Cybersecurity Management
Introduction
Lecture 1
References and Course Format
Class code
● -
BOOKs:
● Michael Whitman, Herbert Mattord Cengage, Management of Information Security,
● Michael Whitman, Herbert Mattord, Principles of Information Security
Exam Format:
● Coursework(Technical Report) = 50%
○ Research-based technical report (about 2500 words)
○ After 3rd lecture
● Written Exam = 50%
○ Final Exam
2
Course Timeline
3
Syllabus Outline
● Introduction to Cybersecurity
● Risk Identification and Risk Assessment
● Risk Management and Risk Control
● Security Policy, Standard, and Practices
● Contingency Planning
● Protection Mechanisms
● Legal, Ethical and Professional Issues
● IT Security Audit
● Information Security Implementation and Maintenance (SecOps)
4
History
5
History
6
Top Threats
7
Attack Surface
● Attacks are prolific because of increasing attack surface
○ All the vulnerabilities or weaknesses in the security controls that an attacker could exploit
○ Attack vectors used by the threat actors to gain unauthorized access to confidential data and
carry out cyberattacks.
○ For example, security gaps in IoT and smart devices, mobile devices, home network, data
centers, supply chain, etc.
8
Any action or inaction that could cause
damage, destruction, loss, or of assets
Organizational Assets
● IP
● Data
● Human (knowledge, Skills, Abilities) Weakness, flaw, loophole, oversight,
● Brand error, limitation, frailty, or susceptibility
● Goodwill
Security Controls Being susceptible to asset loss
● Firewall because of a threat
● IDS/IPS
● Auditing
● Data classification
● Separation of duties
Likelihood that a threat will exploit a
9
vulnerability
10
Cybersecurity Management - Why?
● The cyber-attack has transformed into a global economic, political, and
technical warfare.
● Attackers continuously evolve and develop sophisticated attack tactics,
techniques, and procedures (TTPs).
● The most advanced attack can swiftly compromise the whole network in just a
few hours (Ryuk ransomware 2 hours after the initial access).
● Massive ransomware attacks, big-game hunting, widespread data breaches,
critical vulnerabilities, etc. are now a part of daily news headlines.
● Looking at the trend, the future of cyber attack might take a different turn with
the use of machine learning based approaches.
11
Actors Posing Risk to Business
● Cyber criminals interested in making money through fraud or from the sale of
valuable information
● Industrial competitors and foreign state actors interested in gaining an
economic advantage for their own companies or countries
○ APT interested in gathering military and national intelligence information
● hackers who find interfering with computer systems an enjoyable challenge
● hacktivists who wish to attack companies for political or ideological motives
● employees, or those who have legitimate access, either by accident or
deliberate misuse.
12
13
But...
● Management, at most organizations, still believes that InfoSec is a relatively
unimportant issue, not worthy of considerable top management attention.
● Top management so often doesn’t appreciate how doing a good job in the
information security realm will lead to a variety of tangible business benefits,
like increased sales and competitive advantage.
○ If being able to double the level of sales isn’t important to top management, what is?
14
The Impact of Cyber Attack?
● Reputational damage, financial loss, loss of customers, drop of stocks and
profits, loss of sales.
○ Sensitive customer information, intellectual property, and even the control of key machinery
are increasingly at risk from cyber attack.
15
Warren Buffet rightly said,
“It takes 20 years to build a reputation and five minutes to ruin it. If you think about
that, you will do things differently.”
16
So...
● Put cyber security on the agenda before it becomes the agenda
● Incorporate cyber risks into existing risk management and governance
processes
● Elevate cyber risk management discussions to the Executive and Board,
where its consideration and mitigation can be commensurate with the risk
posed.
● The traditional approach to thinking about cyber security in terms of building
bigger walls (firewalls and antivirus software) - while still necessary - is no
longer sufficient.
○ A holistic approach to cyber security risk management – across the organisation, its network,
supply chains and the larger ecosystem – is required.
17
Introduction
● Business operations are enabled by technology
○ boardroom to the mailroom, businesses make deals, ship goods, track client accounts, and
inventory company assets
● But as business place is no longer static, technology alone cannot protect
business
○ Business moves whenever employees travel from office to office, from city to city, or even from
office to home.
● Computer security has evolved to information security (cyber security)
○ Covers a broader range of issues, from protection of data to protection of human resources.
● Information security is no longer an IT problem, but the responsibility of all
employees, especially managers.
○ There are no security risks. There are only business risks.
■ Steve Katz - known as world’s first ciso
18
InfoSec Communities
● Information security involves more than just technical managers.
● Altogether, three communities of interest:
○ Managers and professionals in the field of information security
■ Information security community protects information assets from threats (CISO)
○ Managers and professionals in the field of IT
■ Information technology community supports business objectives by supplying and
supporting IT appropriate to the organization’s needs. CTO, IT head
○ Managers and professionals from the rest of the organization (non-technical)
■ General business community articulates and communicates organizational policy and
objectives and allocates resources to the other groups. Top Management, PM,
Department Heads
● They engage in constructive debate to reach consensus on an overall plan to
secure an organization’s information assets most effectively
19
What is Security?
● Security is the quality or state of being secure—being free from danger.
○ be protected from the risk of loss, damage, or unwanted modification, or other hazards.
● Security is achieved using several strategies simultaneously
○ implementation of a multilayered system
○ Defense in depth, data abstraction, data hiding (security through obscurity), encryption,
● It is the role of management to ensure that each strategy is properly planned,
organized, staffed, directed, and controlled.
20
Defense in depth
21
Specialized Area of Security
● Physical security – strategies to protect people, physical assets, and the workplace
from fire, unauthorized access, and natural disasters.
○ Biometrics, Fence, CCTV, Fire Extinguisher
● Personal security – protection of the people within the organization.
○ Evacuation plan, Floor Warden
● Operations security – ensuring business to run without interruption or compromise.
○ BCP and DRP plan
● Communications security – protection of communications media, technology, and
content, and its ability to use these tools to achieve the organization’s objectives.
○ Encryption
● Network security – the protection of an organization’s data networking devices,
connections, and contest, and the ability to use that network to accomplish the
organization’s data communication functions.
○ Firewall, IPS/IDS, DMZ
● Information Security (InfoSec)
22
Information Security
● It is the protection of information and its critical characteristics (confidentiality,
integrity, and availability), including the systems and hardware that use, store,
and transmit that information, through the application of policy, training and
awareness programs, and technology.
● InfoSec includes information security
management, computer security, data security,
and network security
○ Policy is central to all information security
efforts.
23
CIA
● Confidentiality: Prevent or minimize unauthorized access to data while in
storage, in process, and in transit.
○ Privacy: Information that is collected, used, and stored by an organization should be used only
for the purposes stated by the data owner at the time it was collected.
○ Many organizations collect, swap, and sell personal information as a commodity.
● Integrity: The quality or state of being whole, complete, and uncorrupted.
● Availability: Authorized subjects granted timely and uninterrupted access to
objects.
24
IAAA
● Identification: when an information system is able to recognize individual
users. It is the first step in gaining access to secured information or areas.
○ Providing username, swiping a card, presenting biometrics scan
● Authentication: where a user provides proof that he or she is who he or she
really is.
● Authorization: the assurance that the user or the computer has been
authorized to be granted access to specific information.
○ System evaluates an ACL that compares subject, object, and intended activity
● Accountability: when a control provides assurance that all activities can be
linked or attributed to a certain person or a process.
○ Password sharing?
● Non-repudiation: the assurance that someone cannot deny the validity of
something.
25
Confidentiality
Attack Events Countermeasure
● Capturing network traffic ● Failing to properly encrypt a transmission ● Encryption
● Stealing password files ● Failing to fully authenticate a remote system ● Network traffic padding
● Social engineering before transferring data ● Strict access control
techniques ● Leaving open otherwise secured access points ● Rigorous authentication
● Port scanning ● Accessing malicious code that opens a procedures
● Eavesdropping backdoor ● Data classification
● Sniffing ● Misrouted faxes ● Application of security
● Escalation of privileges ● Documents left on printers policies
● Walking away from an access terminal while ● Extensive personnel
data is displayed on monitor training
26
Confidentiality - Concepts, Conditions, and Aspects
● Sensitivity refers to the quality of information, which could cause harm or damage if
disclosed. For example: zero-day with PoC code.
● Discretion is an act of decision where an operator can influence or control disclosure in
order to minimize harm or damage.
● Criticality The level to which information is mission critical is its measure of criticality.
○ Trade secret, military intelligence, etc.
● Concealment is the act of hiding or preventing disclosure. (Security through obscurity)
● Secrecy is the act of keeping something a secret or preventing the disclosure of
information.
● Privacy refers to keeping information confidential that is personally identifiable or that might
cause harm, embarrassment, or disgrace to someone if revealed.
● Seclusion involves storing something in an out-of-the-way location.
○ This location can also provide strict access controls.
○ Seclusion can help enforcement of confidentiality protections.
● Isolation is the act of keeping something separated from others.
○ Isolation can be used to prevent commingling of information or disclosure of information
27
Integrity
● Integrity is protecting the reliability and correctness of data.
○ Prevents unauthorized alterations of data. Ensures data remains correct, unaltered, and preserved.
● Integrity can be examined as:
○ Preventing unauthorized subjects from making modifications
○ Preventing authorized subjects from making unauthorized modifications, such as mistakes
Attack Events Countermeasure
● Viruses ● Corruption can occur while ● Strict access control
● logic bombs information is being compiled, ● Rigorous authentication procedure
● Unauthorized access stored, or transmitted ● Intrusion detection systems
● Errors in coding and ● Faulty programming ● Object/data encryption
applications ● Noise in transmission channel ● Hash total verifications
● Malicious modification ● Interface restrictions
● Intentional replacement ● Input/function checks
● System backdoor ● Extensive personnel training
28
Integrity - Concepts, Conditions, and Aspects
● Accuracy: Being correct and precise
● Truthfulness: Being a true reflection of reality
● Authenticity: Being authentic or genuine
● Nonrepudiation: Not being able to deny having performed an action or activity or
being able to verify the origin of a communication or event
● Accountability: Being responsible or obligated for actions and results
● Responsibility: Being in charge or having control over something or someone
○ Data custodian is responsible to protect the asset
● Validity: Being factually or logically sound
○ guarantees that all false information is excluded
● Completeness: Having all needed and necessary components or parts
○ guarantees that all true information is included
● Comprehensiveness: Being complete in scope; full inclusion of needed elements
○ Ensures that the entire scope of the data is collected with intentional limitations documented
29
Availability
● Availability means authorized subjects are granted timely and uninterrupted access to objects.
● Availability protection controls support sufficient bandwidth and timeliness of processing as deemed
necessary by the organization or situation.
● If a security mechanism offers availability, it offers a high level of assurance that the data, objects, and
resources are accessible to authorized subjects.
● Availability includes efficient uninterrupted access to objects and prevention of denial-of-service (DoS)
attacks.
Attack Events Countermeasure
● DoS attacks ● Accidentally deleting files ● Using access controls effectively
● Object destruction and ● Over-utilizing a hardware or ● Monitoring performance and network traffic
● Communication software component ● Using firewalls and routers to prevent DoS
interruptions ● Under- allocating resources attacks
● Mislabeling or incorrectly ● Implementing redundancy for critical systems
classifying objects ● Maintaining and testing backup systems
30
Availability
● Availability depends on both integrity and confidentiality.
○ Without integrity and confidentiality, availability cannot be maintained.
● Usability: The state of being easy to use or learn or being able to be understood and
controlled by a subject
● Accessibility: The assurance that the widest range of subjects can interact with a resource
regardless of their capabilities or limitations
● Timeliness: Being prompt, on time, within a reasonable time frame, or providing low-latency
response
31
CIA
● Availability ● Integrity
○ Redundant array of inexpensive disks ○ Hashing (data integrity)
(RAID) ○ Configuration management (system
○ Clustering integrity)
○ Loadbalancing ○ Change control (process integrity)
○ Redundant data and power lines ○ Access control (physical and technical)
○ Software and data backups ○ Software digital signing
○ Disk shadowing ○ Transmission CRC functions
○ Co-location and off-site facilities ● Confidentiality
○ Roll-back functions ○ Encryption for data at rest (whole disk,
○ Fail-over configurations database encryption)
○ Encryption for data in transit (IPSec, SSL,
PPTP, SSH)
○ Access control (physical and technical)
CNSS Security Model (McCumber cube)
● CNSS (Committee on National Security Systems)
● Shows the three dimensions that are central to the discussion of InfoSec
○ information characteristics, information location, and security control categories.
● Main purpose of the model is to identify gaps in the coverage of an InfoSec program.
s
re
su
ea
m
Security Goals
er
nt
ou
C
Information States 33
What is Management?
● Management is the process of achieving objectives using a given set of
resources.
● A manager is a member of the organization assigned to marshal and
administer resources, coordinate the completion of tasks, and handle the
many roles necessary to complete the desired objectives.
● Managers have many roles to play within organizations, including the
following:
○ Informational role—Collecting, processing, and using information that can affect the
completion of the objective
○ Interpersonal role—Interacting with superiors, subordinates, outside stakeholders, and other
parties that influence or are influenced by the completion of the task
○ Decisional role—Selecting from among alternative approaches and resolving conflicts,
dilemmas, or challenges
34
Leaders Vs Managers
35
Leaders Vs Managers
● A leader influences employees so that they are willing to accomplish
objectives.
○ Lead by example and demonstrate personal traits that instill a desire in others to follow.
○ Leadership provides purpose, direction, and motivation to those who follow.
○ Autocratic: “do as i say”
○ Democratic: seek input from all interested parties
○ Laissez-faire: allows the process to develop as it goes, only making minimal decisions to avoid
bringing the process to a complete halt.
● A manager administers the resources of the
organization.
○ Creates budgets, authorizes expenditures, and hires
employees.
○ Effective managers are also effective leaders.
36
37
Boss vs Leaders
[Link]
38
39
Popular Management Theory (POLC)
40
POLC - Planning
● The process that develops, creates, and implements strategies for the
accomplishment of objectives.
○ Strategic Plan long-term fairly stable plan that defines the organization’s purpose.
■ Useful for five years if maintained and updated annually.
○ Tactical Plan mid-term plan to provide details on accomplishing the goals set forth in the
strategic plan
■ Typically useful for about a year.
■ Examples: project plans, acquisition plans, hiring plans, budget plans, maintenance
plans, support plans, and system development plans.
○ Operational Plan short-term, highly detailed plan based on the strategic and tactical plans.
■ Resource allotments, budgetary requirements, staffing assignments, scheduling, and
step-by-step or implementation procedures.
■ Examples: training plans, system deployment plans, and product design plans.
41
POLC - Organizing, Leading, Controlling
● Organizing: structuring of resources to support accomplishment of objectives
○ Determine: What is to be done, In what order, By whom, By which methods, When
○ Eg.: structuring departments and staffs, the storage of raw materials, collection of information
to aid in the accomplishment of the task, and organize people to maximize productivity
● Leading: the implementation of the planning and organizing functions
○ It includes supervising employee behavior, performance, attendance, and attitude while
ensuring completion of the assigned tasks, goals, and objectives.
○ Leadership generally addresses the direction and motivation of the human resource.
● Controlling: monitoring progress toward completion and making necessary
adjustments to achieve desired objectives require the exercise of control
○ It ensures the validity of the organization’s plan, sufficient progress is made, impediments to
the completion of the task are resolved, and that no additional resources are required.
○ Should the plan be found invalid, the manager takes corrective action.
42
POLC - Control Tools
● Economic—Comparing the costs and benefits of a possible solution with other
possible solutions.
● Technological—Assessing the organization’s ability to acquire the technology
needed to implement a particular solution.
● Behavioral—Assessing the likelihood that subordinates will adopt and support
a particular solution rather than resist it.
● Operational—Assessing the organization’s ability to integrate a particular
solution into its current business processes.
43
POLC - Control Process
●
44
Information Security Management
● InfoSec management team is focused on the secure operation of the
organization
○ ensure the confidentiality, integrity, and availability of information
○ Their goals and objectives differ from those of the IT and general management communities
● IT Group: The primary focus of the IT group is to ensure the effective and
efficient processing of information
● Conflict
○ Almost 93% of CISOs reports directly to CIO.
○ Reporting to CIO, who is responsible for the IT function, confines cybersecurity to IT function.
○ So, issues and prioritization conflicts can arise unless upper-management intervenes.
45
Characteristics of Information Security Management
● Planning – activities that are important in supporting design, creation, and
implementation of information security strategies within the IT panning
environment.
● Several types of InfoSec plans exist:
○ Incident response
○ Business continuity
○ Disaster recovery
○ Policy
○ Personnel
○ Technology rollout
○ Risk management
○ Security program including education, training, and awareness
46
Characteristics of Information Security Management
● Policy – A set of organizational guidelines that dictates certain behavior within
the organization. Three types of policy are:
○ General program policy – sets the tone for the InfoSec department and the InfoSec climate
across the organization.
○ An issue-specific security policy (ISSP) is a set of rules that defines acceptable behavior within
a special technology
■ email or Internet usage.
○ System-specific policy (SSSPs) are technical in nature and control the use of a piece of
equipment or technology.
■ Standards or procedures/checklist used for configuring or maintaining systems
47
Characteristics of Information Security Management
● Programs – the operations carry out within InfoSec. Policy is broken down
into programs for implementation
○ Security Education and Training Awareness, a physical security program, physical access,
gates, guards, and so on
● Protection – is executed via a set of risk management activities. Finding
weakness and strength. Such as risk assessment and control, protection
mechanisms, technologies, and tools. (Red team vs Blue team)
● People – the most critical link and important part in the information security
program.
● Project Management – identifying and controlling the resources applied to the
project, measuring progress and adjusting the process as progress is made
toward the goal.
48