0% found this document useful (0 votes)
28 views25 pages

Cybersecurity Risk Assessment Guide

The document outlines a cybersecurity risk assessment for New Age Bank, detailing the identification, analysis, and evaluation of potential security risks to its information systems. It includes specific risk scenarios for selected assets such as the bank's website, customer data, and payroll system, along with threats, vulnerabilities, likelihood, impact, and risk levels. Additionally, it proposes risk mitigation strategies and justifications for selected cybersecurity controls to enhance the bank's security posture.

Uploaded by

Mihret Habte
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
28 views25 pages

Cybersecurity Risk Assessment Guide

The document outlines a cybersecurity risk assessment for New Age Bank, detailing the identification, analysis, and evaluation of potential security risks to its information systems. It includes specific risk scenarios for selected assets such as the bank's website, customer data, and payroll system, along with threats, vulnerabilities, likelihood, impact, and risk levels. Additionally, it proposes risk mitigation strategies and justifications for selected cybersecurity controls to enhance the bank's security posture.

Uploaded by

Mihret Habte
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

CYBER SECURITY ASSIGNMENT

NAME: MIHRET HABTE


STUDENT ID: UGR/2619/14
SECTION: 2

SUMITTED TO: SENAIT DESALEGN


Introduction

Cyber security risk assessment is a systematic process of identifying, analyzing, and evaluating potential security risks to an
organization's information systems and assets. This critical process helps organizations understand their security posture and make
informed decisions about resource allocation for protecting their digital infrastructure.
Risk scenarios represent specific situations where security breaches could occur. These scenarios emerge from the interaction
between threats (potential sources of harm) and vulnerabilities (weaknesses that can be exploited). For example, a risk scenario
might involve a malicious actor exploiting an unpatched software vulnerability to gain unauthorized access to sensitive customer
data.
Threats can be both internal and external, ranging from sophisticated cyber criminals and state-sponsored actors to disgruntled
employees and human error. Vulnerabilities encompass technical weaknesses like outdated software, misconfigured systems, and
weak passwords, as well as organizational weaknesses such as inadequate security training or poor access control policies.
The assessment of risk involves analyzing both likelihood (the probability of a threat exploiting a vulnerability) and impact (the
potential consequences of a security breach). These factors combine to determine the overall risk level, which helps prioritize
security efforts. For instance, a vulnerability that's easily exploitable and could lead to significant financial loss would be classified as
high-risk.
Risk mitigation strategies are comprehensive approaches to reduce identified risks to acceptable levels. These strategies typically
involve implementing various cybersecurity controls, which can be technical (like encryption and firewalls), administrative (such as
policies and procedures), or physical (including secure facilities and hardware protection).
The selection of specific security controls must be justified based on their effectiveness, cost-efficiency, and alignment with
organizational objectives. This justification should demonstrate how each control addresses specific risks while considering the
organization's resource constraints and operational requirements.
Regular reassessment of these elements ensures that security measures remain effective as threats evolve and new vulnerabilities
emerge in the ever-changing cyber security landscape.
CASE STUDY

The New Age Bank Cybersecurity Risk Assessment and Mitigation Scenario

The New Age Bank is one of the pioneer banks in the Ethiopian banking industry. The bank provides a full-fledged payment card
service, mobile banking, internet banking, and online banking on top of the branch based services.

The New Age Bank is highly reliable on information systems to provide its services. It is a pioneer to adopt cutting edge technologies
in the banking industry. It recently has adopted an intelligent banking system, AI enabled banking system, which can provide diverse
services for customers.

Its reliance on information systems and cutting edge technologies is highly increasing the reputation of the bank and its profit.
Unfortunately, it is also become attractive for cybercriminals and the bank is getting thousands of cyber-attack attempts daily.
Therefore, the senior management of the bank has decided to cybersecurity risk assessment based on NIST-SP 800-30 standard. The
senior management has decided to conduct this task by dividing the task for different groups of professionals considering the broad
assets of the bank and the time required. You are among the selected cybersecurity professionals who will conduct this critical
initiative.

The bank has identified selected departments and assets which should be considered in the first phase. The asset inventory which
constitute the assets that are in the scope of the first phase are provided to you and your team members. The asset inventory consists
different assets under six categories.

Tasks:
1. Review the attached asset inventory and select three to five assets, based on the number of your group members. The assets should
be selected from different categories.

2. Conduct a cybersecurity risk assessment for the selected assets

a. Develop a risk scenario for each asset. You should put at least two scenarios for each asset.

b. Identify the threats and the vulnerabilities.


c. Analyze the likelihood and the impact, and determine the risk level

3. Put risk mitigation strategies for each risk you identified.


4. Identify the applicable cyber security controls required to mitigate the identified risks and put justification for your selection.
.

1. Information Assets

Asset Group Asset Asset Owner /Department Location Value Security


Number access

Website D1 Website IT Services Mgt Web Server H Unrestricted


Department

Emails D2 Emails (Webmail) Various Email Server M Private


Owners/Various
Departments

D3 Emails (Archive) Various Server M Private


Owners/Various
Departments

Customer data D12 Customer data Various Server


Owners/Various
Departments

SAGE Payroll D6 SAGE Payroll Finance Department Public File Server H Restricted
System & Data System & Data
Personnel Data D7 Personnel Data HR Department Public File Server H Restricted

Public Server D5 Compliance CEO (Various users Public File Server & H Restricted
Based Documents have access) Backup Drive
Documents
including Licences
& Certification

D8 Sales & Suppliers Marketing Department Public File Server H Restricted


Documentation

D9 Quality System CEO Public File Server M Restricted


(ISO Documents)

D10 Accounts Finance Department Public File Server H Restricted


Documentation –
Company accounts,
Inland Revenue,
V.A.T.

D14 Job Quotations HR Department Public File Server M Confidential


Selected Assets:

 Asset 1: Website (D1)


 Asset 2: Customer Data (D12)
 Asset 3: SAGE Payroll System & Data (D6)
Risk Assessment for Each Asset
Asset 1: Website (D1)

 a. Risk Scenarios:

o Scenario 1: Website Defacement: An attacker gains unauthorized access and changes the content of the website, damaging the
organization's reputation.
o Scenario 2: Denial of Service (DoS) Attack: An attacker floods the website with traffic, making it unavailable to legitimate users.
 b. Threats and Vulnerabilities:

o Threats: Hackers, malicious bots, disgruntled employees.


o Vulnerabilities: Unpatched software vulnerabilities (e.g., in the web server or content management system), weak passwords,
SQL injection vulnerabilities, cross-site scripting (XSS) vulnerabilities, lack of proper input validation.
 c. Likelihood, Impact, and Risk Level:

o Scenario 1 (Defacement):
 Likelihood: Medium (depending on the security of the website)
 Impact: Medium (reputational damage, loss of customer trust)
 Risk Level: Medium
o Scenario 2 (DoS):
 Likelihood: Low to Medium (depending on the website's infrastructure and security measures)
 Impact: High (loss of business, customer frustration)
 Risk Level: Medium to High
 3. Risk Mitigation Strategies:

o Scenario 1 (Defacement):
 Regularly patch software vulnerabilities.
 Implement strong password policies and multi-factor authentication.
 Use a web application firewall (WAF) to protect against common web attacks.
 Implement input validation to prevent SQL injection and XSS attacks.
 Regularly monitor website logs for suspicious activity.
o Scenario 2 (DoS):
 Use a content delivery network (CDN) to distribute traffic and absorb attacks.
 Implement rate limiting to prevent excessive traffic from a single source.
 Use a DDoS mitigation service.
 Monitor network traffic for anomalies.
 4. Applicable Cyber security Controls and Justification:

o Technical Controls:
 Web Application Firewall (WAF): Protects against web-based attacks like SQL injection and XSS.
Justification: Directly addresses vulnerabilities that could lead to defacement.
 Intrusion Detection/Prevention System (IDS/IPS): Monitors network traffic for malicious activity and blocks or alerts on
suspicious behavior.
Justification: Helps detect and prevent both defacement and DoS attacks.
 Patch Management System: Ensures that all software is up-to-date with the latest security patches.
Justification: Reduces the attack surface by eliminating known vulnerabilities.
 DDoS Mitigation Service: Protects against denial-of-service attacks. Justification: Specifically addresses the DoS
risk.
o Administrative Controls:
 Security Awareness Training: Educates employees about security threats and best practices.
Justification: Reduces the risk of human error, such as weak passwords or clicking on malicious links.
 Incident Response Plan: Outlines the steps to be taken in the event of a security incident.
Justification: Ensures a coordinated and effective response to minimize damage.
Asset 2: Customer Data (D12)

 a. Risk Scenarios:

o Scenario 1: Data Breach: An attacker gains unauthorized access to the server and steals customer data (e.g., names, addresses,
credit card numbers).
o Scenario 2: Accidental Data Leakage: An employee accidentally exposes customer data (e.g., by sending an email to the wrong
recipient or misconfiguring a database).
 b. Threats and Vulnerabilities:
o Threats: Hackers, malicious insiders, negligent employees.
o Vulnerabilities: Weak access controls, unencrypted data, unpatched server vulnerabilities, SQL injection vulnerabilities, lack of
data loss prevention (DLP) measures, misconfigured databases.
 c. Likelihood, Impact, and Risk Level:

o Scenario 1 (Data Breach):


 Likelihood: Medium (depending on the security of the server and the data)
 Impact: High (financial loss, reputational damage, legal penalties)
 Risk Level: High
o Scenario 2 (Accidental Data Leakage):
 Likelihood: Medium (depending on employee training and data handling procedures)
 Impact: Medium to High (reputational damage, legal penalties)
 Risk Level: Medium to High
 3. Risk Mitigation Strategies:

o Scenario 1 (Data Breach):


 Implement strong access controls and multi-factor authentication.
 Encrypt sensitive data at rest and in transit.
 Regularly patch server vulnerabilities.
 Use a web application firewall (WAF) to protect against SQL injection attacks.
 Implement intrusion detection and prevention systems (IDS/IPS).
 Regularly monitor server logs for suspicious activity.
o Scenario 2 (Accidental Data Leakage):
 Implement data loss prevention (DLP) measures to prevent sensitive data from leaving the organization's control.
 Provide regular security awareness training to employees.
 Implement data handling procedures to ensure that employees handle sensitive data securely.
 Use email encryption to protect sensitive data in transit.
 4. Applicable Cyber security Controls and Justification:

o Technical Controls:
 Data Encryption (at rest and in transit): Protects data even if a breach occurs.
Justification: Reduces the impact of a data breach by rendering the stolen data unusable.
 Access Control Lists (ACLs) and Role-Based Access Control (RBAC): Limits access to customer data to only authorized
personnel.
Justification: Prevents unauthorized access and reduces the risk of both internal and external threats.
 Data Loss Prevention (DLP) System: Monitors and prevents sensitive data from leaving the organization's control.
Justification: Prevents accidental data leakage.
 Database Activity Monitoring (DAM): Monitors database activity for suspicious behavior.
Justification: Helps detect and prevent data breaches.
o Administrative Controls:
 Data Security Policy: Outlines the organization's policies for protecting customer data.
Justification: Provides a framework for data security and ensures that all employees are aware of their responsibilities.
 Employee Background Checks: Reduces the risk of hiring malicious insiders.
Justification: Helps prevent insider threats.
Asset 3: SAGE Payroll System & Data (D6)
a. Risk Scenarios:

o Scenario 1: Payroll Fraud: An attacker gains unauthorized access to the payroll system and manipulates employee salaries or
bank account details.
o Scenario 2: Data Breach: An attacker gains unauthorized access to the payroll system and steals employee personal and
financial information.
b. Threats and Vulnerabilities:

o Threats: Hackers, malicious insiders, disgruntled employees.


o Vulnerabilities: Weak access controls, unencrypted data, unpatched system vulnerabilities, SQL injection vulnerabilities, lack of
audit trails, inadequate segregation of duties.
c. Likelihood, Impact, and Risk Level:

o Scenario 1 (Payroll Fraud):


 Likelihood: Low to Medium (depending on the security of the system)
 Impact: High (financial loss, legal penalties, reputational damage)
 Risk Level: Medium to High
o Scenario 2 (Data Breach):
 Likelihood: Medium (depending on the security of the system and the data)
 Impact: High (financial loss, reputational damage, legal penalties)
 Risk Level: High
3. Risk Mitigation Strategies:

o Scenario 1 (Payroll Fraud):


 Implement strong access controls and multi-factor authentication.
 Implement segregation of duties to prevent a single person from having complete control over the payroll process.
 Implement audit trails to track all changes to the payroll system.
 Regularly review payroll data for anomalies.
o Scenario 2 (Data Breach):
 Encrypt sensitive data at rest and in transit.
 Regularly patch system vulnerabilities.
 Use a web application firewall (WAF) to protect against SQL injection attacks.
 Implement intrusion detection and prevention systems (IDS/IPS).
 Regularly monitor system logs for suspicious activity.
4. Applicable Cyber security Controls and Justification:

o Technical Controls:
 Multi-Factor Authentication (MFA): Requires users to provide multiple forms of authentication before accessing the
system.
Justification: Significantly reduces the risk of unauthorized access.
 Database Encryption: Encrypts the payroll database to protect sensitive data.
Justification: Reduces the impact of a data breach.
 Intrusion Detection/Prevention System (IDS/IPS): Monitors network traffic for malicious activity.
Justification: Helps detect and prevent both fraud and data breaches.
 Security Information and Event Management (SIEM) System: Collects and analyzes security logs from various sources to
identify suspicious activity.
Justification: Provides a centralized view of security events and helps detect anomalies.
o Administrative Controls:
 Segregation of Duties: Divides responsibilities among multiple employees to prevent a single person from having too
much control.
Justification: Reduces the risk of fraud.
 Regular Audits: Regularly audit the payroll system to identify vulnerabilities and ensure compliance with security
policies.
Justification: Helps identify and correct security weaknesses.
 Background Checks: Conduct thorough background checks on employees with access to the payroll system.
Justification: Reduces the risk of insider threats.

2. Service Assets

Asset Group Asset Asset Owner/Department Location Value Security


Number access

Power and E1 Fire Alarm System Company Secretary Head Office H Restricted
Safety Building

E2 Intruder Alarm System Company Secretary Head Office H Restricted


Building

E3 UPS Company Secretary DC M Restricted

E4 Air Conditioning Unit Company Secretary DC M Restricted

Kaspersky Anti-Virus IT Service Mgt Server H Restricted


Department

Emails (Webmail) IT Service Mgt Email Server M Private


Department (External)

X1 Acronis Backup & Recovery™ IT Infrastructure Server M Restricted


10 Advanced Server SBS Edition Department

X4 CIO External M Restricted

IT service enablers X1
X2

X3

ICT Support Contracts

The three critical assets from the table

 Fire Alarm System (E1)


 Kaspersky Anti-Virus
 UPS (E3)

1. FIRE ALARM SYSTEM (E1)


a. Risk Scenarios:

 Scenario 1: System Malfunction


o Fire alarm fails to trigger during an actual emergency
o False alarms causing unnecessary evacuations
 Scenario 2: Cyber Attack
o System compromise through network connectivity
o Malicious disabling of the system
b. Threats and Vulnerabilities:

 Threats:
o Power outages
o Cyber attacks
o Physical tampering
o System malfunction
 Vulnerabilities:
o Outdated firmware
o Network connectivity exposures
o Insufficient backup power
o Poor maintenance
c. Risk Level Analysis:

 Scenario 1 (System Malfunction)


o Likelihood: Medium
o Impact: High (potential loss of life/property)
o Risk Level: High
 Scenario 2 (Cyber Attack)
o Likelihood: Low
o Impact: High
o Risk Level: Medium
2. KASPERSKY ANTI-VIRUS
a. Risk Scenarios:

 Scenario 1: Protection Failure


o Failure to detect new malware
o Delayed virus signature updates
 Scenario 2: System Compromise
o Anti-virus software being disabled
o False positives affecting critical systems
b. Threats and Vulnerabilities:

 Threats:
o New malware variants
o Zero-day exploits
o Internal sabotage
o Update server issues
 Vulnerabilities:
o Outdated virus definitions
o Configuration errors
o Network connectivity issues
o Admin access misuse
c. Risk Level Analysis:

 Scenario 1 (Protection Failure)


o Likelihood: High
o Impact: High
o Risk Level: High
 Scenario 2 (System Compromise)
o Likelihood: Medium
o Impact: High
o Risk Level: High
3. UPS (E3)
a. Risk Scenarios:

 Scenario 1: Hardware Failure


o UPS fails during power outage
o Battery degradation
 Scenario 2: Maintenance Issues
o Improper maintenance leading to malfunction
o Overload situations
b. Threats and Vulnerabilities:

 Threats:
o Power surges
o Equipment failure
o Overheating
o Physical damage
 Vulnerabilities:
o Aging batteries
o Poor maintenance
o Inadequate cooling
o Overload capacity
c. Risk Level Analysis:

 Scenario 1 (Hardware Failure)


o Likelihood: Medium
o Impact: High
o Risk Level: High
 Scenario 2 (Maintenance Issues)
o Likelihood: Medium
o Impact: Medium
o Risk Level: Medium
RISK MITIGATION STRATEGIES:
Fire Alarm System:

o Regular system testing and maintenance


o Backup power supplies
o Network segmentation
o 24/7 monitoring
o Regular firmware updates
o Physical access controls
Kaspersky Anti-Virus:

o Automated update scheduling


o Regular license renewal monitoring
o Secondary anti-malware solutions
o User awareness training
o Regular system scans
o Configuration audits
UPS:

o Regular battery testing


o Preventive maintenance schedule
o Temperature monitoring
o Load testing
o Redundant systems
o Emergency response procedures
CYBERSECURITY CONTROLS:
Technical Controls:

 Access control systems


 Network monitoring
 Encryption
 Automated alerts
 Redundant systems
 Regular backups
Administrative Controls:

 Security policies
 Staff training
 Incident response plans
 Change management
 Regular audits
 Documentation
Physical Controls:

 Access restrictions
 Environmental monitoring
 Security cameras
 Backup power
 Fire suppression
 Physical locks
Justification for Controls:

 Addresses multiple risk scenarios


 Provides layered security
 Follows industry best practices
 Cost-effective protection
 Measurable effectiveness
 Supports compliance requirements
This assessment should be reviewed and updated:

 Quarterly for high-risk systems


 When new threats emerge
 After system changes
 Following security incidents
 During regular security reviews
 When new vulnerabilities are discovered

3. People Assets

Asset Group Asset Asset Owner/Department Location Value Security access


Number

Employees P1 Board BoD N/A H N/A


and
stakeholders members

P2 Executive CEO Head Office Buliding H N/A


Members
P3 Directors Chiefs Head Office Buliding H N/A

P4 Managers Directors Head Office Buliding H N/A

P5 Employees Respective managers Head Office Buliding H N/A


(staffs)

P6 IT staffs IT Manager Head Office Buliding H N/A

P7 Consultants Marketing Manager N/A M N/A

P8 Suppliers Marketing Manager N/A M N/A

The three critical assets from the table

 Board member(P1)

 It staff (P6)

 Consultant (P7)

1. BOARD MEMBERS (P1)


a. Risk Scenarios:

 Scenario 1: Social Engineering Attacks


o Targeted phishing attempts
o Impersonation attacks
 Scenario 2: Information Leakage
o Unauthorized sharing of sensitive information
o Lost or stolen devices containing confidential data
b. Threats and Vulnerabilities:

 Threats:
o Targeted cyber attacks
o Social engineering
o Physical threats
o Corporate espionage
 Vulnerabilities:
o High-profile positions
o Access to sensitive information
o Travel requirements
o Public exposure
c. Risk Level Analysis:

 Scenario 1 (Social Engineering)


o Likelihood: High
o Impact: High
o Risk Level: Critical
 Scenario 2 (Information Leakage)
o Likelihood: Medium
o Impact: High
o Risk Level: High
2. IT STAFFS (P6)
a. Risk Scenarios:

 Scenario 1: Insider Threats


o Misuse of privileged access
o Accidental system changes
 Scenario 2: Social Engineering
o Targeted attacks due to access levels
o Credential theft attempts
b. Threats and Vulnerabilities:

 Threats:
o Privileged access misuse
o Social engineering
o Burnout/stress
o External recruitment
 Vulnerabilities:
o High-level system access
o Access to multiple systems
o Knowledge of security measures
o Stress from critical responsibilities
c. Risk Level Analysis:

 Scenario 1 (Insider Threats)


o Likelihood: Medium
o Impact: High
o Risk Level: High
 Scenario 2 (Social Engineering)
o Likelihood: High
o Impact: High
o Risk Level: Critical
3. CONSULTANTS (P7)
a. Risk Scenarios:

 Scenario 1: Data Exposure


o Unauthorized data sharing
o Insecure handling of company information
 Scenario 2: Access Control Issues
o Excessive access rights
o Continued access after contract completion
b. Threats and Vulnerabilities:

 Threats:
o Data leakage
o Intellectual property theft
o Unauthorized access
o Competitive intelligence gathering
 Vulnerabilities:
o Temporary nature of engagement
o Limited organizational loyalty
o Variable security awareness
o Multiple client exposure
c. Risk Level Analysis:

 Scenario 1 (Data Exposure)


o Likelihood: Medium
o Impact: High
o Risk Level: High
 Scenario 2 (Access Control)
o Likelihood: High
o Impact: Medium
o Risk Level: High
RISK MITIGATION STRATEGIES:
Board Members:

o Executive security awareness training


o Secure communication channels
o Device encryption
o Travel security protocols
o Regular security briefings
o Incident response procedures
IT Staff:

o Privileged access management


o Regular security training
o Activity monitoring
o Stress management support
o Rotation of duties
o Clear security policies
Consultants:

o NDAs and security agreements


o Limited access controls
o Monitoring systems
o Regular access reviews
o Data loss prevention
o Off boarding procedures
CYBERSECURITY CONTROLS:
Technical Controls:

 Multi-factor authentication
 Access monitoring
 Encryption
 Mobile device management
 Data loss prevention
 Network segmentation
Administrative Controls:

 Security policies
 Background checks
 Training programs
 Confidentiality agreements
 Access review processes
 Incident response plans
Physical Controls:

 Access cards
 CCTV surveillance
 Clean desk policy
 Secure disposal
 Visitor management
 Physical security
Justification for Controls:
1. Addresses human-centric risks
2. Protects sensitive information
3. Maintains regulatory compliance
4. Reduces insider threats
5. Enables monitoring and audit
6. Supports incident response
This assessment should be reviewed:

 During organizational changes


 After security incidents
 When new threats emerge
 During policy updates
 For new role creation
 Following structural changes
4. Software Assets

Asset Group Asset Asset Owner/Department Location Value Security


Number access

Server A2 Microsoft Windows IT Infrastructure Server H Restricted


Operating 2022 (Server Edition) Department
Systems

Client Operating A3 Microsoft Windows 10 x IT Infrastructure Individual PC’s & H Restricted


Systems 120 items Department Laptops (Office
Network)

Application A4 T24 core banking system IT Infrastructure Server H Restricted


Department
software
A5 Internet banking system IT Infrastructure Server H Restricted
Department

A6 Mobile banking system IT Infrastructure Server H Restricted


Department

A7 Microsoft Office 360 IT Infrastructure Individual PC’s & M Private


Department Laptops (Office
Network)

A8 SAGE – Accounts 2011 Finance Department Server M Restricted

A9 SAGE – Payroll 2008 Finance Department Server M Restricted

A10 Acronis Backup & IT Service Mgt Server M Restricted


Recovery™ 10 Department
Advanced Server SBS
Edition

Avast Anti- A11 Kaspersky Anti-Virus IT Service Mgt Server H Restricted


Virus Department

Selected asset number

 A2 (Windows Server 2022)


 A5 (Internet Banking System)
 A8 (SAGE - Accounts 2011)

1. ASSET A2 - Windows Server 2022


Risk Scenarios:
1. Unauthorized Access Scenario
 Threat: Malicious actors gain privileged access to the server
 Vulnerability: Weak authentication mechanisms, unpatched security vulnerabilities
 Likelihood: Medium (servers are common targets)
 Impact: High (complete system compromise possible)
 Risk Level: High
2. Service Disruption Scenario
 Threat: DDoS attacks or system failure
 Vulnerability: Network exposure, resource limitations
 Likelihood: Medium
 Impact: High (affects all dependent services)
 Risk Level: High
Mitigation Strategies:
 Implement multi-factor authentication
 Regular security patching
 Network segmentation
 DDoS protection
 Regular system backups
Controls:

 Access Control (AC-2, AC-4): Implement role-based access control and network segmentation
 System and Information Integrity (SI-2): Automated patch management
 System and Communications Protection (SC-5): DDoS protection
Justification: These controls address the primary vectors of attack while maintaining system availability.
2. ASSET A5 - Internet Banking System
Risk Scenarios:
1. Data Breach Scenario
 Threat: Unauthorized access to customer financial data
 Vulnerability: SQL injection, insecure APIs
 Likelihood: High (financial systems are prime targets)
 Impact: High (financial and reputational damage)
 Risk Level: Critical
2. Transaction Manipulation Scenario
 Threat: Fraudulent transactions
 Vulnerability: Insufficient transaction validation
 Likelihood: Medium
 Impact: High (direct financial loss)
 Risk Level: High
Mitigation Strategies:

 Regular security testing and code reviews


 Encryption of data in transit and at rest
 Strong input validation
 Transaction monitoring systems
 Multi-layer authentication
Controls:

 Identification and Authentication (IA-2, IA-5): Strong authentication mechanisms


 System and Communications Protection (SC-8, SC-13): Encryption
 Audit and Accountability (AU-2, AU-6): Transaction monitoring
Justification: Financial systems require the highest level of security due to direct monetary risks.
3. ASSET A8 - SAGE Accounts 2011
Risk Scenarios:
1. Legacy System Vulnerability Scenario
 Threat: Exploitation of unpatched vulnerabilities
 Vulnerability: Outdated software version
 Likelihood: High (older systems have known vulnerabilities)
 Impact: High (financial data compromise)
 Risk Level: Critical
2. Data Integrity Scenario
 Threat: Corruption of financial records
 Vulnerability: Lack of modern data validation
 Likelihood: Medium
 Impact: High (financial reporting issues)
 Risk Level: High
Mitigation Strategies:

 System upgrade or replacement


 Implementation of additional security layers
 Regular data backups
 Access restrictions
 Monitoring and logging
Controls:
 Configuration Management (CM-2, CM-6): Version control and secure configurations
 System and Information Integrity (SI-7): Data integrity checking
 Contingency Planning (CP-9): System backups
Justification: Legacy systems require additional protective measures due to inherent vulnerabilities.
General Control Recommendations:
1. Technical Controls:
 Network segmentation
 Encryption
 Access control systems
 Monitoring tools
 Backup systems
2. Administrative Controls:
 Security policies
 Regular audits
 Staff training
 Incident response procedures
 Change management
3. Physical Controls:
 Secure server rooms
 Environmental controls
 Access logging
 CCTV monitoring
 Biometric access
The implementation priority should be based on:
1. Risk level (Critical first)
2. Implementation cost
3. Resource availability
4. Operational impact

5. Physical and Hardware Assets

Category Asset Asset Owner/Department Location Value Security


Number access

IT support S1 Data Center & CIO Head Office Building H Restricted


infrastructur Fixtures
e
S2 Door Access System IT Infrastructure Department Head Office Building H Restricted

S3 LAN IT Infrastructure Department Head Office M Restricted


Buildings

S4 Broadband Connection IT Infrastructure Department Head Office Building H Restricted

S5 Monitored Intruder IT Infrastructure Department Head Office Building M Restricted


Alarm

S6 Lockable filing CEO Secretary Head Office Building H Restricted


cabinets (CEO
Office, Chiefs’
Office)

IT hardware H1 DELL PowerEdge IT Infrastructure Department DC H Restricted


R750XA

H2 24 – Port IT Infrastructure Department DC M Restricted


PowerConnect 2124-
2508 Switch
H3 Dell 230 MT IT Infrastructure Department CEO Office, Chiefs’ M Restricted
Workstation & 19 Office
Inch TFT Monitor x
17

H4 Dell Vostro IT Infrastructure Department 1 – CIO Office 1 – M Restricted


Notebook V3500 x CEO Office
2

H5 Mitel VOIP IT Infrastructure Department DC M Restricted


Telephone Server

H6 PC & 19 Inch TFT IT Infrastructure Department CEO Office M Restricted


Monitor – Non
Networked

Building H7 Building CEO Addis Ababa H Restricted

Selected assets number for risk assessment:


 Data Center & Fixtures (S1)
 Door Access System (S2)
 DELL PowerEdge R750XA Server (H1)

1. DATA CENTER & FIXTURES (S1)


a. Risk Scenarios:

 Scenario 1: Physical Infrastructure Failure


o Power outage
o Cooling system failure
o Fire/water damage
 Scenario 2: Security Breach
o Unauthorized physical access
o Sabotage
o Theft of equipment
b. Threats and Vulnerabilities:

 Threats:
o Natural disasters
o Power failures
o Physical intrusion
o Environmental issues
 Vulnerabilities:
o Single point of failure
o Physical access controls
o Environmental controls
o Backup systems
c. Risk Level Analysis:

 Scenario 1 (Infrastructure Failure)


o Likelihood: Medium
o Impact: Critical
o Risk Level: High
 Scenario 2 (Security Breach)
o Likelihood: Low
o Impact: Critical
o Risk Level: High
2. DOOR ACCESS SYSTEM (S2)
a. Risk Scenarios:
 Scenario 1: System Failure
o Access control malfunction
o Database corruption
o Power failure
 Scenario 2: Security Compromise
o Unauthorized access
o Credential theft
o System tampering
b. Threats and Vulnerabilities:

 Threats:
o Power outages
o System hacking
o Social engineering
o Hardware failure
 Vulnerabilities:
o Network connectivity
o Backup power
o Access card cloning
o System maintenance
c. Risk Level Analysis:

 Scenario 1 (System Failure)


o Likelihood: Medium
o Impact: High
o Risk Level: High
 Scenario 2 (Security Compromise)
o Likelihood: Medium
o Impact: High
o Risk Level: High
3. DELL PowerEdge R750XA (H1)
a. Risk Scenarios:

 Scenario 1: Hardware Failure


o Component failure
o System crash
o Data corruption
 Scenario 2: Security Compromise
o Unauthorized access
o Malware infection
o Data breach
b. Threats and Vulnerabilities:

 Threats:
o Hardware malfunction
o Cyber attacks
o Power issues
o Configuration errors
 Vulnerabilities:
o System access
o Patch management
o Backup procedures
o Configuration settings
c. Risk Level Analysis:

 Scenario 1 (Hardware Failure)


o Likelihood: Medium
o Impact: High
o Risk Level: High
 Scenario 2 (Security Compromise)
o Likelihood: Medium
o Impact: Critical
o Risk Level: Critical
RISK MITIGATION STRATEGIES:
Data Center & Fixtures:

o Redundant power systems


o Environmental monitoring
o Fire suppression systems
o Access control systems
o 24/7 security monitoring
o Regular maintenance
Door Access System:

o Regular system testing


o Backup power supply
o Access log monitoring
o Regular maintenance
o Emergency override procedures
o Multi-factor authentication
DELL PowerEdge Server:

o Regular backups
o Hardware monitoring
o Patch management
o Access controls
o Configuration management
o Incident response plan
CYBERSECURITY CONTROLS:
Technical Controls:

 Access control systems


 Environmental monitoring
 Network security
 Backup systems
 Encryption
 System monitoring
Administrative Controls:

 Security policies
 Access procedures
 Maintenance schedules
 Training programs
 Incident response
 Change management
Physical Controls:

 Security personnel
 CCTV systems
 Environmental controls
 Access cards
 Biometric systems
 Fire suppression
Justification for Controls:

 Protects critical infrastructure


 Ensures business continuity
 Maintains data security
 Enables quick recovery
 Supports compliance
 Reduces operational risks
This assessment should be reviewed:

 Quarterly for critical systems


 After significant changes
 Following incidents
 During upgrades
 For compliance audits
 When new threats emerge

6. Intangible Assets

Asset Group Asset Number Asset Owner Location Value Security access
/Department

Licences and I1 Business licenses CEO Intangible H Restricted


Certifications

I2 Standard Compliance CEO Intangible H Restricted


Certification (Accrediting
Bodies)

Competitive I3 Clients CEO Intangible H N/A


values
I4 Reputation CEO Intangible H N/A

I5 Brand Name CEO Intangible H N/A

Insurances I6 Insurances CEO Intangible H Restricted

Industry I8 Industry Experience All employees Intangible H Confidential


Experience

Selected Assets:
I1: Business licenses
I3: Clients
I5: Brand Name

For I1: Business Licenses


Scenario 1: Digital License Theft/Tampering

 Threat: Unauthorized modification of license documents


 Vulnerability: Digital document storage security gaps
 Likelihood: Medium
 Impact: Critical (could lead to business suspension)
 Risk Level: High
Scenario 2: License Information Leak

 Threat: Unauthorized access to license documentation


 Vulnerability: Insufficient access controls
 Likelihood: Low
 Impact: High
 Risk Level: Medium
For I3: Clients
Scenario 1: Client Database Breach

 Threat: Unauthorized database access


 Vulnerability: Inadequate database security
 Likelihood: High
 Impact: Critical
 Risk Level: Critical
Scenario 2: Client Data Manipulation
 Threat: Internal/external data tampering
 Vulnerability: Insufficient data integrity controls
 Likelihood: Medium
 Impact: High
 Risk Level: High
For I5: Brand Name
Scenario 1: Brand Reputation Attack

 Threat: Social media compromise/brand impersonation


 Vulnerability: Weak social media security controls
 Likelihood: High
 Impact: High
 Risk Level: High
Scenario 2: Website Defacement

 Threat: Website compromise


 Vulnerability: Web application security weaknesses
 Likelihood: Medium
 Impact: High
 Risk Level: High
[Link] Mitigation Strategies:
For Business Licenses (I1):

 Implement digital document management system


 Create secure backup system for all license documentation
 Establish version control and audit trail
 Implement strict access control policies
For Clients (I3):

 Implement robust database encryption


 Regular security audits of client data systems
 Data loss prevention solutions
 Client data access monitoring
 Regular data backup and recovery testing
For Brand Name (I5):

 Implement brand monitoring systems


 Social media security protocols
 Website security hardening
 Digital certificate management
 Regular security assessments
[Link] Controls and Justification:
For Business Licenses (I1):

 Technical Controls:
o Document Management System
Justification: Ensures license integrity
o Access Control System
Justification: Prevents unauthorized access
o Encryption
Justification: Protects sensitive license information
For Clients (I3):

 Technical Controls:
o Database Activity Monitoring
Justification: Detects unauthorized access
o Data Encryption
Justification: Protects client data
o Access Control Lists
Justification: Ensures appropriate access
 Administrative Controls:
o Data Handling Procedures
Justification: Ensures consistent data protection
o Regular Audits
Justification: Maintains compliance
For Brand Name (I5):

 Technical Controls:
o Web Application Firewall
Justification: Protects online brand presence
o Brand Monitoring Tools
Justification: Detects brand abuse
o SSL/TLS Certificates
Justification: Ensures authentic web presence
 Administrative Controls:
o Social Media Policy
Justification: Protects brand reputation
Incident Response Plan

Justification: Quick response to brand attacks


Conclusion
Risk Assessment:
The implementation of NIST SP 800-30 provides a robust foundation for The New Age Bank's cybersecurity risk assessment as it is recognized
as the most comprehensive assessment guide . The bank should treat this as an ongoing process rather than a one-time activity , especially
given its adoption of AI-enabled banking systems and increasing cyber-attack attempts.
Risk Mitigation and Strategy:
The assessment will help identify specific business risks and determine appropriate mitigation actions . Given the bank's reliance on cutting-
edge technologies and the thousands of daily cyber-attack attempts, the focus should be on:

 Protecting information through systematic risk mitigation


 Implementing a semi-quantitative approach for risk evaluation
 Establishing clear mappings between security standards and guidelines, working with both public and private sector entities
Control Implementation:
The bank should select and implement security controls based on the detailed methodology provided in NIST SP 800-30 . This should include:

 Regular assessment of federal information systems and organizational security


 Continuous monitoring and updating of security measures
 Integration of controls across all digital banking services (payment card, mobile banking, internet banking, and AI-enabled systems)
Justification:
The adoption of NIST SP 800-30 is justified because:
1. It provides a comprehensive framework specifically designed for conducting risk assessments
2. It ensures compliance with federal guidelines and best practices
3. It supports ongoing risk management rather than point-in-time assessment
4. It allows for systematic identification and mitigation of information security risks
Given The New Age Bank's position as a pioneer in the Ethiopian banking industry and its heavy reliance on information systems, this
structured approach to risk assessment and management is crucial for maintaining both security and competitive advantage while protecting
against the increasing cyber threats they face.

You might also like