GSFC UNIVERSITY
FUNDAMENTAL OF CYBER SECURITY BTCS407
SEMESTER IV
Unit # 2 Cyber Security Concepts
1) Cyber Security Risk, Common Attack Types and Vectors
2) Cyber Security Control
3) Policies and Procedures
4) Digital Forensics
5) Investigation, Legal Holds and Preservation
6) Disaster Recovery and Business Continuity
2
1. Cyber Security Risk, Attacks and Vectors
Cybersecurity risk is the probability of exposure or loss resulting
from a cyber attack or data breach on your organization. A
better, more encompassing definition is the potential loss or
harm related to technical infrastructure, use of technology or
reputation of an organization
Organizations are becoming more vulnerable to cyber
threats due to the increasing reliance on computers, networks,
programs, social media and data globally. Data breaches, a
common cyber attack, have massive negative business impact
and often arise from insufficiently protected data
ow computers or networks communicate witother. 3
Cyber Security Risk, Attacks and Vectors Continues…
What are the Key Cyber Risks and Security Threats?
Cybersecurity is relevant to all systems that support an
organization's business operations and objectives, as well as
compliance with regulations and laws. An organization will
typically design and implement cybersecurity controls across the
entity to protect the integrity, confidentiality and availability of
information assets
Cyberattacks are committed for a variety of reasons including
financial fraud, information theft, activist causes, to deny
service, disrupt critical infrastructure and vital services of
government or an organization 4
Cyber Security Risk, Attacks and Vectors Continues…..
The six common types of risks:
Nation states
Cyber criminals
Hacktivists
Insiders and service providers
Developers of substandard products and services
Poor configuration of cloud services like S3 buckets
Common cybersecurity threats in terms of cyber attacks include:
Phishing attacks
Social engineering attacks
Ransomware
DDoS attacks 5
Denial-of-Service attacks
Cyber Security Risk, Attacks and Vectors Continues…..
Who Should Own Cybersecurity Risk in My Organization?
Cybersecurity risk management is generally set by leadership, often including an
organization's board of directors in the planning processes. Best-in-class organizations
will also have a Chief Information Security Officer (CISO) who is directly responsible for
establishing and maintaining the enterprise vision, strategy and program to ensure
information assets and customer data is adequately protected.
Common Cyber Defense activities that a CISO will own include:
Administering security procedures, training and testing
Maintaining secure device configurations, up-to-date software, and vulnerability
patches
Deployment of intrusion detection systems and penetration testing
Configuration of secure networks that can manage and protect business networks
Deployment of data protection and loss prevention programs and monitoring
Restriction of access to least required privilege
Encryption of data where necessary 6
Proper configuration of cloud services
Cyber Security Risk, Attacks and Vectors Continues…..
The Difference Between an Attack Vector, Attack Surface and
Threat Vector
An attack vector is a method of gaining unauthorized
access to a network or computer system
An attack surface is the total number of attack vectors an
attacker can use to manipulate a network or computer
system or extract data
Threat vector can be used interchangeably with attack
vector and generally describes the potential ways a hacker
can gain access to data or other confidential information
7
Cyber Security Risk, Attacks and Vectors Continues…..
Common Attack Vector Examples
1. Compromised Credentials: Usernames and passwords are still the most
common type of access credential and continue to be exposed in data
leaks, phishing scams, and malware. When lost, stolen, or exposed, credentials
give attackers unfettered access. This is why organizations are now investing
in tools to continuously monitor for data exposures and leaked credentials.
Password managers, two-factor authentication (2FA), multi-factor
authentication (MFA), and biometrics can reduce the risk of leak credentials
resulting in a security incident too
2. Weak Credentials: Weak passwords and reused passwords mean one data
breach can result in many more. Teach your organization how to create a
secure password, invest in a password manager or a single sign-on tool, and
educate staff on their benefits
3. Insider Threats: Disgruntled employees or malicious insiders can expose
private information or provide information about
company-specific vulnerabilities
8
Cyber Security Risk, Attacks and Vectors Continues…..
4. Missing or Poor Encryption: Common data encryption methods
like SSL certificates prevent man-in-the-middle attacks and protect the
confidentiality of data being transmitted
5. Misconfiguration: Misconfiguration of cloud services, like Google
Cloud Platform, Microsoft Azure, or AWS, or using default credentials
can lead to data breaches and data leaks, check your S3 permissions or
someone else will. Automate configuration management where possible
to prevent configuration drift.
6. Ransomware: Ransomware is a form of extortion where data is
deleted or encrypted unless a ransom is paid, such as WannaCry.
Minimize the impact of ransomware attacks by maintaining a defense
plan, including keeping your systems patched and backing up important
data.
Track supply chain risks with this free pandemic questionnaire template
9
mputers or networks communicate witother.
Cyber Security Risk, Attacks and Vectors Continues…..
7. Phishing: Phishing attacks are social engineering attacks where
the target is contacted by email, telephone, or text message by
someone who is posing to be a legitimate colleague or institution to
trick them into providing sensitive data, credentials, or personally
identifiable information (PII). Fake messages can send users to
malicious websites with viruses or malware payloads
10
2. Cyber Security Control
What is Cyber Security Control?
The controls are created to ensure the CIA triad i.e. confidentiality,
integrity, and availability of an organization’s information and
technology assets. And controls revolve around four essentials of
people, technology, processes, and strategy
Cyber security control is a mechanism that is used to prevent,
detect and reduce cyber-attacks and threats. Cyber security
controls are every organization's need, as it is used to manage the
security program of a company/organization
Cyber security is the top priority of organizations, where they
determine what control, they need
11
Cyber Security Control
Continues…
• Types of Cyber Security Controls:
The essential cyber security
controls are divided into three
types, technical, administrative,
and physical. The main goal of
implementing security control is
preventative, detective,
corrective, compensatory, or
deterrent
12
Cyber Security Control Continues…….
Technical Controls: Technical controls are also known as logical controls. That is
used to reduce attacks on both hardware and software. And automated software
tools are installed to protect the system.
Encryption
Antivirus and anti-malware software
Firewalls
Security information and event management (SIEM)
Instruction Detection Systems (IDS) and Intrusion Prevention Systems (IPS)
Technical control is implemented using two methods
Access Control Lists (ACL): ACL is a network traffic filter that controls incoming
and outgoing traffic. They are commonly used in routers or firewalls, but they
can also be programmed in any device that runs on the network, from hosts to
servers
Configuration Rules: It is a set of instructional codes used to guide the execution
13
of the system when information is passed through it
Cyber Security Control Continues……
Administrative controls: Administrative security controls refer to policies, procedures, and guidelines
that define the roles or business practices of an organization's security goals
To implement administrative controls, additional security controls are necessary for monitoring and
enforcement. The controls used to monitor and enforce them are as follows,
Management controls: This control is used to mainly focus on risk management and information
security management.
Operational controls: The security controls that are primarily implemented, like technical and
managerial controls executed by people, are saved by operational controls.
Physical controls: Physical security controls in cyber security are implemented based on cyber
measures in a defined structure. That is used to detect or prevent unauthorized access to sensitive
data.
Closed-circuit surveillance cameras
Motion or thermal alarm systems
Security guards and picture IDs
Locked and dead-bolted steel doors
Biometrics 14
Cyber Security Control Continues……
Preventative controls
These controls are used to prevent loss or errors. Examples of preventative
controls are:
Hardening: It’s a process of reducing attacks and tightening security controls
Security awareness training is the process of providing formal cyber security
education to employees and stakeholders about security threats and the
organization's policies and procedures
Change management: Measures taken by an organization to describe and
implement changes both internally and externally in the system that include
preparing and supporting employees to take the necessary steps for change
Account disable policy: This policy will disable the account when an
employee leaves the organization
15
Cyber Security Continues…
Detective controls
It is an accounting term, that uses internal control to find errors within the
organization. Examples of detective controls are as follows:
Log monitoring – analyzing real-time data
SIEM- A set of tools and services are offered to analyze various system
operational logs
Trend Analysis – Identifying the pattern from an application’s log output, to
gather relevant information
Security Audits- set of measures that focus on cyber security standards and
guidelines
Video Surveillance - Digital images and videos that are sent over
communication networks are monitored
Motion Detection – Sensors are attached to detect nearby motions 16
Cyber Security Control Continues…..
Corrective controls
After a system malfunction, corrective controls are used to make the system
more effective to use. Examples of corrective controls include,
IPS: detection of anomalies in traffic flow to quickly prevent malicious activity.
Backups and system recovery: the Process of creating and storing data copies
that can be used as backups when data is lost.
Deterrent controls
Deterrent controls are used to reduce deliberate attacks, which are usually in the
form of a tangible object or person. Examples of deterrent controls include
Cable locks
Hardware locks
Video surveillance and guards
17
Cyber Security Control Continues…
Compensating controls
Compensating control is an alternative method that is used to satisfy
the requirement for security. And certain security measures can’t be
implemented due to financial or simple impractical reasons at the
time
Example of Compensating control:
Time-based OTP- One of the best examples for compensating control
is OTP, i.e., One-time password, where a code is generated by an
algorithm that uses the current time of day as one of its
authentication factors
18
Cyber Security
Investigation
Cyber crime investigations play a
vital role in the modern world,
addressing emerging threats and
helping to maintain the safety of
our digital spaces
They encompass the identification,
examination, and legal action
against a broad spectrum of illicit
activities in the digital sphere,
including Hacking
19
Cyber Security Investigation Continues….
What are the two types of cyber investigations?
The two general categories of cyber investigations are digital forensics and
open-source intelligence. Cyber investigations are affecting more than just
the investigators. They must determine what tools they need to use based
on the information that the tools provide and how effectively the tools
and methods work
Digital forensics is a branch of forensic science that focuses on identifying,
acquiring, processing, analyzing, and reporting on data stored
electronically. Electronic evidence is a component of almost all criminal
activities and digital forensics support is crucial for law enforcement
investigations
Open-source intelligence (OSINT) is the insight gained from processing
and analyzing public data sources such as broadcast TV and radio, social
media, and websites. These sources provide data in text, video, image, and
audio formats
20
Cyber Security Investigation Continues…
DF Consists of 5 Key Elements:
Identification of evidence: It includes of identifying evidences related to the digital
crime in storage media, hardware, operating system, network and/or applications. It
is the most important and basic step
Collection: It includes preserving the digital evidences identified in the first step so
that they doesn’t degrade to vanish with time. Preserving the digital evidences is
very important and crucial
Analysis: It includes analyzing the collected digital evidences of the committed
computer crime in order to trace the criminal and possible path used to breach into
the system
Documentation: It includes the proper documentation of the whole digital
investigation, digital evidences, loopholes of the attacked system etc. so that the
case can be studied and analyzed in future also and can be presented in the court in
a proper format
Presentation: It includes the presentation of all the digital evidences and
documentation in the court in order to prove the digital crime committed and
identify the criminal 21
Cyber Security Investigation Continues…
Branches of Digital Forensics:
Media forensics: It is the branch of digital forensics which includes
identification, collection, analysis and presentation of audio, video and
image evidences during the investigation process
Cyber forensics: It is the branch of digital forensics which includes
identification, collection, analysis and presentation of digital evidences
during the investigation of a cyber crime
Mobile forensics: It is the branch of digital forensics which includes
identification, collection, analysis and presentation of digital evidences
during the investigation of a crime committed through a mobile device like
mobile phones, GPS device, tablet, laptop
Software forensics: It is the branch of digital forensics which includes
identification, collection, analysis and presentation of digital evidences
during the investigation of a crime related to software's only
22
Why Digital Forensics is Important?
The purpose of digital forensics is to identify and preserve the digital evidence
in its most-purest form, to make it possible for relevant investigation
procedures to be performed and conclusions made
For corporates and businesses, digital forensics is a very important part
related to the incident response process. The digital evidence gathered from
electronic devices may be asked to be presented in a court of law. Therefore,
organizations or businesses perform forensics reviews diligently and with the
required care
Specialists possess expertise in performing forensics investigations to
conclude criminal or cybercrime incidents. They are experienced in searching
and gathering digital evidence, considering the technical flow of data and
digital footprints stored or recorded in electronic or digital devices
Cyber Security- Legal Hold
A legal or litigation hold is a part of the eDiscovery process by which an organization
is required to preserve potentially relevant information. When a legal hold is issued,
the organization has to notify the custodians about what they are supposed to do
and not do
Legal Hold Process:
Identification of Information to be preserved: The first step of implementing a
litigation hold is determining the potentially relevant information. Depending on
the case, it might be a mix of electronically stored information (ESI) and physical
documents
Identification of custodians: Custodians are the individuals who possess the
relevant information and are in charge of preserving it. Legal and IT teams need
to work together to identify every single custodian relevant to the matter at
hand. This also includes identifying “silent custodians,” whose data is preserved
without their knowledge.
24
Legal Hold Continues…
Legal Hold Notice Issuance: Once the relevant information and custodians
have been identified, a notification will be sent to the custodians informing
them about the legal hold. The notice will also specify the information that
must be preserved
Reminder Notices: Reminders must be sent to the custodians to make sure
that they remember the legal hold. These notices can also be used as a way
for the custodians to acknowledge their obligations
Legal Hold Release: This is the last step, where the custodians are notified
that they are no longer required to preserve the data. It is of paramount
importance to ensure a robust release process, to avoid a custodian being
released from their obligation when they shouldn’t
25
1. Policy, Procedure, Standard and Guideline
Information Security Policies are high-level business rules that the
organization agrees to follow that reduce risk and protect information. They
define “what” the organization is going to do and often “who” is going to do it
Information Security Standards provide more specific details that enable
policies to be implemented within the organization using different
technologies. For example, an Information Disposal Standard would define
how various type of media are destroyed to implement a policy. ex ISO
27001, Payment Card Industry PCI DSS 3.2, Privacy etc.
Procedure provides detailed mandatory steps someone needs to follow to
achieve a recurring task or comply with a policy
Guideline provides general guidance, and additional advice and support for
policies, standards or procedures 26
Policy, Procedure, Standard and Guideline Continue…
27
BC and DR
Business continuity focuses on keeping business
operational during a disaster, while disaster
recovery focuses on restoring data access and
IT infrastructure after a disaster
Business Continuity Planning (BCP) and Disaster
Recovery Planning (DRP) are an organization's
last corrective control when all other controls
have failed! BCP/DRP may prevent or provide a
remedy for force majeure circumstances such
as injury, loss of life, or failure of an entire
organization
BC AND DR Continues…
29
BC PLAN
Business continuity planning goes beyond the technology component. It
involves many short-term and long-term processes, such as the response,
recovery, resumption, and maintenance of the entire organization.
There are eight general steps involved in creating a business continuity plan:
Identifying the scope of the plan
Identifying key business areas
Identifying critical functions
Identifying dependencies between various business areas and functions
Determining acceptable downtime for each critical function
Creating a plan to maintain operations
Testing your Business Continuity Plan
Reviewing and improving your Business Continuity Plan 30
DR PLAN
A Disaster Recovery Plan contains detailed instructions on how to respond to
unplanned incidents and is more thorough than a business continuity plan.
There are seven steps involved in creating a disaster recovery plan:
Creating a DR response team
Identifying critical operations and setting goals
Evaluating potential disaster scenarios
Creating a communication plan
Establishing roles and responsibilities
Developing a data backup and recovery plan
Testing your plan
Reviewing and updating your plan
31
BENEFITS B C AND D R
Identifying weaknesses and preventing risks, where possible
Preparing for risks and unforeseen events that you cannot control
Mitigating financial risks
Protecting team members
Improving last-minute decisions
Increasing employee productivity
Maintaining high-quality services regardless of the event
Reducing the risk of human errors
Increasing confidence of investors and customers 32