ؤCISSP Training Course 2021
Security Risk Management
Security Governance Principles
Compliance
Professional Ethics
Security Documentation
Risk Management
Threat Modeling
Business Continuity Plan Fundamentals
Acquisition Strategy and Practice
Personnel Security Policies
Security Awareness and Training
The CIA Triad
ty
Int
ali
e
g ri
nt i
ty
de
nf i
Co
Availability
Common Security Terms
Term Description
Asset Anything of value that could be compromised, stolen, or harmed, including information,
physical resources, and reputation.
Threat Any event or action that could potentially cause damage to an asset or an interruption
of services.
Attack The intentional act of attempting to bypass one or more security services or controls of
an information system.
Vulnerability A condition that leaves the system and its assets open to harm.
Exploit A technique that takes advantage of a vulnerability to perform an attack.
Risk The likelihood of a threat occurring, as well as its potential damage to assets.
Control A countermeasure that you put in place to avoid, mitigate, or counteract security risks
due to threats or attacks.
Social engineering The practice of using deception and trickery against human beings as a method of
attack.
Defense in depth The practice of providing security in multiple layers for more comprehensive protection
against attack.
Security Governance
Methods of exercising
control and management
over an organization.
Seeks to mitigate security
risk.
Turns a reactionary
security culture into a
proactive one.
Supports business
objectives to minimize
cost and disruption.
Governance Requirements
Strategic alignment of information security with business strategies to support
organizational objectives.
Risk management by risk mitigation and reducing potential impact on resources.
Resource management by use of information security knowledge and
infrastructures.
Performance measurement by evaluating, monitoring, and reporting information
security governance metrics to achieve objectives.
Value delivery by optimizing information security investments that support
organizational objectives.
Security Council
Gets insight from all parts of the organization.
Pushes support for security initiatives.
Performs the following activities:
Select security project initiatives.
Prioritize information security activities.
Review and recommend organizational security policies.
Monitor the existing security program.
Promote security throughout the organization.
Suggest areas of security requiring development and investment.
Organizational Governance Structure
Board of Directors/CEO
CISO
Security Department
Management
Staff
The Organizational Culture's Impact on Security
Structure of an organization can impact its security.
Who is responsible for what? Who do they report to?
Different levels responsible for different security requirements and
tasks.
Security and Business Alignment
Security professionals must advise decision makers based on risk.
Cost prohibits 100% security.
To support business constraints:
Assess risk and determine needs.
Implement policies and controls to mitigate risk.
Promote awareness of expectations.
Monitor and evaluate effectiveness of thecontrols.
Use as input in next risk assessment.
IT is the business, and the business is IT.
Not separate function; integral to the business.
Business makes money from IT platform.
Recognize mutual nature of security and business.
SECURITY BUSINESS
Organizational Processes
Mergers and acquisitions
Mismatch of technology and security levels can cause challenges.
Rectify security discrepancies.
Transition staff gracefully; terminated personnel may be a risk.
Divestitures
Risk of information leakage.
Child organization may keep information that belongs to the parent.
Sensitive information must not leave its intended domain.
Hiring and firing
New staff must undergo security training.
Departing staff must no longer be able to access sensitive information.
Governance committees
Evaluate effectiveness of governance personnel and practices.
Onboard or offboard governance members.
Committee members should have basic security management understanding.
Roles and Responsibilities
Role Responsibilities
End Users • Protect information on a daily basis.
• Adhere to security policies.
• Be mindful of everything they do.
• Report security issues.
Administrative Assistants • First line of defense against social engineering.
• Screen phone calls for executives.
Help Desk/Service Desk • Answer user questions about system problems.
Administrators • Help desk calls may indicate security issues.
Physical Security • First line of defense regarding physical location of assets.
• Can work with external law enforcement.
• Role may be integrated with information systems security.
Information Systems/IT • Design security controls into information systems.
Professionals
Information Systems • Inform executive management of security concerns and suggest solutions.
Security Professionals
Information Systems • Determine whether systems and personnel are in compliance.
Auditors • Check configuration and design, implementation and operation of systems.
Roles and Responsibilities (Cont.)
Role Responsibilities
Business Continuity • Develop contingency plans to prepare for incidents.
Planners
Data/Information Custodians • Implement access control levels based on data owner’s specifications.
• Back up data to ensure recovery after loss or corruption.
Data/Information/Business • Classify data.
Owners • Determine level of access to data.
Security Administrators • Manage access to information systems.
• Keep logs of all requests for access.
• Provide logs to auditor.
Network/Systems • Keep network infrastructure running to ensure availability.
Administrators • Physically implement access controls to data.
Executive Management • Protect information assets of organization.
• May include Chief Information Officer (CIO).
• May also include Chief Information Security Officer (CISO)
CISO Role
Protects all business information from loss and disclosure.
Works with individuals to ensure policies, procedures, and other documents are
implemented.
May also run the organization’s incident response team.
Supports governance activities.
Develops programs to review security from several viewpoints.
Must balance security needs with business objectives, especially when limited
by cost or time.
CISO Responsibilities
Role Responsibilities
Understand the business • Become knowledgeable about business operation and goals.
• Understand vision and mission, and how IT security helps to meet goals.
• Be a member of the management team.
• Provide security guidance to entire organization.
Stay informed • Be up to date on changing threat environment.
• Be aware of emerging technologies that provide security solutions.
Budget • Develop and justify security budget.
• Communicate budget needs to senior management to ensure approval.
• Ask for needs rather than wants.
Develop • Develop security policies, procedures, baselines, standards, and guidelines.
• Develop organization-wide security awareness programs.
• Develop security management skills within thesecurity organization.
Train • Ensure user and management training in information security protection.
• Train security staff in new threats, new safeguards, and current operations.
Ensure compliance • Ensure compliance to laws, regulations, and policies within areas controlled by
information security.
• Coordinate with legal department as necessary.
CISO Responsibilities (Cont.)
Role Responsibilities
Promote awareness • Promote an organization-wide climate of security awareness.
• Communicate importance of business continuity and disaster recovery planning.
Inform • Be conduit for security information in the organization.
• Provide frequent status updates on security environment.
• Provide advance information about pending changes to help plan training.
Measure • Measure security effectiveness by conducting penetration testing and other similar
activities.
• Work with auditors to determine weaknesses.
Assist • Assist senior management in understanding information security requirements.
• Assist application designers and developers to provide security in new and existing
systems.
Report • Report security accomplishments and limitations to senior management.
• Provide details regarding security violations.
Communications
Speak persuasively and be able to listen.
Lack of communication may jeopardize security efforts.
Understand business initiatives to protect the appropriate assets.
Communicate security concerns to management.
Help management understand risks.
Be ready to answer:
What problem are you solving?
What is the risk to the company?
What is the cost of the safeguard vs. doing nothing?
Will this eliminate or simply mitigate risk?
How long will the project last?
What resources will be required?
Security Reporting Options
Security Reporting Pros and Cons
Option
Chief Executive Officer • Pros:
(CEO) • Top-level visibility.
• Accessibility to resources.
• Cons:
• Lack of independence.
Internal audit department • Pros:
• Develops strong relationship.
• Provides good feedback.
• Cons:
• Audit should be independent of other departments and activities.
• Violates separation of duties (SoD).
IT department • Pros:
• Most security issues are IT-related.
• A strong working relationship is important.
• Cons:
• Lack of independence.
• Violates SoD.
Administrative services • Pros:
department • Independent of most other departments.
• Cons:
• Department management may not understand security requirements and
needs.
Security Reporting Options (Cont.)
Security Reporting Pros and Cons
Option
Insurance and risk • Pros:
management department • In tune with security needs.
• Understands risk.
• Cons:
• May not understand computer security risks.
Legal department • Pros:
• Knows security-related legal requirements.
• Cons:
• Not usually technically driven.
• May focus on legal requirements vs. overall risk reduction.
Corporate security • Pros:
• Security oriented.
• Cons:
• Focus may be physical security only.
• May not understand information security issues.
Security Goal Categories
Goal Description
Strategic • Align with business and information technology goals.
• Long horizon (3-5 years or more).
• Ex: establish security policies and ensure all users understand responsibilities.
Tactical • Provide broad initiatives necessary to support goals of strategic plan.
• May consist of multiple projects.
• Usually 6-18 month time period.
• Ex: implement disaster recovery programs and customer relationship management.
Operational • Specific short-term goals.
• Put tactical plan into practice.
• Ensure that individual projects are completed with milestones.
• Ex: perform project-wise risk assessment and development of security policies.
Control Frameworks
Minimizes risk in an organization by creating a structure for security controls.
Meet the following criteria:
Consistent
Measurable
Standardized
Comprehensive
Modular
Due Care and Due Diligence
Due care: behaviorial expectations that organizations must adhere to.
Act responsibly and reasonably: “prudent person” or “reasonable person” rule.
Ex: provide appropriate security training for all employees.
Failing in due care is negligence, a legal offense.
Liability: legal responsibility for damage caused by an individual or business
entity.
Organizations must protect themselves from liability.
Due diligence: research necessary to make good, informed decisions.
Ex:
Background checks on employees.
Risk assessment of physical security systems.
Testing of backup services.
Guidelines for Applying Security Governance
Principles
Consider CIA triad when securing information and other assets.
Balance need for availability with needs for confidentiality and integrity.
Establish clear chain of organizational governance.
Security and business operations must align to be effective.
Decision makers must understand that security is not an after-thought.
Ensure security is incorporated into major business processes.
Ensure each job role is clearly defined and positioned relative to security needs.
Know roles and responsibilities of a CISO.
Communicate security concerns to decision makers clearly and understandably.
Listen to concerns and advice of others.
Establish a security reporting structure.
Create or adopt a security control framework.
Always exercise due care and due diligence.
Compliance
Awareness of and adherence to relevant laws and regulations.
Can be:
Set forth by governments and other private organizations.
Internal and self-imposed.
Consult with legal department to determine how laws and regulations impact
security operations.
Legislative and Regulatory Compliance
Security professionals must understand all laws that apply to their organization.
Specific conditions must be met in certain cases.
Identify any safe harbors that could help the organization avoid penalties.
Safe harbors are practices or actions that are deemed not to be in violation of the law.
Policies and other documentation should be consistent with applicable laws and
regulations.
Privacy Issues
Personally identifiable information (PII) could
be used to identify an individual.
Only a few pieces of information can expose
a person’s identity.
Criminals can use PII for extortion, fraud, or
shaming.
Ex:
Names
Social Security numbers
Addresses
Personal characteristics
PII, once exposed, may not be “recoverable”.
U.S. Information Privacy Law
Information Privacy Description
Law Act
Privacy Act of 1974 Protects privacy of individual information held by U.S. government. Applies to all
personal information, provides for restrictions on individual access, and enforces
penalties for unauthorized disclosure.
FERPA Protects privacy of educational information held in federally funded higher-learning
institutions. (Ex: mailing college grade reports to a student's parents now prohibited.)
ECPA Made it a crime to snoop into employee activities while using electronic
communications devices without notifying employees in advance of monitoring.
Enforced requirement for legal authorization of wiretaps, other government monitoring.
HIPAA Originally intended to protect people with health insurance when they transferred from
one company to another. The privacy component adopted in 2003 protects a class of
information called Protected Health Information (PHI). PHI is any information that can
identify a particular patient and includes a patient’s medical record or payment history.
GLBA Protects privacy of an individual's financial information as held by financial and other
institutions. Includes privacy standard and rules to safeguard information; provides
provide penalties for violations.
U.S. Information Privacy Law (Cont.)
Information Privacy Description
Law Act
COPPA Protects online privacy of children. Restrictions include rights to: opt out of information
sent by a provider; limit amount and type of information collected from children; require
parental consent for information provided to children.
USA PATRIOT Act Increased governmental ability to wiretap and control financial transactions used to
fund terrorism. Government could potentially collect Internet information with blanket
subpoena.
SOX Act Controls how corporations self-report and audit. Requires retention of long-term email,
voicemail, and instant messaging records in corporations.
FCRA Provides consumers with ability to view, correct, contest, and limit use of their
information in a credit report.
Federal Sentencing All organizations shall:
Guidelines • Exercise due diligence to prevent and detect criminal conduct.
• Establish standards and procedures to prevent and detect criminal conduct.
• Hold high-level officers accountable for instituting effective compliance and ethics
program.
• Conduct effective training programs.
• Periodically evaluate effectiveness of compliance and ethics program.
U.S. Information Privacy Law (Cont.)
Information Privacy Description
Law Act
FISMA Requires federal agencies to develop, document, and implement an agency-wide
information security program.
Cyber Security Used to access and analyze law enforcement and intelligence information from
Enhancement Act government agencies to fight terrorism.
ESIGN Facilitates use of electronic signatures and electronic records in both domestic
(interstate) and foreign commerce.
DMCA Criminalizes dissemination of technologies or actual attempts to circumvent digital
rights management of copyrighted works.
Economic Espionage Act of Makes theft of trade secrets and economic espionage a federal crime.
1996
International Privacy Law
Organization may be subject to international laws depending on:
Who it serves
Where its offices and customers reside.
Ex: European Data Protection Directive permits processing personal data only
when:
Processing necessary for compliance and legal action.
Processing required to protect someone's life.
The person has provided consent.
Processing is within law and scope of “public interest.”
Conditions may not align with U.S. laws.
Frameworks like US-EU Safe Harbor Protection Framework help organizations
comply with foreign laws and regulations.
Be mindful of all jurisdictions your operations are subject to.
Computer Crime
Classified Information
Attack
Government
Database
U.S. Computer Crime Law
Computer Crime Law Description
Act
CFAA Protects government systems from illegal access or from exceeding access
permissions. Prohibited activities include: retrieving information without authorization;
trafficking passwords; sending viruses or worms to infect computers; etc.
CSA Key requirements: fulfill training needs and plan development for information and
systems security. (Replaced by FISMA.)
NIIPA Created legal remedies for hacking, stealing trade secrets, and damaging systems and
information. Targeted Internet infrastructure security in particular
FISMA Passed to remedy evolutionary nature of information systems security in federal
government. Some key organizational provisions:
• Define boundaries of system to be protected and identify types of information within
that system.
• Document system information and perform risk assessment to identify areas
requiring additional protection.
• Protect systems using an identified set of controls; certify systems before use.
• Continuously monitor systems for proper operation.
Data Breach
An incident that results in release or potential
exposure of secure information.
Can be true test of legal compliance.
If organization performs due care to comply with
laws, breach’s effects may be mitigated.
Organization can also avoid severe legal
penalties.
Especially a concern with privacy laws, as many
breaches expose customer PII.
Consequences for compliance failure are
magnified under a breach.
Licensing and Intellectual Property
Intellectual Property Description
Law
Patent Protects item's creator from competition for a given time period. Very strong, but patent
owners have responsibility to protect their patents.
Trademark A design or phrase used to identify unique products or services.
Copyright Protects an original artistic work. Not as strong as patent protection, but length of
protection is much greater.
Trade secret An item requiring protection that, if lost, would severely damage the business. To be
provided legal protection, trade secret must be properly secured and protected.
Licensing Permission to use a creator’s protected materials. Violating licensing provision may
result in civil or criminal charges.
Trans-Border Data Flow
Both private and non-private sensitive data are impacted by their flow across borders.
Raises issue of how and when a company should comply with certain laws, regulations,
and standards.
OECD proposes guidelines for privacy protection under trans-border PII flow:
Personal data collected should be limited and obtained legally with knowledge and consent of individual.
Personal data relevant to intended purpose should be kept up to date.
Individuals should be notified why PII is needed when collected; should be used only for those purposes.
PII should not be shared or used for a different purpose unless individual gives consent or law demands it.
Personal data should be protected with reasonable security safeguards against loss, unauthorized access,
destruction, modification, or release.
Developments, practices, and policies regarding personal data should be transparently communicated.
Every individual should have the right:
To obtain confirmation an organization has their personal information.
To obtain details of collected data with reasonable time and cost, in understandable form.
To be informed why a request for information was denied; to have right to challenge denial.
To challenge accuracy of personal data and have it corrected.
Import and Export Controls
Limitations when importing or exporting goods and services.
Be aware of:
ITAR: defined defense articles and services with stipulations for their import and export.
EAR: allowed US President to regulate export of civilian
goods and services.
Wassenaar Agreement:
contributes to regional and
international security in
transfers of arms and
dual-use goods and
technologies.
All companies (especially in
defense or aerospace industry), should consult legal counsel
regarding import/export laws.
Industry Standards
IT/Information Security Description
Standard
PCI DSS • Specifies how organizations handle information security for major card brands.
• Compliance validated on annual basis.
• Organizations or merchants that accept, transmit, or store cardholder data from
these brands must comply.
NIST SP 800 series Various publications establish computer security standards, including:
• SP 800-12: An Introduction to Computer Security: The NIST Handbook
• SP 800-14: Generally Accepted Principles and Practices for Securing Information
Technology Systems
• SP 800-33: Underlying Technical Models for Information Technology Security
• SP 800-53: Security and Privacy Controls in Federal Information Systems and
Organizations
COBIT 5 Standards for IT management and governance, promoting five principles:
• Meeting stakeholder needs.
• Covering the enterprise end-to-end.
• Applying a single, integrated framework.
• Enabling a holistic approach.
• Separating governance from management.
ISO/IEC 27001 Focuses on topics in information security management:
• Responsibilities and procedures.
• Reporting information security events.
• Reporting information security weaknesses.
• Assessment of and decision on information security events.
• Response to information security incidents.
• Learning from information security incidents.
• Collection of evidence.
Guidelines for Supporting Compliance
Perform due diligence by researching legal jurisdiction and industry standards.
Consult with legal department.
Ensure that policies and other documentation are consistent with laws and
regulations.
Identify any ways in which your organization works with PII.
Stay current on applicable privacy laws.
Understand that privacy laws differ based on the country.
Stay current on computer crime laws.
Consider how a breach could expose compliance failures.
Understand intellectual privacy laws that govern use of third party content
services.
Understand how IP laws apply to your content and services.
Understand import/export laws that affect how you move goods and services
across borders.
Research industry standards that affect your organization.
The Purpose of Ethics
The organization’s principles, proper conduct, and system of moral values.
Code of ethics helps professionals cooperate and pursue common goals.
Code can guard against competitive pressures to act unscrupulously.
Provides a guide for what other professionals will do.
WRONG RIGHT
Organizational Ethics
Organizations often document ethical expectations.
May also be bound by ethics outlined in laws and standards.
Ethical codes can also minimize risk.
Employees with a track record of ethical behavior can help the organization
avoid harm.
Organizations are also responsible for acting ethically to their employees,
customers, and other stakeholders.
Regulatory Requirements for Ethics Programs
Ethics enforced by organizations and governmental agencies may apply if you
do business with them.
Bware of ethical codes pertaining to your organization.
SOX, HIPAA, and GLBA require adoption of ethical standards.
Ethics Issues in a Computing Environment
Computer ethics is a subset of business ethics.
Affects same people and processes.
Organizational concerns:
Employees may be unaware that they can be tracked with IM, GPS, and other systems.
Individual concerns:
Seeming anonymity may tempt employees to misuse access to digital information.
Common Computer Ethics Fallacies
Ethics Fallacy Criminals Feel:
Free information “Information wants to be free;” they want to help it escape.
Computer game Penetrating security is like a game; they want to level up.
Taking candy from a baby An action that is easy to perform must be acceptable.
Shatterproof Making small changes will do minimal harm.
The ends justify the means It can’t be wrong to gain knowledge that can help themselves or society.
Law-abiding citizen fallacy If their actions are legal, they don't have to consider their consequences.
Internet Architecture Board Ethics
IAB actions to avoid include:
Seeking to gain unauthorized access to Internet resources.
Disrupting intended Internet use.
Wasting resources such as people, capacity, and computers through unprincipled actions.
Destroying the integrity of computer-based information.
Compromising user privacy.
Ethical Minefields for Security Professionals
Expediency requires temporary suspension of proper security practice.
Inability to find licensed software required for a one-time purpose.
A direct order from a supervisor to shortcut ethics to accomplish a critical goal.
(ISC)2 Code of Ethics
• Protect society, the common good,
necessary public trust and
confidence, and the infrastructure.
• Act honorably, honestly, justly,
responsibly, and legally.
• Provide diligent and competitive
service to principals.
• Advance and protect the
profession.
(ISC)2 Code of Ethics
Ethical Code Goals
Preamble Includes:
• Ensuring the safety of the commonwealth and the responsibility and accountability to
principals, (ISC)2 committee members, and other CISSP professionals.
• Requiring and acknowledging adherence to the utmost ethical values and standards
of behavior.
• Strictly observing this code to demonstrate compliance and fulfill the conditions of
certification.
Canons Include:
• Guarding the commonwealth, the infrastructure, and society.
• Behaving responsibly, justly, honestly, honorably, and legally.
• Providing adept, competent, and assiduous service to principals.
• Improving, enhancing, and protecting the profession.
Guidelines for Upholding Professional Ethics in
Security
Follow a code of ethics in every facet of your security career.
Document any organization-specific ethical provisions.
Enforce ethical codes mandated by applicable laws and industry regulations.
Use ethical codes to minimize risk to the organization.
Have a code of ethics for how the organization treats its employees, customers,
and other stakeholders.
Consider the unique ethical challenges posed by computers.
Make sure your employees are aware of these computer-specific ethical
concerns.
Understand the fallacies that others may employ to justify attacks and other
malicious behavior.
Consult the Internet Architecture Board of Ethics (IAB) and its provisions for
what actions to avoid.
Closely study the (ISC)2 Code of Ethics and understand that you must, at all
times, adhere to this code.
The Value of Security Documentation
Lack of documentation creates organizational
chaos.
Documentation provides a framework for
people to work together in achieving
organizational goals.
Security documentation can also act as a road
map to governance.
Security Document Types
Security Document Description
Type
Policy High-level statement of management intentions. Contains purpose, scope, and
compliance expected of every employee.
Example: Information security will ensure the protection of information by implementing
security best practices.
Standard Required implementation or use of tools.
Example: The corporation must implement 802.1x security for all wireless networks.
Guideline Recommended or suggested action or best practice.
Example: When travelling with laptops, users should use safety precautions to prevent
laptop theft, damage, or data loss.
Procedure Step-by-step description of how to implement a system or process.
Example: To implement Secure Shell (SSH) on the router, enter the enable mode and
then enter the appropriate commands for the router.
Baseline Minimum security required for a system or process.
Example: Trivial File Transfer Protocol (TFTP) must be disabled in all servers except for
those specifically used for the TFTP service.
Security Planning
Security Planning Description
Effort
Strategic planning • Long-term (three- to five-year) planning process.
• Focuses on major security changes in an organization.
• Processes such as mergers and acquisitions could trigger a plan review.
Tactical planning • Mid-term process (6 to 18 months).
• For example, a move to RADIUS for authentication could take a year to complete.
Operational and project • Near-term, per-project basis.
planning • Supports milestones and completion dates that are communicated regularly.
• For example, planning for a penetration test in three months.
Security Policy Objectives
Objectives that security policies can fulfill:
Inform employees about their security-related duties and responsibilities.
Define an organization’s security goals.
Outline a computer system's security requirements.
Objectives depend on the organization’s specific requirements.
Policies should be long enough to explain but short enough to be understood.
All employees should have access to the policy.
Security Policy Types
Security Policy Type Description
Advisory • Indicates certain types of actions as being more appropriate or effective than others.
• Includes consequences and reprimands that may occur if actions are not as
indicated.
• Commonly indicate how to handle private documentation and money.
Informative • Provides data to employees on a specified subject.
• Includes no ramifications.
• Often used as instructional instruments.
Regulatory • Addresses industry regulations regarding the conduct of organizations.
• Commonly used for health care and financial organizations.
The Relationship Between Security Document Types
Laws and Requirements
Policies Policy Types:
Strategic • Advisory
Statement of management • Informative
intentions • Regulatory
Standards Guidelines
Tactical Mandatory Recommended
implementation actions
Procedures Baselines
Operational Step-by-step Consistent
instructions comparison points
Guidelines for Drafting Security Documentation
Should provide a common framework to achieve organizational goals.
Should provide a road map to good governance.
Utilize appropriate document types:
Policies are a high-level statement of management intentions.
Standards describe required implementation or use of tools.
Guidelines recommend or suggest an action or best practice.
Procedures document a step-by-step activity.
Baselines specify the minimum level of security for a system or process.
Utilize three planning tiers:
Strategic planning for long-term examination of security processes.
Tactical planning for mid-term examination of security processes.
Operational and project planning for examination of security on a per-project basis.
Policies should:
Inform employees about their security-related duties and responsibilities.
Define the organization's security goals.
Outline a computer system's security requirements.
Consider the relationships between the different document types.
What Is Risk?
• Building damage
• Data loss
• Loss of productivity
• Loss of life
• Loss of equipment
• Access to system by malicious
individual
Risk Management
Risk
Analysis
Monitoring Prioritization
Response
Results of Improper Risk Management
Disclosure Modification
CRITICAL ASSETS
Loss /
Interruption
Destruction
Integrating Governance, Compliance, and Risk
Management
The Risk Analysis Process
Risk Analysis Process Description
Phase
Asset identification and Identifying assets that require protection and determining value of the assets, including
valuation data, data systems, buildings, and employees.
Vulnerability identification Identifying vulnerabilities so analyst can confirm where problems exist.
Threat assessment Determining what threats may exploit identified vulnerabilities.
Risk assessment Assessing the probability that threats will exploit vulnerabilities. Can be quantitative
(numbers-based) or qualitative (words-based).
Financial impact evaluation Once probabilities are determined, evaluating potential financial impact of risks.
Asset Identification
Comprehensively identify all assets in the organization.
Waiting until it’s too late will make it harder to recover an asset.
If you don’t identify an asset, you may not even know when it’s compromised.
Describe assets in terms of:
Basic characteristics.
Value to the company.
Use on a daily basis.
Replaceability.
Asset Valuation
What effort was required to develop or obtain it?
What does it cost to maintain and protect it?
How much will we lose in operational functionality if the asset is misplaced or
damaged?
What would it cost to replace it?
What enemies might pay for it?
What liability penalties might occur if the asset is compromised?
Asset Valuation Methods
Asset Valuation Description
Method
Asset management system Contains a detailed record of corporate property and similar assets, including facilities,
furniture, computers, and other real property
Accounting system Contains additional financial information about assets, such as expensing the cost to
develop software packages.
Insurance valuation Good source of asset valuation due to rigorous analysis of risk of loss.
Qualitative valuation Narrative descriptions capture expert judgement about asset value.
Areas of Vulnerability
Vulnerability Area Example Threat and Risk
Physical structure Window accessibility in a room where secure information is stored can expose
vulnerabilities and create a venue for sudden intrusion threats.
Electrical Failure of a vulnerable electrical feed can threaten system data.
Software Worms, viruses, and Trojans threaten systems.
Network Unencrypted data on network can be vulnerable to interception and exploit.
Personnel Key trained personnel must be available to deal with critical events to avoid corporate-
wide vulnerabilities.
Hardware Losses due to theft and physical damage generate costs for replacement and lost
productivity.
Documentation If poorly written, can cause confusion and impair decision making.
Organization must protect integrity and confidentiality of sensitive documentation.
Process Outdated or inefficient processes can impair business operations; poor security
processes weaken defenses and increase risk.
Identify Threats
Threat Type Description
Natural disasters • Earthquakes
• Wildfires
• Flooding
• Excessive snowfalls
• Tsunamis
• Hurricanes
• Tornados
• Landslides
Man-made disasters Intentional:
• Arson
• Terrorist attacks
• Political unrest
• Break-ins
• Theft of equipment and/or data
• Equipment damage
• File destruction
• Information disclosure
Unintentional:
• Employee mistakes
• Power outages
• Excessive employee illnesses or epidemics
• Information disclosure
Risk Assessment Methodologies
CRAMM (CCTA Risk Analysis and Management Method)
Failure Modes and Effect Analysis (FMEA)
FRAP (Facilitated Risk Analysis Process)
OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation)
Security Officers Management and Analysis Project (SOMAP)
Risk Assessment Determination Factors
Likelihood - how likely is it that the threat occurs?
Impact - what kind of damage will the threat cause?
Qualitative Assessment
Impact
Likelihood Insignificant Minor Moderate Major Catastrophic
5. Almost
H H E E E
certain
4. Likely M H H E E
3. Possible L M H E E
2. Unlikely L L M H E
1. Rare L L M H H
Risk
L = Low M = Medium H = High E = Extreme
Quantitative Assessment
Determination Factor Description
Likelihood • Annual rate of occurrence (ARO) = event number / years.
• If a flood occurs every 10 years, the ARO is 10%.
Exposure • Exposure factor (EF) = loss value / asset value (AV).
• Facility’s AV is $20 million, expected loss is $4 million in a flood.
• EF is 20%.
Impact • Single loss expectancy (SLE) = EF * AV.
• Flooding incurs 20% EF, the facility’s value is $20 million.
• SLE is $4 million
Risk • Annual loss expectancy (ALE) = ARO * SLE.
• Flood occurs once every 10 years, expected loss is $4 million for each flood.
• ALE is $400,000.
Risk Management Prioritization
Large impending risks must be prioritized over smaller, longer-term risks.
Prioritization occurs in phases.
Perform risk List risks Determine Prioritize by probability level; focus
analysis tasks on discovered risk on high-probability risks in response
an individual basis. through analysis. probability. process.
Responses to Risk
Response to Risk Description and Example
Avoidance • Choose: when risk is likely, and impact is great.
• Computer equipment could be stolen if an office window is broken. Move equipment
to an alternate location.
Mitigation • Choose: if risk is likely, but impact is not excessive.
• Leave equipment in place, but add bars to the window.
Transfer • Choose: if the risk is unlikely, but impact is great.
• Offloading the responsibility to a third party, usually an insurance company.
• Leave equipment and window in place, but add insurance coverage.
Acceptance • Choose: if the risk is unlikely, and impact is minimal, or if cost outweighs benefit.
• Do nothing if theft is unlikely and equipment is not sensitive or valuable.
Control Selection Criteria
Selection criteria:
Cost effectiveness
Risk reduction
Practicality
Additional details to consider:
Can the control be audited?
Is the control from a trusted source?
Can the control be consistently applied?
Is the control reliable?
Is the control independent from other controls?
Is the control easy to use?
Can the control be automated?
Is the control sustainable?
Control Types
Administrative
Covers personnel security, risk management, training, permissions, etc.
Example: Security guards consult an access list to determine who is allowed access to the
building without questioning.
Physical
Limit a person’s physical access to assets or facilities, using locks, doors, fences, etc.
Example: Infrared monitoring system can detect the presence of an intruder.
Technical
Implemented in computing environments like operating systems, applications, databases,
network devices, etc.
Example: A user sign-in process requiring an account name and password for authentication to
a network.
User
***
Administrative Physical Technical
Control Functions
Recovery
Controls
Corrective
Controls
Detective
Controls
Tim
INCIDENT
e
Compensating
Controls
Preventative
Controls
Directive
Controls
Deterrent Low Medium High
Controls
Threat Level Based on Figure 1.17 in the Official (ISC) 2 Guide to the CISSP CBK.
Control Implementation Matrix
Administrative Physical Technical
Directive X
Deterrent X X
Preventative X X X
Compensating X X
Detective X X
Corrective X
Recovery X X
Residual Risk
Risk that remains even after controls
are in place.
Can’t account for every risk, no
matter how hard you try. Inherent
Risk
Identifying residual risk can help you
assess the effectiveness of your
controls.
Controls
Residual
Risk
Monitoring and Measuring
Not just simple pass-fail results or generating paperwork for an audit.
Well-executed assessment determines validity and effectiveness of controls.
Can expose strengths and weaknesses of current systems.
Helps identify a plan for correcting weaknesses.
Continuous Improvement
Ongoing effort to optimize policies and processes.
A function of risk management.
Includes best practices:
Continuously seek to discover new vulnerabilities.
Be context aware in your risk analysis.
Prioritize your efforts to vulnerabilities that actually pose a significant risk.
Determine patchability.
e
e t e rmin ty ritiz
e
D ili Prio y
hab
pa tc b
risk
us
n t i nuo
Co
Improvement
Be aware
Seek new of context
vulnerabilities
Risk Management Frameworks
Frameworks ensure risks are handled in the context of:
The nature of the risks faced by the organization.
The organization's risk tolerance.
The resources available to manage risks.
The organization's culture.
Common frameworks:
ISACA Risk IT Framework
ISO 31000
COSO Enterprise Risk Management Framework
NIST Risk Management Framework
Guidelines for Implementing Risk Management
Construct program around process of analysis, prioritization, response, and
monitoring and measuring.
Integrate into a larger framework of governance, risk management, and
compliance (GRC).
Follow phases of the risk analysis process.
Identify all assets that are susceptible to risk.
Place value on assets using one or more valuation methods.
Identify how each asset is vulnerable.
Identify threats to each vulnerable asset.
Assess risk using qualitative or quantitative language.
Prioritize risks.
Respond to risk in different ways depending on the context.
Select controls based on cost effectiveness, practicality, and efficacy.
Consider residual risk as a way to review efficacy of your controls.
Monitor and measure effectiveness of risk response techniques and
management processes.
Continuously improve the risk management program.