0% found this document useful (0 votes)
15 views18 pages

Final Coursework Complete

COMP1843 Principle of Security Coursework
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
15 views18 pages

Final Coursework Complete

COMP1843 Principle of Security Coursework
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

COURSEWORK

COMP1843 – Principles of Cyber Security

Student name: Dao Manh Kien


Student ID: GCH230235
Assessor: Mr. Michael Omar
Table of contents:
1. Risk Assessment report for Digi………………………………………………………………….4
I. Business Overview and Expansion……………………………………………………4
II. Technology and Security Challenges…………………………………………………4
III. Vulnerabilities of a Start-Ups…………………………………………………………….4
IV. Legal, Compliance, and Ethical Issues……………………………………………….5
V. Organizational Structure and Productivity………………………………………..5
VI. Risk Analysis and Mitigation Strategies…………………………………………….5
VII. Consultancy Services Requirement…………………………………………………..6
2. Management Summary……………………………………………………………………………..6
3. Risk identification………………………………………………………………………………………8
I. Identify, Inventory, and Category Assets…………………………………………..8
II. Classify, Value, and Prioritize Assets…………………………………………………8
III. Assumptions…………………………………………………………………………………….9
IV. Identify, and Prioritize Threats………………………………………………………….9
V. Specify Asset and Vulnerabilities…………………………………………………….10
4. Risk management……………………………………………………………………………………..11
I. Asset Identification and Classification…………………………………………….11
II. Weighted Factor Analysis Technique……………………………………………….12
III. Risk register……………………………………………………………………………………12
IV. Calculate Risk…………………………………………………………………………………14
V. Critique of the Risk Probabilities…………………………………………………….14
5. Risk Control Strategies……………………………………………………………………………..14
6. Conclusion………………………………………………………………………………………………..16
References………………………………………………………………………………………………..17
List of table:
Table 1: Asset Identification and Classification Table
Table 2: Risk management table
Table 3: Risk register table
1. Risk Assessment Report for DiGi
I. Business Overview and Expansion
DiGi is a tech firm specializing in interactive software and application development,
creating bespoke solutions compatible with both Android and Apple interfaces. This
cross-platform adaptability expands their customer base, including SMEs and large
smart device manufacturers. Recent financial growth includes a significant
investment of £8 million, earmarked for scaling operations, expanding customer
acquisition efforts, and enhancing product portfolios. Corporations view
establishing CVC subsidiaries as an effective way to conduct research and
development (R&D) activities externally and to expose their management to new
technologies and an entrepreneurial way of thinking (R. Chemmanur and E.
Loutskina, 2014). This investment positions DiGi for market share growth and
operational optimization.

II. Technology and Security Challenges


"Cloud computing’s ability to add or remove resources at a fine grain (one server
at a time with EC2) and with a lead time of minutes rather than weeks allows
matching resources to workload much more closely" (Armbrust, M., Fox, A.,
Griffith, 2010). As DiGi expands, concerns about the scalability of its current
systems arise. Increased user traffic and data volumes may strain existing
infrastructure, necessitating upgrades to maintain performance and availability.
Security threats are also escalating, with risks from generative AI, stealth viruses,
phishing, and spam posing significant dangers. DiGi must strengthen its
cybersecurity measures to protect systems, data, and users from potential attacks.

III. Vulnerabilities of Start

DiGi’s rapid growth and online operations expose it to heightened vulnerabilities,


including inadequate data encryption, server capacity limitations, and insufficient
access controls. These weaknesses increase the risk of unauthorized access and
data breaches, making it critical for DiGi to implement robust security measures to
protect its operations and maintain client trust.

IV. Legal, Compliance, and Ethical Issues

DiGi’s fast-paced growth has outstripped its competencies in compliance, legal


matters, and ethics, posing a threat to its competitive edge. The company must
adhere to existing laws, manage legal issues like copyrights and patents, and foster
an ethical organizational culture to prevent legal consequences and sustain its
reputation. Data protection, particularly under GDPR, and safeguarding intellectual
property are also crucial for maintaining DiGi’s market position. “The GDPR aims
to meet the current challenges related to personal data protection, strengthen online
privacy rights, and boost Europe's digital economy" (Tikkinen-Piri, C., Rohunen, A.,
& Markkula, J., 2018)

V. Organizational Structure and Productivity

DiGi’s flat organizational structure, with 74 employees across various roles, fosters
cooperation but creates role confusion, impacting productivity and data
management. Clear role definitions are essential to enhance operational efficiency
and align resources with the company’s growth objectives. Formalizing roles and
responsibilities will help DiGi streamline processes and improve communication
within the organization.
Role clarity is essential for DiGi to improve its operational efficiency and increase
productivity. "Formalization, which reflects how well roles are defined within an
organization such as those related to communications and procedures" (Siddiqui,
A. 2022). When roles are clearly outlined, DiGi has the potential to enhance the
practices of data handling in the database. It also helps to improve productivity
because it removes unnecessary layers of complexity, allowing employees to
concentrate on their work and communicate better with each other.
VI. Risk Analysis and Mitigation Strategies

"The first step in creating an effective risk-management system is to understand the


qualitative distinctions among the types of risks that organizations face" (Kaplan, R.
S., & Mikes, A. 2012). After identification, each risk is evaluated to determine the
likelihood and the degree of its impact on DiGi Company’s operations, reputation,
and profitability. Thereafter, it develops contingency measures that are geared
towards minimizing or eradicating the aforementioned risks. DiGi conducts
comprehensive risk assessments to identify potential threats and develop
mitigation strategies. "Mitigation is defined as one of the risk response options,
which mission is to reduce probability and/or impact through active measures"
(Kivisaari, H. 2019). Short-term tactics include enhancing data protection and
server availability, while long-term strategies focus on sustainability, such as regular
security audits and compliance training. These measures ensure DiGi can effectively
manage risks and create a secure, compliant organization.

VII. Consultancy Services Requirement

DiGi seeks consultancy services to address its business strategy and risk
management needs. Consultants will identify current and future risks, assess their
impact on DiGi’s operations and reputation, and recommend tailored risk
management strategies. This professional advice will help DiGi overcome growth
challenges and achieve its strategic goals.

2. Management Summary
In today’s rapidly evolving technological landscape, businesses like DiGi, a
burgeoning tech start-up, face an increasingly complex array of risks that could
significantly impact their operations and long-term viability. This risk assessment
report aims to systematically identify, analyze, and mitigate these risks by examining
DiGi’s key assets, evaluating external and internal threats, and proposing effective
risk control strategies.
The first step in the risk assessment process involves the identification and
categorization of DiGi's assets, including its intellectual property, customer data,
software products, and IT infrastructure. These assets are then classified based on
their value and prioritized according to their importance to the company’s business
continuity and overall security. The report also outlines the assumptions made
during the risk assessment process, which include the scope of the assessment and
the external and internal factors that could influence DiGi’s operations.

The subsequent sections delve into the identification and prioritization of external
threats such as cyber-attacks, phishing, and industry competition. These threats are
evaluated based on their likelihood and potential impact on DiGi’s assets. Internal
vulnerabilities within DiGi's processes and systems are also identified and examined
to determine how they could be exploited by these external threats.
To manage these risks effectively, the report utilizes the weighted factor analysis
technique, which helps in determining the relative importance of each asset by
assigning weights to various risk factors. A risks register is then created to document
the identified risks, their probabilities, potential impacts, and the assets they
threaten. This information is used to calculate the overall risk score for each threat,
which serves as the basis for selecting appropriate control strategies.
The final section of the report proposes a range of control strategies designed to
mitigate the identified risks. These strategies are justified based on their
effectiveness in reducing the likelihood and impact of threats while aligning with
DiGi’s business objectives and resources. The report also provides a plan for
implementing, monitoring, and assessing these controls to ensure their ongoing
effectiveness.

3. Risk Identification
I. Identify, Inventory, and Categorize Assets
DiGi’s business model relies heavily on a variety of critical assets that support its
operations and competitive advantage. “Asset identification involves recognizing
assets, such as hardware, software, data, and people, that are critical to the
organization’s operations and security posture” (Piya Shedden, Atif Ahmad, 2016).
These assets include intellectual property, such as proprietary software algorithms
and patents, which form the core of DiGi’s product offerings. Customer data is
another vital asset, encompassing sensitive personal information and purchasing
history that enables DiGi to tailor its services and marketing efforts. Additionally,
the company’s software products and IT infrastructure, including servers,
databases, and networking equipment, are essential for maintaining seamless
operations and ensuring customer satisfaction.

To safeguard these assets, it is imperative to categorize them based on their


importance to DiGi’s business. Intellectual property, for example, is a high-value
asset that requires robust protection to prevent unauthorized use or theft. Similarly,
customer data is classified as a critical asset due to the potential legal and
reputational repercussions of a data breach. Software products and IT
infrastructure are categorized as essential operational assets, as any disruption to
these systems could lead to significant downtime and loss of revenue.

II. Classify, Value, and Prioritize Assets


After identifying and categorizing DiGi’s key assets, the next step is to classify them
based on their value to the company. This involves assessing both the tangible and
intangible benefits that each asset provides. Intellectual property, for instance, is
not only valuable in terms of its potential revenue generation but also as a key
differentiator in the competitive tech market. Customer data, on the other hand, is
valuable for its role in driving customer engagement and personalization strategies.

The prioritization of assets is guided by their value and the potential impact of their
loss or compromise. High-value assets, such as intellectual property and customer
data, are prioritized for protection due to their critical role in DiGi’s business model.
Operational assets, such as software products and IT infrastructure, are also
prioritized to ensure that DiGi can maintain continuous service delivery and
operational efficiency.

III. Assumptions
In conducting this risk assessment, several assumptions were made to define the
scope and context of the analysis. First, it is assumed that DiGi’s business
environment is dynamic, with ongoing technological advancements and evolving
cybersecurity threats. This assumption necessitates a forward-looking approach to
risk management that considers potential future risks as well as current ones.

Another assumption is that DiGi’s internal processes and systems are subject to
continuous improvement and that any identified vulnerabilities can be addressed
through targeted interventions. The assessment also assumes that external factors,
such as industry regulations and market competition, will continue to influence
DiGi’s risk landscape. These assumptions provide a framework for evaluating the
relevance and applicability of the identified risks and proposed control strategies.

IV. Identify, and Prioritize Threats (External)


The rapidly changing technological environment presents several external threats
that could adversely affect DiGi. One of the most significant threats is the increasing
prevalence of cyber-attacks, which target companies’ digital assets to steal sensitive
information, disrupt operations, or demand ransoms. Phishing attacks, in particular,
pose a high risk to DiGi as they exploit human vulnerabilities and can lead to
unauthorized access to critical systems and data.

Industry competition is another external threat that DiGi must contend with,
particularly in the highly competitive tech sector. Competitors may engage in
aggressive strategies to gain market share, such as poaching key personnel,
undercutting prices, or launching similar products. These actions can undermine
DiGi’s market position and erode its customer base.

To effectively manage these external threats, they must be prioritized based on


their likelihood and potential impact. Cyber-attacks, given their frequency and
potential for significant damage, are prioritized as a top threat. Industry
competition, while also important, is ranked lower due to its more predictable and
manageable nature.

V. Specify Asset Vulnerabilities (Internal)


Internally, DiGi faces several vulnerabilities that could be exploited by external
threats. One of the most critical vulnerabilities is the potential for human error,
which can occur in various forms, such as weak password practices, inadequate
training on cybersecurity protocols, or lapses in data handling procedures. These
vulnerabilities can be exploited by cyber-attackers to gain unauthorized access to
DiGi’s systems and data.

Another internal vulnerability lies in DiGi’s IT infrastructure, particularly if it lacks


redundancy or fails to keep pace with the latest security updates and patches.
Outdated software, unpatched systems, and poorly configured networks can create
entry points for attackers and increase the risk of a successful breach. Additionally,
DiGi’s reliance on third-party vendors for certain services introduces supply chain
risks, as these vendors may have their own vulnerabilities that could be leveraged
to target DiGi.

4. Risk Management
I. Asset Identification and Classification
Building on the initial identification and categorization of assets, this section
provides a more detailed classification, focusing on the role of each asset within
DiGi’s overall business strategy. Intellectual property, for instance, is not only a
valuable asset but also a strategic tool that DiGi uses to maintain its competitive
edge and drive innovation. Customer data, while important for operational
purposes, is also a key resource for strategic decision-making, enabling DiGi to
identify market trends and customer preferences.

By classifying assets according to their strategic importance, DiGi can better align
its risk management efforts with its long-term business goals. This approach
ensures that resources are allocated to protect the assets that are most critical to
DiGi’s success.

Asset Name Asset Type Value


Critically Classification Owner
Customer Information High
Critical Confidential IT
Database Department
Financial Information High Critical Confidential Finance
Records Team
Website ServerHardware/ Medium High Public IT
Technology Department
Employee Hardware Medium Medium Internet Use IT
Workstations Department
Company Email Software/ High Critical Confidential IT
System Technology Department
Customer Information High High Confidential Customer
Service Data Support
Payment Software/ High Critical Confidential Finance
Gateway Technology Team
Table 1: Asset Identification and Classification Table

II. Weighted Factor Analysis Technique


To evaluate the identified assets, the weighted factor analysis technique is
employed. This technique involves assigning weights to various risk factors, such as
the asset’s value, the likelihood of a threat materializing, and the potential impact
of a successful attack. By calculating a weighted score for each asset, DiGi can
determine which assets are most at risk and prioritize them for protection.
For example, intellectual property may receive a high weight due to its critical role
in DiGi’s business model and the significant damage that could result from its theft
or compromise. Customer data may also be weighted heavily, given the legal and
reputational consequences of a data breach. By contrast, less critical assets, such as
office equipment, may receive lower weights, reflecting their lesser importance to
the company’s overall risk profile.

Asset Value Vulnerability Threat Potential Weighted


Level Likelihood Impact Score
Customer data High High Moderate Severe 4.5
Intellectual High Moderate Low High 3.5
property
Operational Moderate High Moderate High 4.0
Data
Server High High High Severe 5.0
infrastructure
Employee Moderate Moderate Moderate Moderate 3.0
Information
Table 2: Risk management table

III. Risks Register


A risks register is a crucial tool for documenting and managing the risks identified
during the assessment process. This register lists each risk, along with its
probability, potential impact, and the assets it threatens. For DiGi, the risks register
serves as a central repository of information that can be used to track and monitor
risks over time.

The risks register also provides a basis for prioritizing risk management efforts, as it
allows DiGi to focus on the risks that pose the greatest threat to its critical assets.
By regularly updating the register, DiGi can ensure that it remains responsive to
emerging risks and can take proactive measures to mitigate them.
Risk Risk Description Asset Impact Likelihood Risk level
ID
1 Unauthorized access to customer Customer High Medium High
database database
2 Data breach via phishing attack Company High Medium High
Email System
3 Server downtime due to DDoS Website High Low Medium
attack Server
4 Loss of financial data due to Financial High Low Medium
hardware failure records
5 Malware infection on employee Employee Medium Medium Medium
workstations Workstations
6 Unauthorized transactions through Payment High Low Medium
payment gateway Gateway
7 Customer service data Customer High Medium High
compromised through social Service data
engineering
Table 3: Risk register table

IV. Calculate Risk


Using the information documented in the risks register, the overall risk score for
each identified threat is calculated. This score is derived from a combination of
factors, including the likelihood of the threat occurring and the severity of its impact
on DiGi’s assets. The risk score provides a quantitative measure of the risk level
associated with each threat, which can be used to guide decision-making and
resource allocation.

For example, a high-risk score may indicate a threat that requires immediate
attention and the implementation of robust control measures. A lower risk score
may suggest a threat that can be managed through routine monitoring and
maintenance activities. By calculating and analyzing these risk scores, DiGi can
prioritize its risk management efforts and ensure that its resources are deployed
effectively.
V. Critique of the Risk Probabilities
While the calculated risk probabilities provide a useful framework for managing
risk, it is important to critically evaluate the assumptions and methodologies used
in their calculation. This critique involves examining the underlying data,
considering potential biases, and assessing the relevance of the identified risks to
DiGi’s specific business context.

For instance, if the risk probabilities are based on industry averages, they may not
fully capture the unique risks that DiGi faces as a start-up. Additionally, the rapidly
changing nature of the tech industry may render some risk estimates outdated,
necessitating ongoing review and adjustment. By critiquing the risk probabilities,
DiGi can ensure that its risk management strategies are both accurate and
adaptable to changing circumstances.

5. Risk Control Strategies


Avoidance:
To eliminate or reduce uncontrolled risks, DiGi can implement several control
measures. These include creating and enforcing robust policies, investing in Security
Education, Training, and Awareness (SETA) programs, and deploying advanced
technologies that protect the organization’s assets. By establishing strict access
controls, enforcing password policies, and regularly updating software to patch
vulnerabilities, DiGi can avoid many security risks. Additionally, the company can
limit its exposure to threats by segmenting its network, ensuring that sensitive data
is isolated from less secure areas.

Transference:
DiGi can manage risks by shifting them to other areas or external entities. This can
be achieved through outsourcing certain high-risk operations to specialized service
providers with stronger security frameworks. For instance, DiGi might choose to
outsource its data storage to a cloud provider with robust security certifications,
thereby transferring the risk associated with data breaches. Additionally, DiGi can
obtain insurance to cover potential financial losses from specific risks, such as
cyber-attacks or data breaches. This approach ensures that while the risk remains,
the impact on DiGi is minimized.

Mitigation:
"Mitigation involves taking measures to reduce the likelihood or impact of risks,
such as adding buffers to schedules or performing additional testing" (Bernie
Roseke, [Link]., 2015). DiGi should develop comprehensive plans, including a
Disaster Recovery Plan (DRP), Incident Response Plan (IRP), and Business Continuity
Plan (BCP). These plans will ensure that in the event of a disaster or security breach,
DiGi can quickly recover operations, minimize downtime, and maintain essential
services. Regular testing and updating of these plans are crucial to ensure their
effectiveness in real-world scenarios. By preparing in advance, DiGi can significantly
reduce the damage caused by unforeseen events.

Acceptance:
In some cases, DiGi may decide to accept certain risks, understanding their
consequences and integrating them into the broader risk management strategy.
This approach is suitable when the cost of mitigation or avoidance outweighs the
potential impact of the risk. For example, DiGi might accept the risk of minor
operational disruptions that do not critically impact its core business functions. By
acknowledging these risks and monitoring them closely, DiGi can manage them
effectively without expending unnecessary resources on mitigation.
6. Conclusion
In conclusion, this risk assessment report provides a comprehensive analysis of the
risks facing DiGi, along with actionable recommendations for mitigating those risks.
By identifying and prioritizing DiGi’s key assets, evaluating external and internal
threats, and proposing targeted control strategies, the report offers a clear
roadmap for enhancing DiGi’s security posture and ensuring its long-term success.
The implementation of these strategies, coupled with ongoing monitoring and
assessment, will enable DiGi to effectively manage its risks and capitalize on
opportunities in the competitive tech industry. As DiGi continues to grow and
evolve, it is crucial that the company remains vigilant and adaptable, continuously
refining its risk management practices to address new challenges and protect its
valuable assets.
References:
1. R. Chemmanur and E. Loutskina, "Corporate Venture Capital, Value
Creation, and Innovation," Review of Financial Studies, vol. 28, no. 10, pp.
3576-3607, 2015. DOI: 10.1093/rfs/hhv051.
[Link]
2. Armbrust, M., Fox, A., Griffith, R., Joseph, A. D., Katz, R., Konwinski, A., Lee,
G., Patterson, D., Rabkin, A., Stoica, I., & Zaharia, M. (2010). A view of cloud
computing. Communications of the ACM, 53(4), 50-58. DOI:
10.1145/1721654.1721672.
[Link]
3. Tikkinen-Piri, C., Rohunen, A., & Markkula, J. (2018). EU General Data
Protection Regulation: Changes and implications for personal data collecting
companies. Computer Law & Security Review, 34(1), 134-153. DOI:
10.1016/[Link].2017.05.015.
[Link]
6
4. Siddiqui, A. (2022). The Impact of Organizational Structure on Firm
Performance: A Systematic Literature Review. University of Barcelona.
[Link]
INTBUS_Siddiqui_2022.pdf
5. Kaplan, R. S., & Mikes, A. (2012). Managing Risks: A New
Framework. Harvard Business [Link] Risks: A New Framework
([Link])
6. Kivisaari, H. (2019). Risk Mitigation in Project Management: Case Horizon
2020. TheseusKivisaari_Hanna.pdf ([Link])
7. • Shedden, P., Ahmad, A., Smith, W., Tscherning, H., & Scheepers, R.
(2016). Asset Identification in Information Security Risk Assessment: A
Business Practice Approach. Communications of the Association for
Information Systems, 39, 15.
8. • Kaplan, R. S., & Mikes, A. (2012). Managing Risks: A New Framework.
Harvard Business Review, 90(6).
9. Bernie Roseke, [Link]., PMP (2015). Five Risk Response Strategies.
Project Engineer. [Link]
strategies/

You might also like