0% found this document useful (0 votes)
16 views53 pages

Cybersecurity Risk Management Guide

The document outlines the process of assessing cybersecurity risk, emphasizing the importance of risk management, assessment, and mitigation. It discusses various risk analysis methods, security standards, and frameworks, as well as the impact of risks on organizations. Additionally, it provides guidelines for documenting assessment results and mitigating risks through continuous monitoring and a defense-in-depth strategy.

Uploaded by

Fack You
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
16 views53 pages

Cybersecurity Risk Management Guide

The document outlines the process of assessing cybersecurity risk, emphasizing the importance of risk management, assessment, and mitigation. It discusses various risk analysis methods, security standards, and frameworks, as well as the impact of risks on organizations. Additionally, it provides guidelines for documenting assessment results and mitigating risks through continuous monitoring and a defense-in-depth strategy.

Uploaded by

Fack You
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

Assessing Cybersecurity Risk

• Identify the Importance of Risk Management


• Assess Risk
• Mitigate Risk
• Integrate Documentation into Risk Management

Copyright © 2021 CertNexus, Inc. All rights reserved. 1


IDENTIFY THE IMPORTANCE OF RISK
MANAGEMENT

Copyright © 2021 CertNexus, Inc. All rights reserved. 2


Elements of Cybersecurity (Endpoint Model)

Copyright © 2021 CertNexus, Inc. All rights reserved. 3


Elements of Cybersecurity (Perimeter Model)

Copyright © 2021 CertNexus, Inc. All rights reserved. 4


The Risk Equation

Risk = Threats × Vulnerabilities × Consequences

Ransomware Technical Business


Attack Impact Impact

Angry Customers
Service

DDoS
Unplanned Expenses
Attack

Asset
Loss of Competitive
Advantage

Natural
Disaster Asset Loss of Stakeholder
Confidence

Copyright © 2021 CertNexus, Inc. All rights reserved. 5


Risk Management

• Management of risk involves assigning weight for different contexts.


• You can communicate technical risk to decision makers.
• Risk is necessary.
• Many risks are worth taking as long as the reward is greater.

vs.

Copyright © 2021 CertNexus, Inc. All rights reserved. 6


The Risk Management Process

Identification

Response
RISK Assessment
MANAGEMENT

Analysis

Copyright © 2021 CertNexus, Inc. All rights reserved. 7


Risk Exposure

Risk exposure: The property that dictates how susceptible an organization is to loss.

• Calculated by multiplying likelihood of risk by impact.


• Example: Likelihood of ransomware hitting your data is 10%, expected loss if it does hit is $100,000.
• Exposure = .10 × 100,000 = $10,000.
• Assumes risk can be quantified.
• Ignoring exposure will hurt the organization.
• Always be vigilant for threats, attacks, and vulnerabilities.

Copyright © 2021 CertNexus, Inc. All rights reserved. 8


Risk Analysis Methods

Qualitative Semi-quantitative Quantitative

• Scenario based • Some issues defy • Number based


• Uses words to measure numbers and cannot • Uses numbers to
the likelihood and impact be quantified calculate the probable
of risk • For example, what is loss for every risk
your corporate
reputation worth?
• Attempts to strike a
balance between
numbers and words

Copyright © 2021 CertNexus, Inc. All rights reserved. 9


The Impact of Risks on the Organization

Legal Financial Physical Assets Intellectual Property

Infrastructure Operations Reputation Health

Copyright © 2021 CertNexus, Inc. All rights reserved. 10


Activity: Identifying the Importance of Risk Management

• You're a cybersecurity team member for Develetech Industries.


• Develetech manufactures home electronics.
• The CEO has placed you in charge of maintaining operational security.
• You need to identify how risk can negatively affect your organization.

Copyright © 2021 CertNexus, Inc. All rights reserved. 11


ASSESS RISK

Copyright © 2021 CertNexus, Inc. All rights reserved. 12


Security Standards and Frameworks (Slide 1 of 2)

• Cybersecurity Framework
• Managing cybersecurity risk in organizations.
• SP 800-61
• Incident response.
• RMF
• Integrating information assurance, auditing, and risk
management into SDLC.

• COBIT
• Five principles of IT framework and governance.
• ITAF
• Auditing roles, responsibilities, and processes.

Copyright © 2021 CertNexus, Inc. All rights reserved. 13


Security Standards and Frameworks (Slide 2 of 2)

• ISO/IEC 27000 series


• Cybersecurity through a family of standards.
• Standard of Good Practice for Information Security
• Implementing cybersecurity in federal organizations.
General
cybersecurity • RFC 2196
• Securing sites with Internet-connected systems.
• CIS Controls
• Procedures for securing 18 control categories.

• SSAE 18
• Financial reporting.
• ISA/IEC-62443
Specialized • Securing industrial control systems (ICSs).
• NERC 1300
• Securing bulk electric systems (BESs).

Copyright © 2021 CertNexus, Inc. All rights reserved. 14


Security Laws and Regulations

• SOX
• Storage and retention of financial and operational
documents.
• FISMA
US • Implementing cybersecurity in federal organizations.
• CMMC
• Cybersecurity certification requirements for government
contractors.

• Computer Misuse Act


UK • Securing computer material against unauthorized access or
modification.

Copyright © 2021 CertNexus, Inc. All rights reserved. 15


Privacy Standards and Frameworks

• Privacy Framework
• Provides guidance for organizations to manage privacy risks.

• ISO/IEC 27000 series


• Has several publications that focus primarily on privacy.
• ISO/IEC 29100
• Outlines common terminology, responsibilities, and
controls for privacy.

• GAPP
• Provides guidance to accountants on maintaining security
of PII.

Copyright © 2021 CertNexus, Inc. All rights reserved. 16


Privacy Laws and Regulations

• HIPAA
• Personal health data.
• GLBA
• Individual's financial information.
US • COPPA
• Data of children under 13.
• CAN-SPAM
• Email recipients.

• PIPEDA
CA • Personal information used by organizations.

• Data Protection Act


UK • Information relating to individuals.

• GDPR
EU • Personal data of EU citizens.

• PCI DSS
• Payment card processing.

Copyright © 2021 CertNexus, Inc. All rights reserved. 17


New and Changing Factors That Impact Risk

• New and changing business strategies


• De-perimeterization
• User behaviors
• New products and technologies
• New threats

Copyright © 2021 CertNexus, Inc. All rights reserved. 18


Internal and External Influences

Internal External Internal Client External Client


Compliance Compliance Requirements Requirements

Audit Top-Level
Competitors
Findings Management
Copyright © 2021 CertNexus, Inc. All rights reserved. 19
System-Specific Risk Analysis

• Analyze how systems are used.


• How can the systems' CIA be threatened?
• Analysis will depend on each system's context.
• Ask questions like:
• How can attack be performed?
• Are there any patches or workarounds?
• How many targets are there?
• How likely is an attack?
• How can you translate technical risks into business terms?

Copyright © 2021 CertNexus, Inc. All rights reserved. 20


Risk Determinations

• Likelihood of threat
• Motivation (if any)
• Source
• ARO
• Trend analysis

• Magnitude of impact

AV ( Asset Value ) × EF ( Exposure Factor )=SLE( Single Loss Expectancy)

SLE × ARO ( Annual Rate of Occurrence )= ALE ( Annual Loss Expectancy)

Copyright © 2021 CertNexus, Inc. All rights reserved. 21


Documentation of Assessment Results

Who asked you to perform the assessment?

What were you asked to do?

What did you assess?

What did you do?

What did you find?

What does it all mean?

Copyright © 2021 CertNexus, Inc. All rights reserved. 22


Guidelines for Assessing Risk

 Assess industry-accepted security/privacy frameworks/standards.


 Identify security/privacy laws/regulations that your organization is subject to.
 Evaluate how new and changing business factors can impact risk.
 Consider how remote work and BYOD impacts your network perimeter.
 Consider how internal/external factors can influence your risk assessment.
 Determine how risks can affect the CIA of specific systems.
 Determine what a threat is, where it comes from, and what risk it poses.
 Calculate the SLE and ARO of a threat, then multiply these to obtain ALE.
 Document assessment findings clearly and comprehensively.

Copyright © 2021 CertNexus, Inc. All rights reserved. 23


Activity: Assessing Risk

• You'll assess risk at Develetech to get an idea of how the business currently fares.
• Recall that Develetech is expanding the business.
• You'll gain an understanding of evolving technology that will affect Develetech.
• You'll also see what unique challenges this poses to its risk management strategy.
• This will enable you to address these risks later.

Copyright © 2021 CertNexus, Inc. All rights reserved. 24


MITIGATE RISK

Copyright © 2021 CertNexus, Inc. All rights reserved. 25


Classes of Information

Public Private
• No risk if • Risk if obtained
disclosed by competitors
• Risk if modified • Risk if modified
or unavailable or unavailable

Classes of
Information
Restricted Confidential
• Access limited
to few • Personal
personnel information
• Unauthorized • Huge risk if
access disrupts disclosed
business

Copyright © 2021 CertNexus, Inc. All rights reserved. 26


Classification of Information Types into CIA Levels

• Think of information in terms of its impact on CIA.


• Example: Public info may not impact confidentiality but will impact availability.
• Investigate how each info type fits into the three larger goals of security.

ty

Int
ali

e
g ri
nt i
de

ty
nf i
Co

Availability

Copyright © 2021 CertNexus, Inc. All rights reserved. 27


Security Control Categories

• Technical
• Hardware or software that prevents and mitigates threats to computers.
• Example: Network firewall.

• Physical
• Measures that restrict, detect, and monitor access to physical areas or assets.
• Example: Door locks.

• Administrative
• Monitor organization's adherence to security policies.
• Example: A regularly scheduled compliance audit.

Copyright © 2021 CertNexus, Inc. All rights reserved. 28


Technical Controls (Template)

Technical Control Upholds Confidentiality? Upholds Integrity? Upholds Availability?

User permissions for


network share

Load balancers for


web servers

Message
authentication codes
(MACs) used in digital
signatures

Copyright © 2021 CertNexus, Inc. All rights reserved. 29


Technical Controls (Example Answer)

Technical Control Upholds Confidentiality? Upholds Integrity? Upholds Availability?

User permissions for Yes, by keeping unauthorized No No


network share users from accessing shared data

Load balancers for No No Yes, by routing traffic to hosts that


web servers are available and have capacity

Message Yes, by comparing the


authentication codes expected message digest
(MACs) used in digital No with the actual message No
signatures digest upon output

Copyright © 2021 CertNexus, Inc. All rights reserved. 30


Risk Scoring Systems

• You can develop risk scores on a sliding scale of harm.


• Simple method:
• 10 for highest risk.
• 1 for lowest.
• 0 for none.
• There are many scoring systems that are more sophisticated and are accepted by the community.
• Scoring systems enable you to prioritize some risks over others.

Copyright © 2021 CertNexus, Inc. All rights reserved. 31


Common Vulnerability Scoring System (CVSS)

Base Metrics Temporal Metrics Environmental Metrics


Attack vector Exploit code maturity Modified base metrics
Attack complexity Remediation level Confidentiality requirements
Privileges required Report confidence Integrity requirements
User interaction Availability requirements
Confidentiality impact
Integrity impact
Availability impact
Scope

Copyright © 2021 CertNexus, Inc. All rights reserved. 32


Common Vulnerabilities and Exposures (CVE)

PrintNightmare
• A public dictionary of vulnerabilities using CVSS.
• Enables vulnerability data sharing between
organizations.
• Maintained by MITRE Corporation.

Copyright © 2021 CertNexus, Inc. All rights reserved. 33


Risk Response Techniques

• Avoid
• Eliminate risk by eliminating the source.

• Transfer
• Move responsibility to a third party.

• Mitigate
• Reduce risk through controls and countermeasures.

• Accept
• Determine that risk is within the organization's appetite and do nothing further.

Copyright © 2021 CertNexus, Inc. All rights reserved. 34


Communicating Recommendations for Mitigating Risk

• You'll likely need approval to respond to risks.


• You'll need to communicate recommended mitigation tactics to an audience.
• Place both risk and risk mitigation in a context business leaders can understand.
• Not always feasible to go through normal channels to obtain approval, especially in an emergency.

Copyright © 2021 CertNexus, Inc. All rights reserved. 35


Levels of Authority

Levels of authority: A hierarchy that defines what responsibility someone has to act.

Decide, act

Decide, inform, act

Act after approval

Act from instruction

Copyright © 2021 CertNexus, Inc. All rights reserved. 36


Continuous Monitoring and Improvement

Continuous monitoring and improvement: The process of detecting changes in an environment and then
quickly and efficiently addressing them.

• Risk is always changing.


• Organizations need to continually evaluate networks to ensure controls are operating as intended.
• E.g., patch management software that constantly updates systems in response to new vulnerabilities.
• Business can bolster its operational processes and cut down on costly risk assessments.
• Tools can alert staff to:
• Unanticipated resource access.
• Invalid or expired software licenses.
• Mobile devices that attach to the network.

Copyright © 2021 CertNexus, Inc. All rights reserved. 37


Verification and Quality Control

• Evaluation/assessment
• Auditing
• Maturity model implementation
• Certification

Copyright © 2021 CertNexus, Inc. All rights reserved. 38


Defense in Depth

Defense in depth: A strategy that positions several layers of security that reduce risk.

Encrypted database
• Personnel
• Processes Intrusion detection
• Technologies system
• Architecture design Vulnerability
assessment

Network segmentation

Trained personnel

Copyright © 2021 CertNexus, Inc. All rights reserved. 39


Guidelines for Mitigating Risk

 Categorize information into classes.


 Classify information in terms of how it will impact your enterprise CIA.
 Incorporate stakeholder input for CIA-based decisions.
 Understand technical controls in terms of how they do or do not fulfill CIA.
 Avoid, transfer, mitigate, or accept risk based on the situation.
 Implement continuous monitoring to quickly detect changes.
 Communicate to relevant stakeholders regarding how you measure, respond to,
and mitigate risks.
 Put products and services through verification and quality control processes.
 Adopt a defense in depth strategy.

Copyright © 2021 CertNexus, Inc. All rights reserved. 40


Activity: Mitigating Risk

• Your team at Develetech has assessed various risks that could affect the business.
• Now it's time to analyze the results and respond appropriately.
• Uphold stakeholder expectations and system security by choosing the right mitigation strategies.

Copyright © 2021 CertNexus, Inc. All rights reserved. 41


INTEGRATE DOCUMENTATION INTO RISK
MANAGEMENT

Copyright © 2021 CertNexus, Inc. All rights reserved. 42


From Policies to Procedures

Procedures
Step-by-step instructions

Guidelines
Recommended controls

Standards
Mandatory controls

Policies
Organization's intentions

Copyright © 2021 CertNexus, Inc. All rights reserved. 43


The Policy Lifecycle

• Reasons for policies are numerous.


• Begin crafting policy by looking at templates.
• Policy should be easy to understand.
• Policy treated as a legal document.
• Involve business leaders in policy development.
• Policy is a living document that must adapt to
new and changing business factors.

Copyright © 2021 CertNexus, Inc. All rights reserved. 44


The Procedure Lifecycle

• Process and procedure documents support policies.


• How-to style documents used by employees to
implement policies.
• Must be tailored to the audience that uses them.
• Style varies between organizations and industries.
• Consider using templates.
• Living documents that must adapt to changes.

Copyright © 2021 CertNexus, Inc. All rights reserved. 45


Topics to Include in Security Policies and Procedures

• The scope of what the policy covers.


• How information is classified.
• Goals for secure handling of information.
• How other management policies relate to the security policy.
• References to supporting documents.
• Specific instructions for handling security issues.
• The person or group who has specific designated responsibilities.
• Known consequences for security policy non-compliance.

Copyright © 2021 CertNexus, Inc. All rights reserved. 46


Best Practices to Incorporate in Security Policies and Procedures

Separation of Mandatory Incident


Job Rotation Least Privilege
Duties Vacation Response

Employment Continuous Training and Auditing Information


Forensics and Termination Monitoring Awareness Classification
Copyright © 2021 CertNexus, Inc. All rights reserved. 47
Types of Policies

• Acceptable use policy


• Account management policy
• Password policy
• Data ownership policy
• Data classification policy
• Data retention policy
• Communication policy

Copyright © 2021 CertNexus, Inc. All rights reserved. 48


Types of Procedures

• Patching
• Compensating control development
• Control testing procedures
• Remediation planning
• Exception management
• Evidence production

Copyright © 2021 CertNexus, Inc. All rights reserved. 49


Business Documents That Support Security Initiatives

• Master service agreement (MSA)


• Statement of applicability (SOA)
• Business impact analysis (BIA)
• Interoperability agreement (IA)
• Interconnection security agreement (ISA)
• Memorandum of understanding (MOU)
• Service-level agreement (SLA)
• Operating-level agreement (OLA)
• Non-disclosure agreement (NDA)
• Business partnership agreement (BPA)

Copyright © 2021 CertNexus, Inc. All rights reserved. 50


Guidelines for Integrating Documentation into Risk Management

 Download free policy templates.


 Consider hiring a consultant.
 Use direct, concise language.
 Include business leaders in policy development.
 Support policies with clearly defined processes and procedures.
 Make processes and procedures easy to follow.
 Compare and contrast policies, processes, and procedures with other organizations.
 Consider policies, processes, and procedures to be living documents.
 Incorporate best practices into policies based on your specific requirements.
 Involve HR, legal, management, and other entities in the policy development process.
 Ensure that policies have provisions for legal and regulatory compliance.
 Identify any sensitive PII that your organization handles.
 Be up front with your clients as to how their PII will be used.
 Advise your clients on best practices to maintain privacy.
 Identify business documents and agreements applicable to your needs.
 Use a partner agreement requiring strong security and legal and financial liability.

Copyright © 2021 CertNexus, Inc. All rights reserved. 51


Activity: Integrating Documentation into Risk Management

• Malicious users tricked help desk employees into divulging sensitive information.
• You'll review an AUP that defines acceptable and unacceptable behavior.
• Document will focus on communication methods.
• You'll add to an existing template.

Copyright © 2021 CertNexus, Inc. All rights reserved. 52


Reflective Questions

1. At your workplace or one you're familiar with, what security risks are there, and what risks do you
envision for the future of the organization?

2. What sort of documentation do you have in your organization or an organization you're familiar with to
support risk management? What other documentation should there be?

Copyright © 2021 CertNexus, Inc. All rights reserved. 53

You might also like