EF (Multiply asset value by
the exposure factor to get SLE)

Example: Asset value = $24,000, Exposure factor = 12.5%. $24,000(AV) X 0.125


(EF) = $3,000 (SLE).

Explanation: An E-commerce website that generates $24,000 of revenue


per day. So $24,000 is the value of that asset on daily basis.

Assume that the website got a risk of downtime whether due to a


malicious attack or some kind of failed hardware component, from past experiences,

it has been learned that on average, the website is down for about 3
Hours. So, take 3 Hours and divide it by 24 Hours of a day, 3/24 = 0.125 = 12.5%
EF.

To calculate SLE, $24,000 X 12.5% = $3,000 (SLE).


> Annualized rate of occurrence (ARO): Expected
number of yearly occurrences. Example: 2-3 times per year.
> Annualized loss expectancy (ALE): Total yearly cost
of bad things happening. To get ALE, multiply the SLE with the ARO. SLE X ARO = ALE

So, as per the example of E-commerce website $3000 (SLE) X 2 (ARO) = $6,000
(ALE).

We are calculating the ALE to compare that amount against how much we are
spending annually

for security controls to protect against that threat being realized against
the E-commerce website.

So, if the ALE is $6,000 then it makes sense to spend "$6,000 or less
annually" to protect that asset.

* Qualitative Risk Assessment:

> Based on subjective opinions regarding: Threat


likelihood, Impact of realized threat
> Threats are given a severity rating

* Risk Register:

> Organization should have one or more


> Centralized list of risks, severities,
responsibilities, and mitigations
> Generally considered qualitative: Severity or
impact ratings, Occasionally includes hard numbers(%,$)

* Risk Heat Map:

> Take risk severity levels and map visually by color


> Risk Register can be combined with Risk heat map

* Risk Matrix:

> Table of risk details


> Similar to a heat map but without colors

* Business Impact Analysis (BIA):

> Prioritize mission-critical processes: Payment


processing systems, Customer/patient records
> Assess risk: Identify sensitive data, Identify
single points of failure

* Business Impact:

> Financial: Fines, Loss of contracts


> Reputation
> Data loss: Breach notification, Escalation
requirements, Data Exfiltration
> Recovery point objective (RPO): Maximum tolerable
amount of data loss, Directly related to backup frequency
> Recovery time objective (RTO): Maximum tolerable
amount of downtime, Return systems and data to usable state

* Failed Component Impact:

> Mean time between failures (MTBF): Average time


between repairable component failures, Software patching
> Mean time to failure (MTTF): Average time between
Non-repairable component failures, Hard disks, switches, routers
> Mean time to repair (MTTR): Time required to repair
a failed component

* Locating Critical Resources:

> Data discovery and classification: Where is our


sensitive data?,

Privacy threshold assessment (PTA): First step before implementing solutions


related to sensitive data
> Impact on sensitive data: Privacy impact assessment
(PIA), Regulatory compliance

Obj Note:

A risk assessment strives to determine the likelihood


and impact of threats

A qualitative risk assessment is based on subjective


risk severity levels

A risk register is an up-to-date centralized list of


risks and their relative severities and mitigations
Risk heat maps and risk matrices are used to plot and
chart risk severity levels

BIA identifies how negative incidents will impact


business processes and sensitive data

MTBF, MTTF and MTTR are related to the impact of


failed components

The RTO defines the maximum tolerable amount of


downtime

RPO defines the maximum tolerable amount of data loss

Obj. 5.5: Explain privacy and sensitive data concepts in relation to


security:

* Data Classification:

> Government/military classification: Top secret,


Secret, Confidential
> Standard classification: PII (Personally
Identifiable Information), PHI (Protected Health Information), Proprietary,
Public/Private, Critical, Financial

* Data Privacy Standards:

> Ensure data privacy and breach notification


> Levy fines
> Protect intellectual property (IP)
> HIPAA is a data privacy standard designed to
safeguard medical information related to patients in US institutions
that deal with things like medical plans,
any kind of medical institution
> PCI DSS is used to protect credit card or
cardholder information.
> GDPR in European Union is a data privacy standard
for EU citizens.

* Data Classification Tools:

> Any method of applying metadata: Cloud resource


tagging

* Data Roles and Responsibilities:

> Owner: Legal data owner, Set policies on how data


will be managed
> Controller: Ensure data complies with applicable
regulations
> Processor: Handles data in accordance with privacy
guidelines
> Custodian/Steward: Responsible for managing data
(permissions, backup) in alignment with data owner policies
> Data privacy officer (DPO): Ensures data privacy
regulation compliance such as with GDPR
* Information Life Cycle:

> Security involved at every phase


> Data collection: Consent
> Implementation depends on regulations/standards
> Information Life Cycle Phases in GDPR: Collect,
Store, Process, Sharing, Archive/Delete

* Personally Identifiable Information (PII):

> One or more pieces of sensitive information that


can be traced back to an individual: Social security number, E-mail address,
Credit card number, Home address, Web
brower cookie containing sensitive session identifiers

* Protected Health Information (PHI):

> One or more pieces of sensitive medical information


that can be traced back to an individual: Health insurance plan number, Blood type,
Patient medical aliments

* Privacy-Enhancing Technologies:

> Anonymization
> The GDPR allows anonymized data collection and use
without user consent
> Anonymized data has limited marketing value

* Anonymization Techniques:

> Pseudo-anonymization: Replace PII with fake


identifiers
> Data minimization: Limit stored/retained sensitive
data
> Tokenization: A digital token authorizes access
instead of the original credentials.
> Data Masking: Hide sensitive data from unauthorized
users, Masked out credit card number digits on a receipt

* Data Sovereignty:

> Location of data and laws that apply to it: Where


did the data originate?, Where does the data reside?, Which laws/regulations apply
to the data?

Obj Note:

Data classification assigns labels to data to


facilitate management

Common data privacy standards include HIPAA, PCI DSS,


GDPR

Data owners determine data management policies

Data custodians apply data management policies

Obj. 2.7: Explain the importance of physical security controls:


* Data Destruction:

> Paper, film, magnetic, tape: Burning, Pulping,


Shredding (Pulverizing)

* Digital Data Destruction:

> Failed or decommisioned storage devices.


> Storage device end-of-life policies: Reuse?,
Donate?, Destroy?

* Digital Media Sanitization:

> Data is still recoverable: Deleted files,


repartitioned, or reformatted drives
> Disk wiping tools: SSD and HDD: Multiple pass disk
overwrites, HDD only: Degaussing
> Cryptographic Erasure: Destroy storage media
decryption key, Self-encrypting drives (SEDs)

Obj. 5.3: Explain the importance of policies to organizational


security:

* Personnel Management Policies:

> Standard Operating Procedure (SOP): Example: Proper


steps for sending sensitive data via E-mail
> Mandatory vacation, Job Role Rotation: Detection of
irregularities
> Separation of Duties (Multi-Person Control): Reduce
likelihood of internal fraud, Does not prevent collusion

* Employee/Contractor Hiring:

> Social media analysis


> Web search
> Background check: Criminal record, Unpaid fines,
Credit check, Interviews with friends-family and/or colleagues

* User Onboarding:

> Non-disclosure agreement (NDA): Proprietary


secrets, PII/PHI
> Security policy awareness: User sign-off
> User account and resource access
> Issue security badge, smart card

* User Habits:

> Clean desk policies


> Physical and digital document shredding: Mitigates
dumpster diving, data recovery
> Personally-owned devices: Mobile device management
(MDM), Bring your own device (BYOD)

* User Training:

> Ongoing, role-based


> Computer-based training (CBT)
> Gamification: Capture the flag contests
> Phishing campaigns/simulations: Lunch and learn,
Can be part of a penetration test

* User Offboarding:

> Termination letter


> Exit interview
> Return of equipment
> Knowledge transfer
> Account disablement vs. deletion

* Third-Party Risk Management:

> Measurement systems analysis (MSA)


> Data Loss Prevention (DLP) systems: Reduce
intentional/unintentional sensitive data exfiltration

* Supply-Chain Security Risks:

> Hardware and software vendors: End-of-service life


(EOL, EOSL) means no more patches or support
> Cloud service providers security compliance
> Contractors: Data privacy notices
> Company mergers and system linking
> Software developers using third-party components

* Agreement Types:

> Interconnection Security Agreement (ISA): Legal


review, regulatory compliance, Linking companies, partners, agencies, Vulnerability
scan results, Mandatory training/certification, Input from IT security
professionals
> Service Level Agreement (SLA): Contractual document
stating level of service, Guarantee service uptime, Consequences for not meeting
requirements
> Memorandum of Understanding (MOU): Broad terms of
agreement between parties
> Memorandum of Agreement (MOA): Detailed terms
between parties
> Business Partnership Agreement (BPA): Legal
document, Responsibilities, investment, decision-making
> Non-disclosure Agreement (NDA): Prevent sensitive
data disclosure to third parties

You might also like