0% found this document useful (0 votes)
13 views24 pages

Threat & Risk Management Overview

security information management

Uploaded by

Iqra Shaikh
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
13 views24 pages

Threat & Risk Management Overview

security information management

Uploaded by

Iqra Shaikh
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

Minor / Honour Program

HCSC701 Security Information


Management
Module 3: - Threat & Risk Management

1
Topics

● Threat Modelling: Threat, Threat-Source,


Vulnerability, Attacks.
● Risk Assessment Frameworks: ISO 31010, NIST-
SP-800-30, OCTAVE

2
Threat Modelling
Threat modeling systematically identifies and evaluates potential threats or risks to a
system, application, or organization.

Example: DREAD ([Link] )

● Damage: Understand the potential damage a particular threat is capable of


causing.
● Reproducibility: Identify how easy it is to replicate an attack.
● Exploitability: Analyze the system’s vulnerabilities to ascertain susceptibility to
cyberattacks.
● Affected Users: Calculate how many users would be affected by a cyberattack.
● Discoverability: Determine how easy it is to discover vulnerable points in the
system infrastructure.
○ [Link]
fimY/edit#gid=0 3
Threat

A threat is any circumstance or event with the potential to adversely impact organizational
operations and assets, individuals, other organizations, or the Nation through an
information system via unauthorized access, destruction, disclosure, or modification of
information, and/or denial of service.

4
Threat Source

Threat events are caused by threat sources.

● A threat source is characterized as:


○ The intent and method targeted at the exploitation of a vulnerability; or
○ A situation and method that may accidentally exploit a vulnerability.

E.g. An end-user uses the ping of death to make the server unavailable. In this threat -
source is end-user who attacks the server.

5
Vulnerability

A vulnerability is a weakness in an information system, system security procedures,


internal controls, or implementation that could be exploited by a threat source.

E.g. An end-user uses the ping of death to make the server unavailable. In this
vulnerability is unpatched system which responds to ping from IP outside network.

6
Attack

An attack refers to a malicious and deliberate attempt to compromise the security,


integrity, or availability of computer systems, networks, or digital devices.

For example, Malware, Social Engineering

7
Risk Assessment

● Overall process of risk identification, risk analysis and risk evaluation is called risk
assessment.
● There are different perspectives with which risk assessment is carried out:
○ Asset centric risk assessment - ISO 27001 version 2005
○ Threat centric risk assessment - NIST-SP-800-30
○ Process centric risk assessment - ISO 27001 version 2013
○ Business centric risk assessment – OCTAVE((Operationally Critical Threat, Asset, and
Vulnerability Evaluation) Allegro
○ Enterprise Risk assessment – ISO 31010

8
ISO 31010

9
ISO 31010

Risk identification:
● Risk identification is the process of finding, recognizing and
recording risks.
● The risk identification process includes identifying the causes and
source of the risk (hazard in the context of physical harm), events,
situations or circumstances which could have a material impact upon
objectives and the nature of that impact

10
ISO 31010

Risk analysis:
● Risk analysis is about developing an understanding of the risk. It provides
an input to risk assessment and to decisions about whether risks need to be
treated and about the most appropriate treatment strategies and methods.
● Risk analysis involves consideration of the causes and sources of risk, their
consequences and the probability that those consequences can occur.

11
ISO 31010

Risk analysis have following steps:

1) Controls assessment : If there are existing control what is the level of effectiveness.

2) Consequence analysis: Consequence analysis determines the nature and type of


impact which could occur assuming that a particular event situation or circumstance
has occurred.

3) Likelihood analysis and probability estimation: Historical data may be used to


predict the likelihood of risk.

12
ISO 31010

Risk evaluation:
● Risk evaluation involves comparing estimated levels of risk with
risk criteria defined when the context was established, in order
to determine the significance of the level and type of risk.
● Risk evaluation also helps in prioritizing of the risks.

13
ISO 31010

Risk Treatment:
● Having completed a risk assessment, risk treatment involves selecting
and agreeing to one or more relevant options for changing the
probability of occurrence, the effect of risks, or both, and implementing
these options.

14
NIST-SP-800-30

15
NIST-SP-800-30

PREPARING FOR THE RISK ASSESSMENT


● Preparing for a risk assessment includes the following tasks:
○ Identify the purpose of the assessment;
○ Identify the scope of the assessment;
○ Identify the assumptions and constraints associated with the assessment;
○ Identify the sources of information to be used as inputs to the
assessment; and
○ Identify the risk model and analytic approaches (i.e., assessment and
analysis approaches) to be employed during the assessment

16
NIST-SP-800-30

IDENTIFY THREAT SOURCES & EVENTS

● Identify and characterize threat sources of concern, including capability, intent, and targeting
characteristics for adversarial threats and range of effects for non-adversarial threats.
● Identify the threat events that can be initiated by threat-source
● For relevant adversarial threat sources:
○ Assess adversary capability
○ Assess adversary intent
○ Assess adversary targeting
● For relevant non-adversarial threat sources:
○ Assess the range of effects from threat sources

17
NIST-SP-800-30

IDENTIFY VULNERABILITIES AND PREDISPOSING CONDITIONS (Regulatory


requirements)

● Identify vulnerability and predisposing condition inputs


● Assess the severity of identified vulnerabilities
● Identify predisposing conditions impact

18
NIST-SP-800-30

DETERMINE LIKELIHOOD

Determine the likelihood that threat events of concern result in adverse impacts

● Assess the likelihood of threat event initiation for adversarial threats and the
likelihood of threat event occurrence for non-adversarial threats
● Assess the likelihood of threat events resulting in adverse impacts, given likelihood
of initiation or occurrence
● Assess the overall likelihood of threat event initiation/occurrence and likelihood of
threat events resulting in adverse impacts

19
NIST-SP-800-30

DETERMINE IMPACT

● Determine the adverse impacts from threat events of concern

DETERMINE RISK

● Determine the risk to the organization from threat events of concern


considering:
○ The impact that would result from the events; and
○ The likelihood of the events occurring

20
OCTAVE

OCTAVE defines a set of self-directed activities for organizations to identify and manage
their information security risks.

During Phase 1, information assets and their values, threats to those assets, and security
requirements are identified using knowledge of the staff from multiple levels within the
organization, along with standard catalogs of information

21
OCTAVE

Phase 2 of OCTAVE builds on the


information captured during Phase 1 by
mapping the information assets of the
organization to the information
infrastructure components (both the
physical environment and networked IT
environment) to identify the high-
priority infrastructure components

22
OCTAVE

Phase 3 of OCTAVE builds on the information


captured during Phases 1 and 2. Risks are
identified by analyzing the assets, threats,
and vulnerabilities identified in OCTAVE’s
earlier phases in the context of standard
intrusion scenarios. The impact and
probability of the risks (also called the risk
attributes) are estimated and subsequently
used to help prioritize the risks

23
Thank You

24

You might also like