Assessing Cybersecurity Risk
• Identify the Importance of Risk Management
• Assess Risk
• Mitigate Risk
• Integrate Documentation into Risk Management
Copyright © 2021 CertNexus, Inc. All rights reserved. 1
IDENTIFY THE IMPORTANCE OF RISK
MANAGEMENT
Copyright © 2021 CertNexus, Inc. All rights reserved. 2
Elements of Cybersecurity (Endpoint Model)
Copyright © 2021 CertNexus, Inc. All rights reserved. 3
Elements of Cybersecurity (Perimeter Model)
Copyright © 2021 CertNexus, Inc. All rights reserved. 4
The Risk Equation
Risk = Threats × Vulnerabilities × Consequences
Ransomware Technical Business
Attack Impact Impact
Angry Customers
Service
DDoS
Unplanned Expenses
Attack
Asset
Loss of Competitive
Advantage
Natural
Disaster Asset Loss of Stakeholder
Confidence
Copyright © 2021 CertNexus, Inc. All rights reserved. 5
Risk Management
• Management of risk involves assigning weight for different contexts.
• You can communicate technical risk to decision makers.
• Risk is necessary.
• Many risks are worth taking as long as the reward is greater.
vs.
Copyright © 2021 CertNexus, Inc. All rights reserved. 6
The Risk Management Process
Identification
Response
RISK Assessment
MANAGEMENT
Analysis
Copyright © 2021 CertNexus, Inc. All rights reserved. 7
Risk Exposure
Risk exposure: The property that dictates how susceptible an organization is to loss.
• Calculated by multiplying likelihood of risk by impact.
• Example: Likelihood of ransomware hitting your data is 10%, expected loss if it does hit is $100,000.
• Exposure = .10 × 100,000 = $10,000.
• Assumes risk can be quantified.
• Ignoring exposure will hurt the organization.
• Always be vigilant for threats, attacks, and vulnerabilities.
Copyright © 2021 CertNexus, Inc. All rights reserved. 8
Risk Analysis Methods
Qualitative Semi-quantitative Quantitative
• Scenario based • Some issues defy • Number based
• Uses words to measure numbers and cannot • Uses numbers to
the likelihood and impact be quantified calculate the probable
of risk • For example, what is loss for every risk
your corporate
reputation worth?
• Attempts to strike a
balance between
numbers and words
Copyright © 2021 CertNexus, Inc. All rights reserved. 9
The Impact of Risks on the Organization
Legal Financial Physical Assets Intellectual Property
Infrastructure Operations Reputation Health
Copyright © 2021 CertNexus, Inc. All rights reserved. 10
Activity: Identifying the Importance of Risk Management
• You're a cybersecurity team member for Develetech Industries.
• Develetech manufactures home electronics.
• The CEO has placed you in charge of maintaining operational security.
• You need to identify how risk can negatively affect your organization.
Copyright © 2021 CertNexus, Inc. All rights reserved. 11
ASSESS RISK
Copyright © 2021 CertNexus, Inc. All rights reserved. 12
Security Standards and Frameworks (Slide 1 of 2)
• Cybersecurity Framework
• Managing cybersecurity risk in organizations.
• SP 800-61
• Incident response.
• RMF
• Integrating information assurance, auditing, and risk
management into SDLC.
• COBIT
• Five principles of IT framework and governance.
• ITAF
• Auditing roles, responsibilities, and processes.
Copyright © 2021 CertNexus, Inc. All rights reserved. 13
Security Standards and Frameworks (Slide 2 of 2)
• ISO/IEC 27000 series
• Cybersecurity through a family of standards.
• Standard of Good Practice for Information Security
• Implementing cybersecurity in federal organizations.
General
cybersecurity • RFC 2196
• Securing sites with Internet-connected systems.
• CIS Controls
• Procedures for securing 18 control categories.
• SSAE 18
• Financial reporting.
• ISA/IEC-62443
Specialized • Securing industrial control systems (ICSs).
• NERC 1300
• Securing bulk electric systems (BESs).
Copyright © 2021 CertNexus, Inc. All rights reserved. 14
Security Laws and Regulations
• SOX
• Storage and retention of financial and operational
documents.
• FISMA
US • Implementing cybersecurity in federal organizations.
• CMMC
• Cybersecurity certification requirements for government
contractors.
• Computer Misuse Act
UK • Securing computer material against unauthorized access or
modification.
Copyright © 2021 CertNexus, Inc. All rights reserved. 15
Privacy Standards and Frameworks
• Privacy Framework
• Provides guidance for organizations to manage privacy risks.
• ISO/IEC 27000 series
• Has several publications that focus primarily on privacy.
• ISO/IEC 29100
• Outlines common terminology, responsibilities, and
controls for privacy.
• GAPP
• Provides guidance to accountants on maintaining security
of PII.
Copyright © 2021 CertNexus, Inc. All rights reserved. 16
Privacy Laws and Regulations
• HIPAA
• Personal health data.
• GLBA
• Individual's financial information.
US • COPPA
• Data of children under 13.
• CAN-SPAM
• Email recipients.
• PIPEDA
CA • Personal information used by organizations.
• Data Protection Act
UK • Information relating to individuals.
• GDPR
EU • Personal data of EU citizens.
• PCI DSS
• Payment card processing.
Copyright © 2021 CertNexus, Inc. All rights reserved. 17
New and Changing Factors That Impact Risk
• New and changing business strategies
• De-perimeterization
• User behaviors
• New products and technologies
• New threats
Copyright © 2021 CertNexus, Inc. All rights reserved. 18
Internal and External Influences
Internal External Internal Client External Client
Compliance Compliance Requirements Requirements
Audit Top-Level
Competitors
Findings Management
Copyright © 2021 CertNexus, Inc. All rights reserved. 19
System-Specific Risk Analysis
• Analyze how systems are used.
• How can the systems' CIA be threatened?
• Analysis will depend on each system's context.
• Ask questions like:
• How can attack be performed?
• Are there any patches or workarounds?
• How many targets are there?
• How likely is an attack?
• How can you translate technical risks into business terms?
Copyright © 2021 CertNexus, Inc. All rights reserved. 20
Risk Determinations
• Likelihood of threat
• Motivation (if any)
• Source
• ARO
• Trend analysis
• Magnitude of impact
AV ( Asset Value ) × EF ( Exposure Factor )=SLE( Single Loss Expectancy)
SLE × ARO ( Annual Rate of Occurrence )= ALE ( Annual Loss Expectancy)
Copyright © 2021 CertNexus, Inc. All rights reserved. 21
Documentation of Assessment Results
Who asked you to perform the assessment?
What were you asked to do?
What did you assess?
What did you do?
What did you find?
What does it all mean?
Copyright © 2021 CertNexus, Inc. All rights reserved. 22
Guidelines for Assessing Risk
Assess industry-accepted security/privacy frameworks/standards.
Identify security/privacy laws/regulations that your organization is subject to.
Evaluate how new and changing business factors can impact risk.
Consider how remote work and BYOD impacts your network perimeter.
Consider how internal/external factors can influence your risk assessment.
Determine how risks can affect the CIA of specific systems.
Determine what a threat is, where it comes from, and what risk it poses.
Calculate the SLE and ARO of a threat, then multiply these to obtain ALE.
Document assessment findings clearly and comprehensively.
Copyright © 2021 CertNexus, Inc. All rights reserved. 23
Activity: Assessing Risk
• You'll assess risk at Develetech to get an idea of how the business currently fares.
• Recall that Develetech is expanding the business.
• You'll gain an understanding of evolving technology that will affect Develetech.
• You'll also see what unique challenges this poses to its risk management strategy.
• This will enable you to address these risks later.
Copyright © 2021 CertNexus, Inc. All rights reserved. 24
MITIGATE RISK
Copyright © 2021 CertNexus, Inc. All rights reserved. 25
Classes of Information
Public Private
• No risk if • Risk if obtained
disclosed by competitors
• Risk if modified • Risk if modified
or unavailable or unavailable
Classes of
Information
Restricted Confidential
• Access limited
to few • Personal
personnel information
• Unauthorized • Huge risk if
access disrupts disclosed
business
Copyright © 2021 CertNexus, Inc. All rights reserved. 26
Classification of Information Types into CIA Levels
• Think of information in terms of its impact on CIA.
• Example: Public info may not impact confidentiality but will impact availability.
• Investigate how each info type fits into the three larger goals of security.
ty
Int
ali
e
g ri
nt i
de
ty
nf i
Co
Availability
Copyright © 2021 CertNexus, Inc. All rights reserved. 27
Security Control Categories
• Technical
• Hardware or software that prevents and mitigates threats to computers.
• Example: Network firewall.
• Physical
• Measures that restrict, detect, and monitor access to physical areas or assets.
• Example: Door locks.
• Administrative
• Monitor organization's adherence to security policies.
• Example: A regularly scheduled compliance audit.
Copyright © 2021 CertNexus, Inc. All rights reserved. 28
Technical Controls (Template)
Technical Control Upholds Confidentiality? Upholds Integrity? Upholds Availability?
User permissions for
network share
Load balancers for
web servers
Message
authentication codes
(MACs) used in digital
signatures
Copyright © 2021 CertNexus, Inc. All rights reserved. 29
Technical Controls (Example Answer)
Technical Control Upholds Confidentiality? Upholds Integrity? Upholds Availability?
User permissions for Yes, by keeping unauthorized No No
network share users from accessing shared data
Load balancers for No No Yes, by routing traffic to hosts that
web servers are available and have capacity
Message Yes, by comparing the
authentication codes expected message digest
(MACs) used in digital No with the actual message No
signatures digest upon output
Copyright © 2021 CertNexus, Inc. All rights reserved. 30
Risk Scoring Systems
• You can develop risk scores on a sliding scale of harm.
• Simple method:
• 10 for highest risk.
• 1 for lowest.
• 0 for none.
• There are many scoring systems that are more sophisticated and are accepted by the community.
• Scoring systems enable you to prioritize some risks over others.
Copyright © 2021 CertNexus, Inc. All rights reserved. 31
Common Vulnerability Scoring System (CVSS)
Base Metrics Temporal Metrics Environmental Metrics
Attack vector Exploit code maturity Modified base metrics
Attack complexity Remediation level Confidentiality requirements
Privileges required Report confidence Integrity requirements
User interaction Availability requirements
Confidentiality impact
Integrity impact
Availability impact
Scope
Copyright © 2021 CertNexus, Inc. All rights reserved. 32
Common Vulnerabilities and Exposures (CVE)
PrintNightmare
• A public dictionary of vulnerabilities using CVSS.
• Enables vulnerability data sharing between
organizations.
• Maintained by MITRE Corporation.
Copyright © 2021 CertNexus, Inc. All rights reserved. 33
Risk Response Techniques
• Avoid
• Eliminate risk by eliminating the source.
• Transfer
• Move responsibility to a third party.
• Mitigate
• Reduce risk through controls and countermeasures.
• Accept
• Determine that risk is within the organization's appetite and do nothing further.
Copyright © 2021 CertNexus, Inc. All rights reserved. 34
Communicating Recommendations for Mitigating Risk
• You'll likely need approval to respond to risks.
• You'll need to communicate recommended mitigation tactics to an audience.
• Place both risk and risk mitigation in a context business leaders can understand.
• Not always feasible to go through normal channels to obtain approval, especially in an emergency.
Copyright © 2021 CertNexus, Inc. All rights reserved. 35
Levels of Authority
Levels of authority: A hierarchy that defines what responsibility someone has to act.
Decide, act
Decide, inform, act
Act after approval
Act from instruction
Copyright © 2021 CertNexus, Inc. All rights reserved. 36
Continuous Monitoring and Improvement
Continuous monitoring and improvement: The process of detecting changes in an environment and then
quickly and efficiently addressing them.
• Risk is always changing.
• Organizations need to continually evaluate networks to ensure controls are operating as intended.
• E.g., patch management software that constantly updates systems in response to new vulnerabilities.
• Business can bolster its operational processes and cut down on costly risk assessments.
• Tools can alert staff to:
• Unanticipated resource access.
• Invalid or expired software licenses.
• Mobile devices that attach to the network.
Copyright © 2021 CertNexus, Inc. All rights reserved. 37
Verification and Quality Control
• Evaluation/assessment
• Auditing
• Maturity model implementation
• Certification
Copyright © 2021 CertNexus, Inc. All rights reserved. 38
Defense in Depth
Defense in depth: A strategy that positions several layers of security that reduce risk.
Encrypted database
• Personnel
• Processes Intrusion detection
• Technologies system
• Architecture design Vulnerability
assessment
Network segmentation
Trained personnel
Copyright © 2021 CertNexus, Inc. All rights reserved. 39
Guidelines for Mitigating Risk
Categorize information into classes.
Classify information in terms of how it will impact your enterprise CIA.
Incorporate stakeholder input for CIA-based decisions.
Understand technical controls in terms of how they do or do not fulfill CIA.
Avoid, transfer, mitigate, or accept risk based on the situation.
Implement continuous monitoring to quickly detect changes.
Communicate to relevant stakeholders regarding how you measure, respond to,
and mitigate risks.
Put products and services through verification and quality control processes.
Adopt a defense in depth strategy.
Copyright © 2021 CertNexus, Inc. All rights reserved. 40
Activity: Mitigating Risk
• Your team at Develetech has assessed various risks that could affect the business.
• Now it's time to analyze the results and respond appropriately.
• Uphold stakeholder expectations and system security by choosing the right mitigation strategies.
Copyright © 2021 CertNexus, Inc. All rights reserved. 41
INTEGRATE DOCUMENTATION INTO RISK
MANAGEMENT
Copyright © 2021 CertNexus, Inc. All rights reserved. 42
From Policies to Procedures
Procedures
Step-by-step instructions
Guidelines
Recommended controls
Standards
Mandatory controls
Policies
Organization's intentions
Copyright © 2021 CertNexus, Inc. All rights reserved. 43
The Policy Lifecycle
• Reasons for policies are numerous.
• Begin crafting policy by looking at templates.
• Policy should be easy to understand.
• Policy treated as a legal document.
• Involve business leaders in policy development.
• Policy is a living document that must adapt to
new and changing business factors.
Copyright © 2021 CertNexus, Inc. All rights reserved. 44
The Procedure Lifecycle
• Process and procedure documents support policies.
• How-to style documents used by employees to
implement policies.
• Must be tailored to the audience that uses them.
• Style varies between organizations and industries.
• Consider using templates.
• Living documents that must adapt to changes.
Copyright © 2021 CertNexus, Inc. All rights reserved. 45
Topics to Include in Security Policies and Procedures
• The scope of what the policy covers.
• How information is classified.
• Goals for secure handling of information.
• How other management policies relate to the security policy.
• References to supporting documents.
• Specific instructions for handling security issues.
• The person or group who has specific designated responsibilities.
• Known consequences for security policy non-compliance.
Copyright © 2021 CertNexus, Inc. All rights reserved. 46
Best Practices to Incorporate in Security Policies and Procedures
Separation of Mandatory Incident
Job Rotation Least Privilege
Duties Vacation Response
Employment Continuous Training and Auditing Information
Forensics and Termination Monitoring Awareness Classification
Copyright © 2021 CertNexus, Inc. All rights reserved. 47
Types of Policies
• Acceptable use policy
• Account management policy
• Password policy
• Data ownership policy
• Data classification policy
• Data retention policy
• Communication policy
Copyright © 2021 CertNexus, Inc. All rights reserved. 48
Types of Procedures
• Patching
• Compensating control development
• Control testing procedures
• Remediation planning
• Exception management
• Evidence production
Copyright © 2021 CertNexus, Inc. All rights reserved. 49
Business Documents That Support Security Initiatives
• Master service agreement (MSA)
• Statement of applicability (SOA)
• Business impact analysis (BIA)
• Interoperability agreement (IA)
• Interconnection security agreement (ISA)
• Memorandum of understanding (MOU)
• Service-level agreement (SLA)
• Operating-level agreement (OLA)
• Non-disclosure agreement (NDA)
• Business partnership agreement (BPA)
Copyright © 2021 CertNexus, Inc. All rights reserved. 50
Guidelines for Integrating Documentation into Risk Management
Download free policy templates.
Consider hiring a consultant.
Use direct, concise language.
Include business leaders in policy development.
Support policies with clearly defined processes and procedures.
Make processes and procedures easy to follow.
Compare and contrast policies, processes, and procedures with other organizations.
Consider policies, processes, and procedures to be living documents.
Incorporate best practices into policies based on your specific requirements.
Involve HR, legal, management, and other entities in the policy development process.
Ensure that policies have provisions for legal and regulatory compliance.
Identify any sensitive PII that your organization handles.
Be up front with your clients as to how their PII will be used.
Advise your clients on best practices to maintain privacy.
Identify business documents and agreements applicable to your needs.
Use a partner agreement requiring strong security and legal and financial liability.
Copyright © 2021 CertNexus, Inc. All rights reserved. 51
Activity: Integrating Documentation into Risk Management
• Malicious users tricked help desk employees into divulging sensitive information.
• You'll review an AUP that defines acceptable and unacceptable behavior.
• Document will focus on communication methods.
• You'll add to an existing template.
Copyright © 2021 CertNexus, Inc. All rights reserved. 52
Reflective Questions
1. At your workplace or one you're familiar with, what security risks are there, and what risks do you
envision for the future of the organization?
2. What sort of documentation do you have in your organization or an organization you're familiar with to
support risk management? What other documentation should there be?
Copyright © 2021 CertNexus, Inc. All rights reserved. 53