Cybersecurity Risk Assessment Guide
Cybersecurity Risk Assessment Guide
Cyber security risk assessment is a systematic process of identifying, analyzing, and evaluating potential security risks to an
organization's information systems and assets. This critical process helps organizations understand their security posture and make
informed decisions about resource allocation for protecting their digital infrastructure.
Risk scenarios represent specific situations where security breaches could occur. These scenarios emerge from the interaction
between threats (potential sources of harm) and vulnerabilities (weaknesses that can be exploited). For example, a risk scenario
might involve a malicious actor exploiting an unpatched software vulnerability to gain unauthorized access to sensitive customer
data.
Threats can be both internal and external, ranging from sophisticated cyber criminals and state-sponsored actors to disgruntled
employees and human error. Vulnerabilities encompass technical weaknesses like outdated software, misconfigured systems, and
weak passwords, as well as organizational weaknesses such as inadequate security training or poor access control policies.
The assessment of risk involves analyzing both likelihood (the probability of a threat exploiting a vulnerability) and impact (the
potential consequences of a security breach). These factors combine to determine the overall risk level, which helps prioritize
security efforts. For instance, a vulnerability that's easily exploitable and could lead to significant financial loss would be classified as
high-risk.
Risk mitigation strategies are comprehensive approaches to reduce identified risks to acceptable levels. These strategies typically
involve implementing various cybersecurity controls, which can be technical (like encryption and firewalls), administrative (such as
policies and procedures), or physical (including secure facilities and hardware protection).
The selection of specific security controls must be justified based on their effectiveness, cost-efficiency, and alignment with
organizational objectives. This justification should demonstrate how each control addresses specific risks while considering the
organization's resource constraints and operational requirements.
Regular reassessment of these elements ensures that security measures remain effective as threats evolve and new vulnerabilities
emerge in the ever-changing cyber security landscape.
CASE STUDY
The New Age Bank Cybersecurity Risk Assessment and Mitigation Scenario
The New Age Bank is one of the pioneer banks in the Ethiopian banking industry. The bank provides a full-fledged payment card
service, mobile banking, internet banking, and online banking on top of the branch based services.
The New Age Bank is highly reliable on information systems to provide its services. It is a pioneer to adopt cutting edge technologies
in the banking industry. It recently has adopted an intelligent banking system, AI enabled banking system, which can provide diverse
services for customers.
Its reliance on information systems and cutting edge technologies is highly increasing the reputation of the bank and its profit.
Unfortunately, it is also become attractive for cybercriminals and the bank is getting thousands of cyber-attack attempts daily.
Therefore, the senior management of the bank has decided to cybersecurity risk assessment based on NIST-SP 800-30 standard. The
senior management has decided to conduct this task by dividing the task for different groups of professionals considering the broad
assets of the bank and the time required. You are among the selected cybersecurity professionals who will conduct this critical
initiative.
The bank has identified selected departments and assets which should be considered in the first phase. The asset inventory which
constitute the assets that are in the scope of the first phase are provided to you and your team members. The asset inventory consists
different assets under six categories.
Tasks:
1. Review the attached asset inventory and select three to five assets, based on the number of your group members. The assets should
be selected from different categories.
a. Develop a risk scenario for each asset. You should put at least two scenarios for each asset.
1. Information Assets
SAGE Payroll D6 SAGE Payroll Finance Department Public File Server H Restricted
System & Data System & Data
Personnel Data D7 Personnel Data HR Department Public File Server H Restricted
Public Server D5 Compliance CEO (Various users Public File Server & H Restricted
Based Documents have access) Backup Drive
Documents
including Licences
& Certification
a. Risk Scenarios:
o Scenario 1: Website Defacement: An attacker gains unauthorized access and changes the content of the website, damaging the
organization's reputation.
o Scenario 2: Denial of Service (DoS) Attack: An attacker floods the website with traffic, making it unavailable to legitimate users.
b. Threats and Vulnerabilities:
o Scenario 1 (Defacement):
Likelihood: Medium (depending on the security of the website)
Impact: Medium (reputational damage, loss of customer trust)
Risk Level: Medium
o Scenario 2 (DoS):
Likelihood: Low to Medium (depending on the website's infrastructure and security measures)
Impact: High (loss of business, customer frustration)
Risk Level: Medium to High
3. Risk Mitigation Strategies:
o Scenario 1 (Defacement):
Regularly patch software vulnerabilities.
Implement strong password policies and multi-factor authentication.
Use a web application firewall (WAF) to protect against common web attacks.
Implement input validation to prevent SQL injection and XSS attacks.
Regularly monitor website logs for suspicious activity.
o Scenario 2 (DoS):
Use a content delivery network (CDN) to distribute traffic and absorb attacks.
Implement rate limiting to prevent excessive traffic from a single source.
Use a DDoS mitigation service.
Monitor network traffic for anomalies.
4. Applicable Cyber security Controls and Justification:
o Technical Controls:
Web Application Firewall (WAF): Protects against web-based attacks like SQL injection and XSS.
Justification: Directly addresses vulnerabilities that could lead to defacement.
Intrusion Detection/Prevention System (IDS/IPS): Monitors network traffic for malicious activity and blocks or alerts on
suspicious behavior.
Justification: Helps detect and prevent both defacement and DoS attacks.
Patch Management System: Ensures that all software is up-to-date with the latest security patches.
Justification: Reduces the attack surface by eliminating known vulnerabilities.
DDoS Mitigation Service: Protects against denial-of-service attacks. Justification: Specifically addresses the DoS
risk.
o Administrative Controls:
Security Awareness Training: Educates employees about security threats and best practices.
Justification: Reduces the risk of human error, such as weak passwords or clicking on malicious links.
Incident Response Plan: Outlines the steps to be taken in the event of a security incident.
Justification: Ensures a coordinated and effective response to minimize damage.
Asset 2: Customer Data (D12)
a. Risk Scenarios:
o Scenario 1: Data Breach: An attacker gains unauthorized access to the server and steals customer data (e.g., names, addresses,
credit card numbers).
o Scenario 2: Accidental Data Leakage: An employee accidentally exposes customer data (e.g., by sending an email to the wrong
recipient or misconfiguring a database).
b. Threats and Vulnerabilities:
o Threats: Hackers, malicious insiders, negligent employees.
o Vulnerabilities: Weak access controls, unencrypted data, unpatched server vulnerabilities, SQL injection vulnerabilities, lack of
data loss prevention (DLP) measures, misconfigured databases.
c. Likelihood, Impact, and Risk Level:
o Technical Controls:
Data Encryption (at rest and in transit): Protects data even if a breach occurs.
Justification: Reduces the impact of a data breach by rendering the stolen data unusable.
Access Control Lists (ACLs) and Role-Based Access Control (RBAC): Limits access to customer data to only authorized
personnel.
Justification: Prevents unauthorized access and reduces the risk of both internal and external threats.
Data Loss Prevention (DLP) System: Monitors and prevents sensitive data from leaving the organization's control.
Justification: Prevents accidental data leakage.
Database Activity Monitoring (DAM): Monitors database activity for suspicious behavior.
Justification: Helps detect and prevent data breaches.
o Administrative Controls:
Data Security Policy: Outlines the organization's policies for protecting customer data.
Justification: Provides a framework for data security and ensures that all employees are aware of their responsibilities.
Employee Background Checks: Reduces the risk of hiring malicious insiders.
Justification: Helps prevent insider threats.
Asset 3: SAGE Payroll System & Data (D6)
a. Risk Scenarios:
o Scenario 1: Payroll Fraud: An attacker gains unauthorized access to the payroll system and manipulates employee salaries or
bank account details.
o Scenario 2: Data Breach: An attacker gains unauthorized access to the payroll system and steals employee personal and
financial information.
b. Threats and Vulnerabilities:
o Technical Controls:
Multi-Factor Authentication (MFA): Requires users to provide multiple forms of authentication before accessing the
system.
Justification: Significantly reduces the risk of unauthorized access.
Database Encryption: Encrypts the payroll database to protect sensitive data.
Justification: Reduces the impact of a data breach.
Intrusion Detection/Prevention System (IDS/IPS): Monitors network traffic for malicious activity.
Justification: Helps detect and prevent both fraud and data breaches.
Security Information and Event Management (SIEM) System: Collects and analyzes security logs from various sources to
identify suspicious activity.
Justification: Provides a centralized view of security events and helps detect anomalies.
o Administrative Controls:
Segregation of Duties: Divides responsibilities among multiple employees to prevent a single person from having too
much control.
Justification: Reduces the risk of fraud.
Regular Audits: Regularly audit the payroll system to identify vulnerabilities and ensure compliance with security
policies.
Justification: Helps identify and correct security weaknesses.
Background Checks: Conduct thorough background checks on employees with access to the payroll system.
Justification: Reduces the risk of insider threats.
2. Service Assets
Power and E1 Fire Alarm System Company Secretary Head Office H Restricted
Safety Building
IT service enablers X1
X2
X3
Threats:
o Power outages
o Cyber attacks
o Physical tampering
o System malfunction
Vulnerabilities:
o Outdated firmware
o Network connectivity exposures
o Insufficient backup power
o Poor maintenance
c. Risk Level Analysis:
Threats:
o New malware variants
o Zero-day exploits
o Internal sabotage
o Update server issues
Vulnerabilities:
o Outdated virus definitions
o Configuration errors
o Network connectivity issues
o Admin access misuse
c. Risk Level Analysis:
Threats:
o Power surges
o Equipment failure
o Overheating
o Physical damage
Vulnerabilities:
o Aging batteries
o Poor maintenance
o Inadequate cooling
o Overload capacity
c. Risk Level Analysis:
Security policies
Staff training
Incident response plans
Change management
Regular audits
Documentation
Physical Controls:
Access restrictions
Environmental monitoring
Security cameras
Backup power
Fire suppression
Physical locks
Justification for Controls:
3. People Assets
Board member(P1)
It staff (P6)
Consultant (P7)
Threats:
o Targeted cyber attacks
o Social engineering
o Physical threats
o Corporate espionage
Vulnerabilities:
o High-profile positions
o Access to sensitive information
o Travel requirements
o Public exposure
c. Risk Level Analysis:
Threats:
o Privileged access misuse
o Social engineering
o Burnout/stress
o External recruitment
Vulnerabilities:
o High-level system access
o Access to multiple systems
o Knowledge of security measures
o Stress from critical responsibilities
c. Risk Level Analysis:
Threats:
o Data leakage
o Intellectual property theft
o Unauthorized access
o Competitive intelligence gathering
Vulnerabilities:
o Temporary nature of engagement
o Limited organizational loyalty
o Variable security awareness
o Multiple client exposure
c. Risk Level Analysis:
Multi-factor authentication
Access monitoring
Encryption
Mobile device management
Data loss prevention
Network segmentation
Administrative Controls:
Security policies
Background checks
Training programs
Confidentiality agreements
Access review processes
Incident response plans
Physical Controls:
Access cards
CCTV surveillance
Clean desk policy
Secure disposal
Visitor management
Physical security
Justification for Controls:
1. Addresses human-centric risks
2. Protects sensitive information
3. Maintains regulatory compliance
4. Reduces insider threats
5. Enables monitoring and audit
6. Supports incident response
This assessment should be reviewed:
Access Control (AC-2, AC-4): Implement role-based access control and network segmentation
System and Information Integrity (SI-2): Automated patch management
System and Communications Protection (SC-5): DDoS protection
Justification: These controls address the primary vectors of attack while maintaining system availability.
2. ASSET A5 - Internet Banking System
Risk Scenarios:
1. Data Breach Scenario
Threat: Unauthorized access to customer financial data
Vulnerability: SQL injection, insecure APIs
Likelihood: High (financial systems are prime targets)
Impact: High (financial and reputational damage)
Risk Level: Critical
2. Transaction Manipulation Scenario
Threat: Fraudulent transactions
Vulnerability: Insufficient transaction validation
Likelihood: Medium
Impact: High (direct financial loss)
Risk Level: High
Mitigation Strategies:
Threats:
o Natural disasters
o Power failures
o Physical intrusion
o Environmental issues
Vulnerabilities:
o Single point of failure
o Physical access controls
o Environmental controls
o Backup systems
c. Risk Level Analysis:
Threats:
o Power outages
o System hacking
o Social engineering
o Hardware failure
Vulnerabilities:
o Network connectivity
o Backup power
o Access card cloning
o System maintenance
c. Risk Level Analysis:
Threats:
o Hardware malfunction
o Cyber attacks
o Power issues
o Configuration errors
Vulnerabilities:
o System access
o Patch management
o Backup procedures
o Configuration settings
c. Risk Level Analysis:
o Regular backups
o Hardware monitoring
o Patch management
o Access controls
o Configuration management
o Incident response plan
CYBERSECURITY CONTROLS:
Technical Controls:
Security policies
Access procedures
Maintenance schedules
Training programs
Incident response
Change management
Physical Controls:
Security personnel
CCTV systems
Environmental controls
Access cards
Biometric systems
Fire suppression
Justification for Controls:
6. Intangible Assets
Asset Group Asset Number Asset Owner Location Value Security access
/Department
Selected Assets:
I1: Business licenses
I3: Clients
I5: Brand Name
Technical Controls:
o Document Management System
Justification: Ensures license integrity
o Access Control System
Justification: Prevents unauthorized access
o Encryption
Justification: Protects sensitive license information
For Clients (I3):
Technical Controls:
o Database Activity Monitoring
Justification: Detects unauthorized access
o Data Encryption
Justification: Protects client data
o Access Control Lists
Justification: Ensures appropriate access
Administrative Controls:
o Data Handling Procedures
Justification: Ensures consistent data protection
o Regular Audits
Justification: Maintains compliance
For Brand Name (I5):
Technical Controls:
o Web Application Firewall
Justification: Protects online brand presence
o Brand Monitoring Tools
Justification: Detects brand abuse
o SSL/TLS Certificates
Justification: Ensures authentic web presence
Administrative Controls:
o Social Media Policy
Justification: Protects brand reputation
Incident Response Plan