Introduction to Information Security Management
Introduction to Information Security Management
1) Introduction to Security
As businesses have become more fluid, "computer security" has evolved into "information security,"
or "InfoSec," which covers a broader range of issues, from the protection of computer-based data to
the protection of human knowledge.
Asset is an organizational resource that is being protected. An asset can be logical, such as a Web
site, software information, or data; or an asset can be physical, such as a person, computer system,
hardware, or other tangible object.
Assets, particularly information assets, are the focus of what security efforts are attempting to
protect.
Information asset is the focus of information security; information that has value to the organization,
and the systems that store, process, and transmit the information.
Information security is no longer the sole responsibility of a small, dedicated group of professionals in
the company. It is now the responsibility of all employees, especially managers.
Information Security (InfoSec) is protection of the confidentiality, integrity, and availability of
information assets, whether in storage, processing, or transmission, via the application of policy,
education, training and awareness, and technology.
The entire organization is represented by three distinct groups of managers and professionals, or
communities of interest:
a) Those in the field of information security
b) Those in the field of IT
c) Those from the rest of the organization
These three groups should engage in a constructive effort to reach consensus on an overall plan to
protect the organization's information assets.
The communities of interest and the roles they fulfill include the following:
a) The information security community protects the organization's information assets from
the many threats they face.
b) The IT community supports the business objectives of the organization by supplying and
supporting IT that is appropriate to the organization's needs.
c) The general business community articulates and communicates organizational policy and
objectives and allocates resources to the other groups.
Each community of interest must understand that information security is about identifying,
measuring, and mitigating (or at least understanding and documenting) the risk associated with
operating information assets in a modern business environment.
Security means being free from danger. To be secure is to be protected from the risk of loss, damage,
unwanted modification, or other hazards.
Information security (lnfoSec) focuses on the protection of information and the characteristics that
give it value, such as confidentiality, integrity, and availability, and includes the technology that
houses and transfers that information through a variety of protection mechanisms such as policy,
training and awareness programs, and technology.
Figure 1- 1 show that InfoSec includes the broad areas of InfoSec management: computer security,
data security, and network security. The figure also shows that policy is the space where these
components overlap.
When using this model to design or review any InfoSec program, it is made sure that each of the 27
cells is properly addressed by each of the three communities of interest.
For example, the cell representing the intersection of the technology, integrity, and storage criteria
could include controls or safeguards addressing the use of technology to protect the integrity of
information while in storage.
Such a control might consist of a host intrusion detection and prevention system (HIDPS), for
example, which would alert the security administrators when a critical file was modified or deleted.
Advantage:
The model identifies gaps in the coverage of an InfoSec program.
Disadvantage:
1) Model omits any discussion of guidelines and policies that direct the implementation of
controls, which are essential to an effective InfoSec program.
2) These controls can be implemented only through a process that includes consensus building
and constructive conflict to reflect the balancing act that each organization faces as it
designs and executes an InfoSec program.
2) Integrity
The integrity or completeness of information is threatened when it is exposed to corruption, damage,
destruction, or other disruption of its authentic state.
Corruption can occur while information is being entered, stored, or transmitted.
Many computer viruses and worms, for example, are designed to corrupt data. For this reason, the key
method for detecting whether a virus or worm has caused an integrity failure to a file system is to look
for changes in the file's state, as indicated by the file's size or, in a more advanced operating system, its
hash value or checksum
File corruption is not always the result of deliberate attacks.
Faulty programming or even noise in the transmission channel or medium can cause data to lose its
integrity. For example, a low-voltage states in a signal carrying a digital bit (a 1 or o) can cause the
receiving system to record the data incorrectly.
To compensate for internal and external threats to the integrity of information, systems employ a
variety of error-control techniques, including the use of redundancy bits and check bits. During each
transmission, algorithms, hash values, and error-correcting codes ensure the integrity of the
information.
Data that has not been verified in this manner is retransmitted or otherwise recovered. Because
information is of little or no value or use if its integrity cannot be verified, information integrity is a
cornerstone of InfoSec.
3) Availability
Availability of information means that users, either people or other systems, have access to it in a
usable format.
4) Privacy
Information that is collected, used, and stored by an organization should be used only for the purposes
stated by the data owner at the time it was collected.
Privacy does not mean freedom from observation (the meaning usually associated with the word); it
means that the information will be used only in ways approved by the person who provided it.
Many organizations collect, swap, and sell personal information as a commodity.
Today, it is possible to collect and combine personal information from several different sources
{known as information aggregation), which has resulted in databases that could be used in ways the
original data owner has not agreed to or even knows about.
Many people have become aware of these practices and are looking to the government to protect their
information's privacy.
5) Identification
Identification process recognizes individual users.
Identification is the first step in gaining access to secured material, and it serves as the foundation for
subsequent authentication and authorization.
Identification and authentication are essential to establishing the level of access or authorization that an
individual is granted.
Identification is typically performed by means of a user name or other ID.
6) Authentication
Authentication is the process by which a control establishes whether a user (or system) is the entity it
claims to be.
Examples include the use of cryptographic certificates to establish Secure Sockets Layer (SSL)
connections as well as the use of cryptographic hardware devices- for example, hardware tokens such
as RSA's SecurID.
Individual users may disclose a personal identification number (PIN), a password, or a passphrase to
authenticate their identities to a computer system.
7) Authorization
After the identity of a user is authenticated, a process called authorization defines what the user
(whether a person or a computer) has been specifically and explicitly authorized by the proper
authority to do, such as access, modify, or delete the contents of an information asset.
An example of authorization is the activation and use of access control lists and authorization groups
in a networking environment.
Another example is a database authorization scheme to verify that the user of an application is
authorized for specific functions, such as reading, writing, creating, and deleting.
c) Power irregularities
Irregularities from power utilities are common and can lead to fluctuations such as power
excesses, power shortages, and power losses.
These fluctuations can pose problems for organizations that provide inadequately conditioned
power for their information systems equipment.
In the United States, residential users are supplied 120-volt, Go-cycle power, usually through
15- and 20-amp circuits. Commercial buildings often have 240-volt service and may also have
specialized power distribution infrastructure.
When power voltage levels vary from normal, expected levels, such as during a blackout,
brownout, fault, noise, spike, surge, or sag, an organization's sensitive electronic equipment-
especially networking equipment, computers, and computer-based systems, which are
vulnerable to fluctuations- can be easily damaged or destroyed.
Most good uninterruptible power supplies (UPS) can protect against spikes, surges, and sags,
and even brownouts and blackouts of limited duration.
3) Espionage or Trespass
When an unauthorized person gains access to information an organization is trying to protect,
the act is categorized as espionage or trespass.
Some information-gathering techniques are legal- for example, using a Web browser to perform
market research. These legal techniques are collectively called competitive intelligence.
When information gatherers employ techniques that cross a legal or ethical threshold, they are
conducting industrial espionage.
a) Shoulder surfing
It is used in public or semipublic settings when people gather information they are not
authorized to have.
Instances of shoulder surfing occur at computer terminals, desks, and ATMs; on a bus, airplane,
or subway, where people use smart-phones and tablet PCs; and in other places where
employees may access confidential information.
Shoulder surfing flies in the face of the unwritten etiquette among professionals who address
information security in the workplace: If you can see person entering personal or private
information into a system, look away as the information is entered. Failure to do so constitutes
not only a breach of etiquette, but also an affront to privacy and a threat to the security of
confidential information.
b) Hackers
The classic perpetrator of espionage or trespass is the hacker, who is frequently glamorized in
fictional accounts as a person who stealthily manipulates a maze of computer networks,
systems, and data to find information that solves the mystery and heroically saves the day.
In the real world, a hacker frequently spends long hours examining the types and structures of
i) Expert hacker
The expert hacker is usually a master of several programming languages, networking
protocols, and operating systems, and exhibits a mastery of the technical environment of the
chosen targeted system.
Once an expert hacker chooses a target system, the likelihood is high that he or she will
successfully enter the system.
a) Professional hacker
The professional hacker seeks to conduct attacks for personal benefit or the benefit of
an employer, which is typically a crime organization or governmentsponsored
operation (see the section on cyber-terrorism).
b) Penetration tester
The penetration tester is one who has authorization from an organization to test its
information systems and network defense, and is expected to provide detailed reports
of the findings.
The primary differences between professional hackers and penetration testers are the
authorization provided and the ethical professionalism displayed.
The precisely targeted attack against organizations is known as an advanced persistent threat
or APT. These attacks are usually a combination of social engineering, spear phishing, and
customized malware generated by nation-state sponsored organizations or sophisticated
criminal operations.
In many cases, these attacks seek to infiltrate high-value information for economic espionage or
attacks against national security.
(_ _ _ cont. hackers_ _ _)
Once an attacker gains access to a system, attacker increase his or her privileges (privilege
c) Phreakers
Phreakers grew in fame in the 1970s when they developed following devices.
i) Blue boxes
Blue boxes enabled Phreakers to make free calls from pay phones.
ii) Red boxes
Red boxes were developed to simulate the tones of coins falling in a pay phone.
iii) Black boxes
Black boxes emulated the line voltage.
d) Password attacks
Password attacks fall under the category of espionage or trespass just as lock-picking falls
under breaking and entering. Attempting to guess or reverse-calculate a password is often
called cracking.
i) Brute force
The application of computing and network resources to try every possible password
combination is called a brute force password attack.
If attackers can narrow the field of target accounts, they can devote more time and resources
to these accounts.
This is one reason to always change the default administrator password assigned by the
manufacturer.
Brute force password attacks are rarely successful against systems that have adopted the
manufacturer's recommended security practices.
Controls that limit the number of unsuccessful access attempts within a certain time are very
effective against brute force attacks.
The strength of a password is a combination of its length and complexity, which help
determine its ability to withstand a brute force attack.
Using best-practice policies for passwords can greatly enhance their strength; use passwords
of at least 10 characters and at least one uppercase and lowercase letter, one number and one
special character, and systems that allow case-sensitive passwords.
4) Forces of nature
Forces of nature, sometimes called acts of God, can present some of the most dangerous threats
because they usually occur with little warning and are beyond the control of people.
Since it is not possible to avoid threats from forces of nature, organizations must implement
controls to limit damage and prepare contingency plans for continued operations, such as
disaster recovery plans, business continuity plans, and incident response plans.
Another term that may encounter force majeure is roughly translated as "superior force”
which includes forces of nature as well as civil disorder and acts of war.
a) Fire
The ignition of combustible material; damage can also be caused by smoke from fires or by
water from sprinkler systems or firefighters.
b) Flood
a) Social engineering
In the context of information security, social engineering is used by attackers to gain system
c) Phishing
Some attacks are sent by e-mail and may consist of a notice that one's e-mail storage
allotment has been exceeded.
The user is asked to log in, to run a test program attached to the e-mail, or even to log into
their "bank" account (spoofed by the attacker) to verify their balance.
While these attacks may seem crude to experienced users, the fact is that many e-mail users
have fallen for them. These tricks and similar variants are called phishing attacks.
Phishing attacks use two primary techniques, often in combination with one another: URL
manipulation and Web site forgery.
In URL manipulation, attackers send an HTML embedded e-mail message or a hyperlink
whose HTML code opens a forged Web site.
In Web forgery, the attacker copies the HTML code from a legitimate Web site and then
modifies key elements.
When victims type their banking ID and password, the attacker records that information and
displays a message that the Web site is now offline.
d) Spear phishing
Spear phishing involves an attacker sending a targeted message that appears to be from an
employer, a colleague, or other legitimate correspondent to a small group or even one
person.
e) Pretexting
Pretexting, sometimes referred to as phone phishing, is a purely social engineering attack in
which the attacker calls a potential victim on the telephone and pretends to be an authority
figure in order to gain access to private or confidential information, such as health,
employment, or financial records.
6) Information extortion
a) Information extortion
Information extortion, also known as cyberextortion, is common in the theft of credit card
numbers.
In 2010, Anthony Digati allegedly threatened to conduct a spam attack on the insurance
company, New York Life. He reportedly sent dozens of e-mails to company executives
b) Ransomware
This attack is usually implemented with malware that is run on the victim's system as a
result of phishing or spear-phishing attacks. The result is that the user's data is encrypted.
Paying the adversary a ransom in a digital currency may or may not result in the victim
receiving the encryption key to recover the data.
Waves of attacks in 2017 used ransomware variants such as WannaCry, Petya, and
NotPetya. Loss events to victims of the CryptoWall ransomware attacks in 2014 and 2015
included ransom payments ranging from $200 to $ 10,0 00 per incident as well as costs for
lost productivity, legal fees, and other recovery expenses.
How do you react if you are the victim of ransomware? Cloud protection and information
management specialists at Druva recommend the following:
1. Do not pay the ransom- There is no guarantee you will get your data back. Druva finds
that one in three organizations affected pay the ransom, yet almost half do not get their data
back.
2. Turn all devices off and disconnect from the network- Try to minimize the spread and
damage from the infection. Shut down th e Wi-Fi service and try to isolate infected systems
so the damage does not spread further.
3. Find the source of the infection- Trying to determine how your systems were infected
can assist you in preventing further spread by informing and educating users.
4. Alert all users- Let everyone know that a ransomware attack is in progress and how not
to get infected. Do not just rely on e-mail to send these alerts- you may want to activate
your phone tree and spread the word that way.
5. Restore from a backup to a new device- Determine if your backups are infected by
eliminating any chance that the infection was present on the computer to which you are
restoring. Then, make sure the data is accessible before porting it to another system.
6. Reimage the infected systems- The only way to be sure ransomware is not lurking in a
hidden file in the operating system, hard drive, or an application is to wipe the infected
systems to their initial state and start over. Many organizations use standard images for
their systems. Wiping all drives clean and reimaging provides a fresh start and some
assurances that the systems will not be immediately reinfected once data is available.
7) Sabotage or Vandalism
This category of threat involves the deliberate sabotage of a computer system or business, or
Chapter 1 |Introduction to the management of security 14
- Neha Rathi
acts of vandalism to destroy an asset or damage the image of an organization. These acts can
range from petty vandalism by employees to organized sabotage against an organization.
Organizations can minimize their risk of Web site defacement by backing up their Web sites
regularly, closely monitoring their Web sites, and minimizing the use of exploitable software
such as scripts, plug-ins, and other application programming interfaces (APIs).
a) Online activism
There are innumerable reports of hackers accessing systems and damaging or destroying
critical data.
Hacked Web sites once made frontpage news, as the perpetrators intended. The impact of
these acts has lessened as the volume has increased.
Today, security experts are noticing a rise in another form of online vandalism, hacktivist or
cyberactivist operations, in which activists hack into a target's online resource, such as e-
mail or social media, and then release that information to the public.
8) Software attacks
Deliberate software attacks occur when an individual or group designs and deploys software to
attack a system.
This type of attack is usually part of a campaign that integrates a variety of tools, techniques,
and procedures (TTP) to merge specially crafted software and social engineering methods that
seek to trick users into installing computer code onto their systems.
Once an infection occurs, the software leverages that foothold by attacking other systems that
a) Malware
Malware is also referred to as malicious code or malicious software.
Malicious code attacks include the execution of viruses, worms, Trojan horses, and active
Web scripts with the intent to destroy or steal information.
The most state-of-the-art malicious code attack is the polymorphic worm, or multivector
worm.
These attack programs use up to six known attack vectors to exploit a variety of
vulnerabilities in common information system devices.
i) Virus
A computer virus consists of code segments (programming instructions) that perform
malicious actions.
The code attaches itself to an existing program and takes control of the program's access
to the targeted computer. The virus- controlled target program then carries out the virus
plan by replicating itself into additional targeted systems.
When these viruses infect a machine, they may immediately scan it for e-mail
applications or even send themselves to every user in the e-mail address book.
Viruses can be classified by how they spread themselves. Among the most common
types of information system viruses are the macro virus, which is embedded in
automatically executing macro code used by word processors, spreadsheets, and
database applications, and the boot virus (or boot-sector virus), which infects the key
operating system files in a computer's boot sector.
Viruses may be classified as memory-resident viruses or nonmemory-resident
viruses, depending on whether they persist in a computer system's memory after they
have been executed.
Resident viruses are capable of reactivating when the computer is booted and
continuing their actions until the system is shut down, only to restart the next time the
system is booted.
ii) Worms
A worm can continue replicating itself until it completely fills available resources, such
as memory, hard drive space, and/or network bandwidth.
The complex behavior of worms can be initiated with or without the user downloading
or executing the file.
Once the worm has infected a computer, it can redistribute itself to other systems
connected to the compromised systems using e-mail directories and network links found
on the infected system.
A worm can deposit copies of itself onto all Web servers that the infected system can
reach; users who subsequently visit those sites become infected.
b) Backdoors
i) Backdoor
Using a known or newly discovered access mechanism, an attacker can gain access to a
system or network resource through a back door.
Attackers place a back door into a system or network they have compromised, making
their return to the system that much easier the next time.
ii) Trapdoor
Viruses and worms can have a payload that installs a back door or trap door component
in a system, allowing the attacker to access the system at will with special privileges.
A trap door is hard to detect because the person or program that places it often makes
the access exempt from the system's usual audit logging features and makes every
attempt to keep the back door hidden from the system's legitimate owners.
d) E-mail attacks
Unwanted e-mail, especially bulk commercial e-mail or spam, is a common problem for e-
mail users.
i) Packet sniffer
A packet sniffer (or network sniffer) can monitor data traveling over a network.
Sniffers can be used both for legitimate network management functions and for stealing
information.
Unauthorized sniffers can be extremely dangerous to a network's security because they are
virtually impossible to detect and can be inserted almost anywhere.
This feature makes them a favorite weapon in the hacker's arsenal.
Sniffers often work on TCP/IP networks.
Sniffers add risk to networks because many systems and users send information on local
networks in clear text.
A sniffer program shows all the data going by, including plain-text passwords, the data
inside files (such as word-processing documents), and potentially sensitive data from
applications.
ii) Spoofing
To engage in IP spoofing, hackers use a variety of techniques to obtain trusted IP
addresses and then modify the packet headers to insert forged addresses.
Newer routers and firewall arrangements can offer protection against IP spoofing.
a) MTBF
The average amount of time between hardware failures, calculated as the total amount of
operation time for a specified number of units divided by the total number of failures.
b) MTTD
The average amount of time a computer repair technician needs to determine the cause of a
failure.
c) MTTF
The average amount of time until the next hardware failure.
d) MTTR
The average amount of time a computer repair technician needs to resolve the cause of a
i) SQL injection
SQL injection occurs when developers fail to properly validate user input before
passing it on to a relational database.
The possible effects of an adversary's "injection" of SQL are not limited to improper
access to information, but may include damaging operations such as dropping the
USERS table or perhaps shutting down the database.
b) Implementation sins
These sins are classic programming errors that produce vulnerabilities in running software.
i) Buffer overflow
Buffers are simply storage space in a program and are normally of some fixed size.
When used to accept input from an external source (e.g., a form field on a Web page), the
source may supply more information than the buffer was designed to hold and thus
overwrite other areas in the program.
This may cause the program to abort or the adversary may specially craft the excess data to
cause the program to perform unintended actions.
c) Cryptographic sins
d) Networking sins
The network is the piping that enables the worldwide flow of information and makes the
Internet such an interesting place.
However, because it is the medium for all that information flow, it is a rich target.
Autocratic leaders
Reserve all decision-making responsibility for themselves and are "do as I say" types.
Such leaders typically issue an order to accomplish a task and do not usually seek or
accept alternative viewpoints.
The autocratic leader may be more efficient given that he or she is not constrained by the
necessity to accommodate alternative viewpoints.
The autocratic leader may be the less effective if his or her knowledge is insufficient for
the task.
Democratic leaders
Work in the opposite way, typically seeking input from all interested parties, requesting
ideas and suggestions, and then formulating positions that can be supported by a majority.
Each of these two diametrically opposed approaches has its strengths and weaknesses.
The democratic leader may be less efficient because valuable time is spent in discussion
and debate when planning for the task.
The democratic leader may be more effective when dealing with very complex topics
and/or those in which subordinates have strongly held opinions.
Laissez-faire leader
Also known as the "laid-back" leader.
While both autocratic and democratic leaders tend to be action oriented, the laissez-faire
leader often sits back and allows the process to develop as it goes, only making minimal
decisions to avoid bringing the process to a complete halt.
Effective leaders function with a combination of these styles, shifting approaches as
situations warrant.
For example, depending on the circumstances, a leader may solicit input when the
situation permits, make autocratic decisions when immediate action is required, and allow
the operation to proceed with little direct intervention if it is progressing in an efficient
and effective manner.
2) Management characteristics-
The management of tasks requires certain basic skills. These skills are variously referred to as
"management characteristics," "management functions;' "management principles;• or
"management responsibilities."
The two basic approaches to management are:
• Traditional management theory- This approach uses the core principles of planning,
organizing, staffing, directing, and controlling (POSDC).
• Popular management theory- This approach uses the core principles of planning,
organizing, leading, and controlling (POLC).
1) Planning
3) Leading
Leading encourages the implementation of the planning and organizing functions.
It includes supervising employee behavior, performance, attendance, and attitude while
ensuring completion of the assigned tasks, goals, and objectives.
Leadership generally addresses the direction and motivation of the human resource.
4) Controlling
Controlling ensures the validity of the organization's plan.
The manager ensures that sufficient progress is made, that impediments to the completion
of the task are resolved, and that no additional resources are required.
Should the plan be found invalid in light of the operational reality of the organization, the
manager takes corrective action.
The control function relies on the use of cybernetic control loops, often called "negative
feedback."
These involve performance measurements, comparisons, and corrective actions, as shown
in Figure.
Here, the cybernetic control process begins with a measurement of actual performance,
which is then compared to the expected standard of performance as determined by the
planning process.
If the standard is being met, the process is allowed to continue toward completion. If an
acceptable level of performance is not being attained, either the process is corrected to
achieve satisfactory results or the expected level of performance is redefined.
1) Planning
Planning in InfoSec management includes InfoSec planning model which are activities
necessary to support the design, creation, and implementation of InfoSec strategies within
the planning environments of all organizational units, including IT.
Because the InfoSec strategic plans must support not only the IT use and protection of
information assets, but also those of the entire organization, it is imperative that the CISO
work closely with all senior managers in developing InfoSec strategy.
The business strategy is translated into the IT strategy. The strategies of other business
units and the IT strategy are then used to develop the InfoSec strategy.
Just as the CIO uses the IT objectives gleaned from the business unit plans to create the
organization's IT strategy, the CISO develops InfoSec objectives from the IT and other
business units to create the organization's InfoSec strategy.
The IT strategy and that of the other business units provides critical information used for
InfoSec planning as the CISO gets involved with the CIO and other executives to develop
the strategy for the next level down.
The CISO then works with the appropriate security managers to develop operational
security plans. These security managers consult with security technicians to develop
tactical security plans.
Each of these plans is usually coordinated across the business and IT functions of the
enterprise and placed into a master schedule for implementation.
Chapter 1 |Introduction to the management of security 32
- Neha Rathi
The overall goal is to create plans that support long-term achievement of the overall
organizational strategy.
If all goes as expected, the entire collection of tactical plans accomplishes the operational
goals and the entire collection of operational goals accomplishes the subordinate strategic
goals; this helps to meet the strategic goals and objectives of the organization as a whole.
Several types of InfoSec plans and planning functions exist to support routine and non-
normal operations.
These include incident response planning, business continuity planning, disaster recovery
planning, policy planning, personnel planning, technology rollout planning, risk
management planning, and security program planning.
2) Policy
In InfoSec, there are three general policy categories, which are
i) Enterprise Information Security Policy (EISP)-
Developed within the context of the strategic IT plan, this sets the tone for the
InfoSec department and the InfoSec climate across the organization.
The CISO typically drafts the program policy, which is usually supported and
signed by the CIO or the CEO.
ii) Issue-Specific Security Policies (ISSPs)-
These are sets of rules that define acceptable behavior within a specific
organizational resource, such as e-mail or Internet usage.
iii) System-Specific Policies (SysSPs)-
A merger of technical and managerial intent, SysSPs include both the managerial
guidance for the implementation of a technology as well as the technical
specifications for its configuration.
3) Programs
InfoSec operations that are specifically managed as separate entities are called "programs”.
An example would be security education training and awareness (SETA) program, a risk
management program, or contingency programs such as incident response, disaster recovery,
or business continuity.
SETA programs provide critical information to employees to maintain or improve their
current levels of security knowledge.
Risk management programs include the identification, assessment, and control of risks to
information assets.
Contingency programs prepare the organization for non-normal business operations such as
reacting to an incident or disaster, which may require the organization to relocate to an
alternate site at least temporarily.
Other programs that may emerge include a physical security program, complete with fire
protection, physical access, gates, guards, and so on.
Some organizations with specific regulations may have additional programs dedicated to
client/customer privacy, awareness, and the like.
Each organization will typically have several security programs that must be managed.
4) Protection
5) People
People are the most critical link in the InfoSec program.
This area encompasses security personnel (the professional information security
employees), the security of personnel (the protection of employees and their information),
and aspects of the SETA program.
6) Projects
Whether an InfoSec manager is asked to roll out a new security training program or select
and implement a new firewall, it is important that the process be managed as a project.
The final element for thoroughgoing InfoSec management is the application of a project
management discipline to all elements of the InfoSec program.
Project management involves identifying and controlling the resources applied to the
project, as well as measuring progress and adjusting the process as progress is made
toward the goal.
DDoS attacks pose a unique challenge because they involve coordinated, large-scale disruption from multiple sources, making defense difficult without a single effective control measure. They are likened to a 'weapon of mass destruction on the Internet' due to their ability to incapacitate systems connected to the internet by overwhelming them with requests .
Effective InfoSec management requires aligning planning, policy, and people. Planning involves developing strategies supporting organizational goals while policies provide frameworks for secure operations. Coordinating these elements ensures personnel are aware of security protocols and engage in secure practices, aiding the CISO and security managers in implementing comprehensive InfoSec strategies supporting both IT and organizational requirements .
Backdoors provide unauthorized access to systems by exploiting known or newly discovered mechanisms. Attackers typically place a backdoor into a system during initial compromise, allowing easier repeated access in the future without leaving traces. Trapdoors, often installed during virus or worm infections, are hidden from audit logs to avoid detection, enabling attackers to access the system with special privileges .
InfoSec management objectives are focused on maintaining the confidentiality, integrity, and availability of information, often requiring resolutions with IT management goals, which prioritize effective information processing. This alignment and conflict demand collaboration between the CISO and CIO to ensure InfoSec plans support IT and organizational strategic goals without significantly impeding information flow .
Ransomware attacks execute by encrypting the victim's data, usually initiated by malicious software during phishing or spear-phishing incidents. Victims receive demands for ransom to decrypt their data. Notable events include the WannaCry, Petya, and NotPetya attacks in 2017, which caused significant data loss and financial impacts without guaranteed data recovery upon ransom payment .
Virus hoaxes can severely disrupt organizational operations by overloading networks with unnecessary communication, wasting time and resources. When users respond to these hoaxes by informing everyone they know, network bandwidth is consumed, and productivity declines due to distractions and misplaced focus on updating antivirus software unnecessarily .
The four subcategories of communications interception attacks are packet sniffers, spoofing, pharming, and man-in-the-middle attacks. Packet sniffers monitor data traveling over networks and can be used legitimately for network management or nefariously to intercept sensitive information. They are hard to detect, making them a potent threat to network security .
Information extortion refers to the act of threatening to withhold critical information or disrupt operations unless a ransom is paid. Real-world examples include Anthony Digati's threat to spam New York Life with negative campaigns unless paid $200,000 and a programmer who locked executives out of a system, demanding payment for access restoration. Often, threats involve wide dissemination of spam or direct system sabotage to force compliance .
Phishing attacks primarily use URL manipulation and website forgery to deceive victims. In URL manipulation, attackers send an HTML embedded e-mail message that opens a forged website when clicked. In website forgery, attackers copy HTML code from legitimate websites and alter crucial components to trick users into submitting sensitive information like banking credentials, which the attacker then records and uses .
Spear phishing differs from traditional phishing techniques by being more targeted and personalized. Unlike general phishing attacks, which are sent to a large audience, spear phishing involves sending a seemingly legitimate message to a small group or individual, often appearing to be from a trusted source such as an employer or colleague to increase the likelihood of deception .