0% found this document useful (0 votes)
17 views7 pages

Cybersecurity Risk Management Overview

The document outlines the key principles of cybersecurity, focusing on the CIA triad: Confidentiality, Integrity, and Availability, along with the AAA framework of Authentication, Authorization, and Accounting. It discusses risk management, including the identification, assessment, and treatment of risks, as well as the importance of security controls to protect information systems. Additionally, it highlights the roles of various threat actors and the significance of data privacy and security in safeguarding information.

Uploaded by

spyhuman489
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
17 views7 pages

Cybersecurity Risk Management Overview

The document outlines the key principles of cybersecurity, focusing on the CIA triad: Confidentiality, Integrity, and Availability, along with the AAA framework of Authentication, Authorization, and Accounting. It discusses risk management, including the identification, assessment, and treatment of risks, as well as the importance of security controls to protect information systems. Additionally, it highlights the roles of various threat actors and the significance of data privacy and security in safeguarding information.

Uploaded by

spyhuman489
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Certification in Cybersecurity

In the context of security, these are the three main pillars of information security, and they are
often referred to as the CIA triad.
Adequate Security:
Security commensurate with the risk and the magnitude of harm resulting from the loss,
misuse or unauthorized access to or modification of information. Source: OMB Circular
A-130

CIA stands for Confidentiality, Integrity, and Availability.


1. Confidentiality:

Refers to protecting information from unauthorized access “Not


disclosed”.

 Risks:
o Cryptoanalysis
 How to Mitigate:
o Encryption
o Access Control
 Example:
1- Personally Identifiable information (PII)
2- Protected Health Information (PHI)
2. Integrity:

Data are trustworthy, complete, and have not been accidentally altered or
modified by an unauthorized user.

 Risks:
o Malware
o Hacker
 How to Mitigate:
o Hash “‫”داتا مشوهة ملخبطة‬
o Digital Signature
o Access Control
3. Availability:

Data is accessible/ Available when you need it.

 Risks:
o Denial of Service (DOS Attack).
o Disaster.
 How to Mitigate:
o Backup
o Physical Protection
o Redundancy ‫الوفرة في الوصول والبيانات واالتصال‬
o High Availability
 Example:
3- Personally Identifiable information (PII)
4- Protected Health Information (PHI)
In the AAA framework context, these are the three main pillars of Confidentiality.
1. Authentication (Who are you):
- The process of verifying the identity of a user or device.
- The Act of identifying or verifying the eligibility of a station, originator, or individual to
access specific categories of information.
o Authentication Methods
A. Something you Know
 Username.
 Password.
 Security Question.
B. Something you have
 Smartphone.
 Hardware Key.
 Smart Card.
C. Something you are
 Fingerprint.
 Face ID.
 Eye Printer.
2. Authorization (what permission do you have?)

The right or permission that is granted to a system entity to access a system resources.

The process of granting access to resources is based on a:


 user's identity and
 privileges.
o Example:
A. Rolls in the European Union.
 In General Data Protection Regulation (GDPR):
 Privacy.
Non-repudiation (( ‫عدم االنكار‬

The inability to deny taking an action such as creating information, approving information, and
sending or receiving messages.

 Data Privacy: ‫كيفية حماية الداتا بحيث ان توصل لألشخاص الخاصة فيهم وما حد‬
‫ثاني يطلع عليها‬

Defines how data is collected, stored & distributed.

 Data Security: ‫كيفية احمي الداتا من ان تخترق او اشخاص غير مصرح الهم‬
‫يوصلوها‬

Tools, processes & controls are used to safeguard data.

What is Privacy? ‫حق الفرد في ان يتحكم في نشر المعلومات الخاصة فيه لألشخاص الي بشوفهم‬
‫صح‬

It is the right of an individual to control the distribution of information about themselves.

3. Accounting:
The process of tracking who has accessed data and what they have done with it.

In addition to AAA security, there are other important security measures that organizations
can take to protect confidentiality. These include:
A. Data Encryption.
B. Physical Security.
C. Security Policies and Procedures.
Risk Management
What is Information security risk:

Reflect the potential adverse impacts that result from the possibility of unauthorized access, use
disclosure, disruption, modification or destruction of information and/or information system.

Responsible from:

1- Security Administrator.

2- Security Engineer.

Risk Analysis:

I should do this every day and give a report to the manager with the solution/ suggestion’s
solution.

Risk = Impact * Likelihood

Risk Management Terminology


1- Assets (‫)األصول‬.

is something in need of protection. ‫أي شيء له قيمة يحتاج للحماية‬

2- Vulnerability (‫)الثغرات – مواطن االختراق‬.

is a gap or weakness in those protection efforts.

‫هي الثغرات الموجودة في وسيله الحماية الي وفرتها وممكن من خاللها شخص يخترقها‬.

Brute force Attack‫تشفير البيانات مثال ممكن استخدم خاصيه موجودة في كالي لينكس‬
‫اسمها‬

‫ ف بحاول االقي حل الها‬،‫هي التولز بتتوقع كلمه السر الخاصة بالملفات المشفرة‬.

3- Threats (‫)التهديدات‬.

is something or someone that aims to exploit a vulnerability to reduce protection efforts.

)‫هو استغالل هي الثغرة ب أي طريقه والوصول ألها (شغالت غير ملموسة‬.

a. Natural (‫)طبيعية‬. ‫الفياضان والزالزل‬


b. Unintentional (‫)غير مقصودة‬. ‫الملفات التي تصل الى األقسام غير المقصودة‬
c. Intentional (‫)مقصودة‬. ‫االختراقات‬

Risk ‫ هو‬asset ‫ جواه‬Vulnerability ‫ وفي‬Threat

‫المخاطر هو أصول جواها ثغرة وفي الها تهديد‬


 Threat actors in Cyber Security are:

 Insiders (‫)"من داخل الشركة او المنظمة “تهديد داخلي‬.


 Outsider (‫)"من خارج الشركة او المنظمة “تهديد خارجي‬.
 Formal entities that are nonpolitical (such as business competitors and
cybercriminals). ‫المنافسين للشركات من شركات أخرى او الهاكرز‬
 Formal entities that are political (such as terrorists, nation-states, and
hacktivists). ‫حروب اإللكترونية بين الدول زي أوكرانيا وروسيا‬
 Intelligence or information gatherers (could be any of the above). ‫االمن‬
‫القومي الخاص بالدولة‬.
 Technology (such as free-running bots and artificial intelligence , which
could be part of any of the above).
Risk Process

1- Risk Identification: ‫تحديد المخاطر‬


Gather information about all risks. ‫جمع المعلومات عن كل المخاطر‬
2- Risk Assessment: ‫تقييم المخاطر‬
the process of identifying, estimating and prioritizing risks to an organization’s
operations (including its mission, functions, image, and reputation), assets, individuals,
other organizations. ‫تحديد وتقدير وترتيب أولويات المخاطر‬
‫لعمليات المنظمة‬.
‫يجب ارفاق رفع تقرير عن الثغرة مع الحل او اقتراح للحل‬.

* Qualitative risk assessment. * Quantitative risk assessment


(Low, Medium, High). (Numbers).

3- Risk Treatment: ‫معالجة المخاطر‬

The Risk control should be less than Risk value.

 Accept the Risk: ‫تقبل المشكلة وطنشها‬

No action is taken “Ignoring Risks”.

 Avoid the Risk: ‫ ال داعي للمخاطره‬،‫اتجنب المشكلة وال أتوقع حصولها‬

The decision to attempt to eliminate the risk entirely.

 Reduce (Mitigate) the Risk:

Taking Action to prevent

 Transfer or share the Risk:

Passig risk to a third party.

‫احتمالية حدوث الريسك وتأثيره‬

Risk Analysis Definitions:

Residual Risk “Risk Appetite”: = ‫المخاطر التي ليس لها حلول ويجب علي تقبلها‬
2000 $
Security Risk Remaining after Implementation Controls.

Risk Tolerance: ‫المخاطرة الي بضيفها على المخاطرة الي تقبلتها تحسبا ان حدث‬
2500 ‫شيء غير متوقع أكون جاهز‬$

The level of risk an entity is willing to assume to achieve a potential desired.

Control Gap:500$

The amount of protection the control can’t provide

‫ وتكلفه حل المشكلة الي رح اتقبلها‬%50 ‫ لو انا عندي برنامج واحتمالية وقوعه هي‬:‫مثال‬
‫ يعني‬$2000 ‫ بدل‬$25000 ‫ بجي بعمل حسابي مثال على‬$2000 ‫رح تصير غصب عني هي‬
‫ الي هي تحسبا لو صار شي غير متوقع‬$500 ‫في زيادة‬

Security Controls
Security Controls (Counter Masure):

Act as safeguards or countermeasures prescribed for an information system or assets to protect


the CIA of the system and its information. Implementation of security controls is expected to
reduce risk to an acceptable level.

Three types of security controls:


1- Physical Controls:

Common questions

Powered by AI

Risk management in information security involves identifying, assessing, and mitigating risks to protect data and systems. The risk management process includes Risk Identification, where information about all potential risks is gathered; Risk Assessment, which involves identifying, estimating, and prioritizing risks; and Risk Treatment, where actions are taken to mitigate or transfer risks . Residual risks remain even after controls are implemented but must be acceptable or transferred .

Security controls mitigate risk by acting as safeguards for information systems, protecting their confidentiality, integrity, and availability. Types of controls include physical controls (e.g., locks and security guards), administrative controls (e.g., policies and procedures), and technical controls (e.g., encryption and firewalls). These controls work collectively to reduce risks to an acceptable level, as per organizational risk management strategies .

The AAA framework enhances data confidentiality through Authentication, Authorization, and Accounting. Authentication verifies user identity through methods like passwords, security questions, smart devices, and biometrics . Authorization grants access to resources based on user identity and privileges, determining what permissions users have . Accounting tracks data access and usage, ensuring that all actions are recorded .

Risk transference involves shifting the potential impact of a risk to a third party, often through insurance or outsourcing services. In cybersecurity, this can be strategically used to manage risks that exceed an organization's risk appetite or expertise. It allows organizations to focus on core competencies while relying on partners to manage specific risks, ensuring comprehensive protection and financial stability in case of cybersecurity incidents .

Residual risk is the risk remaining after implementation of security controls. Risk appetite reflects the level of risk an organization is willing to accept to achieve its objectives. Organizations manage residual risks by either accepting them within their risk appetite, transferring them to third parties, or finding alternative methods to mitigate them . The control gap indicates the protection limitations of implemented controls .

Authentication methods strengthen information system security by ensuring that only authorized users can access sensitive data. Knowledge-based methods (passwords, security questions) verify user identity by confirming information the user knows . Possession-based methods (smartphones, smart cards) require something the user has, adding a physical barrier . Biometric methods (fingerprints, face ID) confirm identity based on unique physical characteristics, enhancing security through increased difficulty in replication or impersonation .

Encryption effectively mitigates confidentiality risks by rendering data unreadable without proper decryption keys, thereby securing data from unauthorized access during transmission or storage . Access control regulates who can view or use resources, ensuring only users with the appropriate credentials can access sensitive information. Together, these methods significantly enhance the security of confidential data against unauthorized access and data breaches .

The CIA triad in cybersecurity refers to Confidentiality, Integrity, and Availability. Confidentiality involves protecting information from unauthorized access, with risks such as cryptoanalysis, which can be mitigated through encryption and access control . Integrity ensures data is trustworthy and complete, with risks from malware and hackers, mitigated through hashing, digital signatures, and access control . Availability ensures data is accessible when needed, facing risks from Denial of Service (DoS) attacks and disasters, which can be mitigated through backups, physical protection, and redundancy .

Risk identification and assessment form the foundation of an organization's cybersecurity posture by determining the potential vulnerabilities and threats the organization faces. Accurate identification and assessment facilitate the prioritization of risks based on their potential impact and likelihood, allowing organizations to allocate resources effectively to mitigate the most critical risks. This systematic approach ensures continuous improvement in security measures and resilience against cyber threats .

Threat actors in cybersecurity include insiders who pose internal threats, outsiders or external threats, and formal entities like business competitors and cybercriminals motivated by financial gain . Political entities such as terrorists and nation-states engage in cyber warfare motivated by political objectives. Intelligence gatherers seek information, which can include any class of actors, while technology like bots and AI can autonomously pose threats .

You might also like