0% found this document useful (0 votes)
14 views44 pages

Risk Mitigation in Information Security

The document discusses various topics relating to information security risk mitigation as covered in Chapter 14, including: 1) Defining risk, false positives, and false negatives. It also discusses common risk responses like transference, avoidance, and mitigation. 2) Covering the basics of privilege management, including defining privileges, privilege management, and privilege auditing. 3) Describing change management methodology, the roles of a change management team, and types of changes that require documentation like system architecture changes and document classification changes.

Uploaded by

marya
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
14 views44 pages

Risk Mitigation in Information Security

The document discusses various topics relating to information security risk mitigation as covered in Chapter 14, including: 1) Defining risk, false positives, and false negatives. It also discusses common risk responses like transference, avoidance, and mitigation. 2) Covering the basics of privilege management, including defining privileges, privilege management, and privilege auditing. 3) Describing change management methodology, the roles of a change management team, and types of changes that require documentation like system architecture changes and document classification changes.

Uploaded by

marya
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

ITIS 412: Information Security

Chapter 14: Risk Mitigation


Controlling Risk
 Risk
 A situation that involves exposure to some type of danger
 False positive
 An event that is considered a risk yet turns out not to be one
 False negative
 An event that does not appear to be a risk but actually turns out
to be one

2 ITIS 412
Controlling Risk

3 ITIS 412
Controlling Risk
 Risk responses:
 Transference - makes a third party responsible for the risk
 Risk avoidance - involves identifying the risk and making the
decision to not engage in the activity
 Mitigation - the attempt to address the risk by making it less
serious
 Another response uses the Simple Risk Model
 See Table 14-2 on the following slide

4 ITIS 412
Controlling Risk

5 ITIS 412
Privilege Management
 Privilege
 Subject’s access level over an object, such as a file
 Privilege management
 Process of assigning and revoking privileges to
objects
 Privilege auditing
 Periodically reviewing a subject’s privileges over an
object
 Objective: determine if subject has the correct
privileges
6 ITIS 412
Privilege Management

7 ITIS 412
Change Management
 Change management
 Methodology for making modifications and keeping track of
changes
 Ensures proper documentation of changes so future changes
have less chance of creating a vulnerability
 Involves all types of changes to information systems
 Two major types of changes that need proper
documentation
 Changes to system architecture
 Changes to file or document classification

8 ITIS 412
Change Management
 Change management team (CMT)
 Body responsible for overseeing the changes
 Composed of representatives from all areas of IT, network
security, and upper management
 Proposed changes must first be approved by CMT
 CMT duties
 Review proposed changes
 Ensure risk and impact of planned change are understood
 Recommend approval, disapproval, deferral, or withdrawal of a
requested change
 Communicate proposed and approved changes to coworkers

9 ITIS 412
Information Security Risk Identification

10 ITIS 412
Incident Management
 Incident management
 Response to an unauthorized incident
 Components required to identify, analyze, and contain an
incident
 Incident handling
 Planning, coordination, communications, and planning
functions needed to resolve incident
 Incident management objective
 To restore normal operations as quickly as possible with least
impact to business or users

11 ITIS 412
Risk Calculation
 Two approaches to risk calculation:
 Qualitative risk calculation - uses an “educated guess” based on
observation
 Typically assigns a numeric value (1-10) or label (High, Medium, or
Low) that represents the risk
 Quantitative risk calculation - attempts to create “hard”
numbers associated with the risk of an element in a system by
using historical data
 Can be divided into the likelihood of a risk and the impact of a risk
being successful

12 ITIS 412
Risk Calculation
 Risk Likelihood
 Several quantitative tools can be used to predict the likelihood
of the risk
 Mean Time Between Failure (MTBF)
 Mean Time To Recovery (MTTR)
 Mean Time To Failure (MTTF)
 Failure In Time (FIT)
 Historical data can be used to determine the likelihood of a risk
occurring within a year
 Known as Annualized Rate of Occurrence (ARO)

13 ITIS 412
Risk Calculation

14 ITIS 412
Risk Calculation
 Risk Impact
 Comparing the monetary loss associated with an asset in order
to determine the amount of money that would be list if the risk
occurred
 Two risk calculation formulas are used to calculate expected
losses:
 Single Loss Expectancy (SLE) - expected monetary loss every time a
risk occurs
 Annualized Loss Expectancy (ALE) - expected monetary loss that can
be expected for an asset due to risk over a one-year period

15 ITIS 412
Risk Prioritization
Reducing Risk Through Policies
 Security policy
 A written document that states how an organization plans to
protect the company’s information technology assets
 Outlines the protections that should be enacted to ensure the
organization’s assets face minimal risk
 Having a written security policy empowers an organization to
take appropriate action to safeguard its data

17 ITIS 412
What Is a Security Policy? (cont’d.)
 Security policy functions
 An overall intention and direction, formally expressed by the
organization’s management

 Details specific risks and how to address them

 Provides controls to direct employee behavior

 Helps create a security-aware organizational culture

 Helps ensure employee behavior is directed and monitored in


compliance with security requirements

18 ITIS 412
Balancing Trust and Control
 Three approaches to trust
 Trust everyone all of the time
 Trust no one at any time
 Trust some people some of the time

 Security policy attempts to provide right amount of trust


 Trust some people some of the time
 Builds trust over time

 Level of control must also be balanced


 Influenced by security needs and organization’s culture
19 ITIS 412
Standard, Guideline , & Policy
 Standard - collection of requirements specific to system or
procedure that must be met by everyone
 Guideline - collection of suggestions that should be
implemented
 Policy - document that outlines specific requirements that
must be met

20 ITIS 412
Designing a Security Policy
 Designing a security policy involves:
 Defining what a policy is
 Understanding the security policy cycle
 Knowing the steps in policy development

 Characteristics of a policy
 Communicates a consensus of judgment
 Defines appropriate user behavior
 Identifies needed tools and procedures
 Provides directives for Human Resource action in response to
inappropriate behavior
 Helps if it becomes necessary to prosecute violators

21 ITIS 412
Designing a Security Policy
 Three phases of the security policy cycle
 Vulnerability assessment

 Create the policy using information from risk management


study

 Review the policy for compliance

22 ITIS 412
Designing a Security Policy

23 ITIS 412
Designing a Security Policy
 Steps in Development
 Security policy design should be the work of a team
 Development team representatives
 Senior level administrator
 Member of management who can enforce the policy
 Member of the legal staff
 Representative from the user community
 Team should first decide on policy goals and scope
 Also how specific the policy should be

24 ITIS 412
Designing a Security Policy
 Due care
 Obligations imposed on owners and operators of assets
 Owners must exercise reasonable care of assets and take
precautions to protect them

 Examples of due care policy statements


 Employees should exercise due care in opening attachments
received from unknown sources
 Students will exercise due care when using computers in a
crowded lab setting

25 ITIS 412
Designing a Security Policy
 Policy development guidelines
 Notify users in advance of development of and reasons for a
new security policy

 Provide affected users an opportunity to review and comment


on policy prior to deployment

 Prior to development, give all users at least two weeks to


review the policy and comment on it

 Allow users given responsibility the authority to carry out their


responsibilities

26 ITIS 412
Types of Security Policies
 Most organizations have security policies that address:
 Acceptable use
 Privacy
 Data
 Security-related human resource
 Ethics
 Password management and complexity

27 ITIS 412
Types of Security Policies
 Acceptable Use Policy (AUP)
 Policy that defines actions users may perform while accessing
systems
 Users include employees, vendors, contractors, and visitors
 Typically covers all computer use
 Unacceptable use may also be outlined by the AUP
 Generally considered most important information security
policy

28 ITIS 412
Types of Security Policies
 Privacy policy
 Outlines how organization uses personal information it collects
 Data policy
 Set of procedures designed to control and manage data by
specifying data collection and storage
 Generally involves creating classification categories
 Example: Level A or High Risk
 Data retention policy - outlines how to maintain information in
the user’s possession for a predetermined length of time

29 ITIS 412
Types of Security Policies
 Data policy
 Data wiping and disposing policy - Addresses disposal of
confidential resources
 Describes how to dispose of equipment, records, and data
 Security-related human resource policy
 Includes statements about how an employee’s information
technology resources will be addressed
 Typically presented at employee orientation session after
employee is hired

30 ITIS 412
Types of Security Policies
 Security-related human resource policy (cont’d.)
 May include statements regarding due process and/or due
diligence
 May include statements regarding actions to be taken when
employee is terminated
 Ethics policy
 Attempts to establish a culture of openness, trust, and integrity
in business practices
 Often contain such topics as executive and employee commitment to
ethics, how to maintain ethical practices, and penalties for unethical
behavior

31 ITIS 412
Types of Security Policies
 Password management and complexity policy
 Addresses how passwords are created and managed
 Reminds users of differences between strong and weak
passwords

32 ITIS 412
Awareness and Training
 Providing users with security awareness training
 One of the key defenses in information security
 Awareness and training topics
 Compliance
 Secure user practices
 Awareness of threats

33 ITIS 412
Compliance
 Users should be informed regarding:
 Security policy training and procedures
 Personally identifiable information
 Information classification
 Data labeling, handling, and disposal
 Compliance with laws, best practices, and standards

34 ITIS 412
User Practices
 Awareness and training also involves helping users
understand how their normal practices can impact the
security of the organization

35 ITIS 412
Threat Awareness
 Peer-to-peer (P2P) networks
 Similar to instant messaging
 Users connect directly to each other
 Typically used for sharing audio, video, data files
 Tempting targets for attackers
 Viruses, worms, Trojans, and spyware can be sent using P2P
 Most organizations prohibit use of P2P
 High risk of infection
 Legal consequences

36 ITIS 412
Threat Awareness
 Social networking
 Grouping individuals based on some sort of affiliation
 Can be physical or online
 Web sites that facilitate social networking called social
networking sites
 Increasingly becoming prime targets of attacks
 Reasons social networking sites are popular with attackers
 Personal data can be used maliciously

37 ITIS 412
Threat Awareness
 Reasons social networking sites are popular with attackers
(cont’d.)
 Users may be too trusting
 Accepting friends may have unforeseen consequences
 Social networking security is lax or confusing
 Security tips for using social networking sites
 Consider carefully who is accepted as a friend
 Show limited friends a reduced version of your profile
 Disable options and reopen only as necessary

38 ITIS 412
Threat Awareness

39 ITIS 412
Threat Awareness

40 ITIS 412
Training Techniques
 Opportunities for security education and training
 When a new employee is hired
 After a computer attack has occurred
 When an employee promoted
 During an annual department retreat
 When new user software is installed
 When user hardware is upgraded

41 ITIS 412
Training Techniques
 Traits of learners impact how people learn
 Examples of learning styles
 Visual
 Auditory
 Kinesthetic
 Training styles impact how people learn
 Role-based training
 Involves specialized training that is customized to the specific role
that an employee holds in the organization

42 ITIS 412
Training Techniques

43 ITIS 412
Training Techniques

44 ITIS 412

You might also like