ITIS 412: Information Security
Chapter 14: Risk Mitigation
Controlling Risk
Risk
A situation that involves exposure to some type of danger
False positive
An event that is considered a risk yet turns out not to be one
False negative
An event that does not appear to be a risk but actually turns out
to be one
2 ITIS 412
Controlling Risk
3 ITIS 412
Controlling Risk
Risk responses:
Transference - makes a third party responsible for the risk
Risk avoidance - involves identifying the risk and making the
decision to not engage in the activity
Mitigation - the attempt to address the risk by making it less
serious
Another response uses the Simple Risk Model
See Table 14-2 on the following slide
4 ITIS 412
Controlling Risk
5 ITIS 412
Privilege Management
Privilege
Subject’s access level over an object, such as a file
Privilege management
Process of assigning and revoking privileges to
objects
Privilege auditing
Periodically reviewing a subject’s privileges over an
object
Objective: determine if subject has the correct
privileges
6 ITIS 412
Privilege Management
7 ITIS 412
Change Management
Change management
Methodology for making modifications and keeping track of
changes
Ensures proper documentation of changes so future changes
have less chance of creating a vulnerability
Involves all types of changes to information systems
Two major types of changes that need proper
documentation
Changes to system architecture
Changes to file or document classification
8 ITIS 412
Change Management
Change management team (CMT)
Body responsible for overseeing the changes
Composed of representatives from all areas of IT, network
security, and upper management
Proposed changes must first be approved by CMT
CMT duties
Review proposed changes
Ensure risk and impact of planned change are understood
Recommend approval, disapproval, deferral, or withdrawal of a
requested change
Communicate proposed and approved changes to coworkers
9 ITIS 412
Information Security Risk Identification
10 ITIS 412
Incident Management
Incident management
Response to an unauthorized incident
Components required to identify, analyze, and contain an
incident
Incident handling
Planning, coordination, communications, and planning
functions needed to resolve incident
Incident management objective
To restore normal operations as quickly as possible with least
impact to business or users
11 ITIS 412
Risk Calculation
Two approaches to risk calculation:
Qualitative risk calculation - uses an “educated guess” based on
observation
Typically assigns a numeric value (1-10) or label (High, Medium, or
Low) that represents the risk
Quantitative risk calculation - attempts to create “hard”
numbers associated with the risk of an element in a system by
using historical data
Can be divided into the likelihood of a risk and the impact of a risk
being successful
12 ITIS 412
Risk Calculation
Risk Likelihood
Several quantitative tools can be used to predict the likelihood
of the risk
Mean Time Between Failure (MTBF)
Mean Time To Recovery (MTTR)
Mean Time To Failure (MTTF)
Failure In Time (FIT)
Historical data can be used to determine the likelihood of a risk
occurring within a year
Known as Annualized Rate of Occurrence (ARO)
13 ITIS 412
Risk Calculation
14 ITIS 412
Risk Calculation
Risk Impact
Comparing the monetary loss associated with an asset in order
to determine the amount of money that would be list if the risk
occurred
Two risk calculation formulas are used to calculate expected
losses:
Single Loss Expectancy (SLE) - expected monetary loss every time a
risk occurs
Annualized Loss Expectancy (ALE) - expected monetary loss that can
be expected for an asset due to risk over a one-year period
15 ITIS 412
Risk Prioritization
Reducing Risk Through Policies
Security policy
A written document that states how an organization plans to
protect the company’s information technology assets
Outlines the protections that should be enacted to ensure the
organization’s assets face minimal risk
Having a written security policy empowers an organization to
take appropriate action to safeguard its data
17 ITIS 412
What Is a Security Policy? (cont’d.)
Security policy functions
An overall intention and direction, formally expressed by the
organization’s management
Details specific risks and how to address them
Provides controls to direct employee behavior
Helps create a security-aware organizational culture
Helps ensure employee behavior is directed and monitored in
compliance with security requirements
18 ITIS 412
Balancing Trust and Control
Three approaches to trust
Trust everyone all of the time
Trust no one at any time
Trust some people some of the time
Security policy attempts to provide right amount of trust
Trust some people some of the time
Builds trust over time
Level of control must also be balanced
Influenced by security needs and organization’s culture
19 ITIS 412
Standard, Guideline , & Policy
Standard - collection of requirements specific to system or
procedure that must be met by everyone
Guideline - collection of suggestions that should be
implemented
Policy - document that outlines specific requirements that
must be met
20 ITIS 412
Designing a Security Policy
Designing a security policy involves:
Defining what a policy is
Understanding the security policy cycle
Knowing the steps in policy development
Characteristics of a policy
Communicates a consensus of judgment
Defines appropriate user behavior
Identifies needed tools and procedures
Provides directives for Human Resource action in response to
inappropriate behavior
Helps if it becomes necessary to prosecute violators
21 ITIS 412
Designing a Security Policy
Three phases of the security policy cycle
Vulnerability assessment
Create the policy using information from risk management
study
Review the policy for compliance
22 ITIS 412
Designing a Security Policy
23 ITIS 412
Designing a Security Policy
Steps in Development
Security policy design should be the work of a team
Development team representatives
Senior level administrator
Member of management who can enforce the policy
Member of the legal staff
Representative from the user community
Team should first decide on policy goals and scope
Also how specific the policy should be
24 ITIS 412
Designing a Security Policy
Due care
Obligations imposed on owners and operators of assets
Owners must exercise reasonable care of assets and take
precautions to protect them
Examples of due care policy statements
Employees should exercise due care in opening attachments
received from unknown sources
Students will exercise due care when using computers in a
crowded lab setting
25 ITIS 412
Designing a Security Policy
Policy development guidelines
Notify users in advance of development of and reasons for a
new security policy
Provide affected users an opportunity to review and comment
on policy prior to deployment
Prior to development, give all users at least two weeks to
review the policy and comment on it
Allow users given responsibility the authority to carry out their
responsibilities
26 ITIS 412
Types of Security Policies
Most organizations have security policies that address:
Acceptable use
Privacy
Data
Security-related human resource
Ethics
Password management and complexity
27 ITIS 412
Types of Security Policies
Acceptable Use Policy (AUP)
Policy that defines actions users may perform while accessing
systems
Users include employees, vendors, contractors, and visitors
Typically covers all computer use
Unacceptable use may also be outlined by the AUP
Generally considered most important information security
policy
28 ITIS 412
Types of Security Policies
Privacy policy
Outlines how organization uses personal information it collects
Data policy
Set of procedures designed to control and manage data by
specifying data collection and storage
Generally involves creating classification categories
Example: Level A or High Risk
Data retention policy - outlines how to maintain information in
the user’s possession for a predetermined length of time
29 ITIS 412
Types of Security Policies
Data policy
Data wiping and disposing policy - Addresses disposal of
confidential resources
Describes how to dispose of equipment, records, and data
Security-related human resource policy
Includes statements about how an employee’s information
technology resources will be addressed
Typically presented at employee orientation session after
employee is hired
30 ITIS 412
Types of Security Policies
Security-related human resource policy (cont’d.)
May include statements regarding due process and/or due
diligence
May include statements regarding actions to be taken when
employee is terminated
Ethics policy
Attempts to establish a culture of openness, trust, and integrity
in business practices
Often contain such topics as executive and employee commitment to
ethics, how to maintain ethical practices, and penalties for unethical
behavior
31 ITIS 412
Types of Security Policies
Password management and complexity policy
Addresses how passwords are created and managed
Reminds users of differences between strong and weak
passwords
32 ITIS 412
Awareness and Training
Providing users with security awareness training
One of the key defenses in information security
Awareness and training topics
Compliance
Secure user practices
Awareness of threats
33 ITIS 412
Compliance
Users should be informed regarding:
Security policy training and procedures
Personally identifiable information
Information classification
Data labeling, handling, and disposal
Compliance with laws, best practices, and standards
34 ITIS 412
User Practices
Awareness and training also involves helping users
understand how their normal practices can impact the
security of the organization
35 ITIS 412
Threat Awareness
Peer-to-peer (P2P) networks
Similar to instant messaging
Users connect directly to each other
Typically used for sharing audio, video, data files
Tempting targets for attackers
Viruses, worms, Trojans, and spyware can be sent using P2P
Most organizations prohibit use of P2P
High risk of infection
Legal consequences
36 ITIS 412
Threat Awareness
Social networking
Grouping individuals based on some sort of affiliation
Can be physical or online
Web sites that facilitate social networking called social
networking sites
Increasingly becoming prime targets of attacks
Reasons social networking sites are popular with attackers
Personal data can be used maliciously
37 ITIS 412
Threat Awareness
Reasons social networking sites are popular with attackers
(cont’d.)
Users may be too trusting
Accepting friends may have unforeseen consequences
Social networking security is lax or confusing
Security tips for using social networking sites
Consider carefully who is accepted as a friend
Show limited friends a reduced version of your profile
Disable options and reopen only as necessary
38 ITIS 412
Threat Awareness
39 ITIS 412
Threat Awareness
40 ITIS 412
Training Techniques
Opportunities for security education and training
When a new employee is hired
After a computer attack has occurred
When an employee promoted
During an annual department retreat
When new user software is installed
When user hardware is upgraded
41 ITIS 412
Training Techniques
Traits of learners impact how people learn
Examples of learning styles
Visual
Auditory
Kinesthetic
Training styles impact how people learn
Role-based training
Involves specialized training that is customized to the specific role
that an employee holds in the organization
42 ITIS 412
Training Techniques
43 ITIS 412
Training Techniques
44 ITIS 412