Information Security
- Confidentiality
- Only required party should know the data
- Integrity
- No data is tampered, against the will
- Availability
- Information accessible when required
- Non Repudiation
- Cannot deny on the action performed
Risk Management Components
- Policy: Proposes principle of actions on which an organization is built, using to make decisions.
- Standard: Set of requirements which must be mandatory to be adhered by everyone.
- Guideline: Provides recommendations or suggestions and best practices.
- Procedure: Provides step by step instructions on how the policy, standard or guideline needs to be implemented. Also known as Standard Operating Procedure - SOP but tend to have more specific details on the instructions.
Security Framework and Standards
- NIST
- NIST is abbreviated as National Institute of Standards Technology.
- Developed for US and US government, but can be applicable for other countries as well.
- NIST Risk Management Framework (RMF), specifically used for federal agencies, and mandatory for US federal agencies.
- Six step process:
- Categorize or define environment
- Select appropriate controls
- Implement controls
- Assess controls
- Authorize a system
- Monitor for ongoing compliance
- NIST is responsible for issuing Federal Information Processing Standards (FIPS).
- NIST is also responsible for issuing advisory guides called as Special Publications.
- NIST provides a list of checklists and benchmarks for variety of operating system and applications called National Checklist Program (NCP)
- NIST Cyber Security Framework (CSF), is responsible to mitigate cybersecurity risks. CSF is can be classified as five functions, which is developed by the NIST.
- Identity
- Develop security systems to mitigate risk, threats, vulnerabilities
- Protect
- Build secure systems at every phase
- Detect
- Perform ongoing monitoring which are capable to identify and protect against different and new threats
- Respond
- Action against the detected risk, threats, vulnerabilities
- Recover
- Restore system or data if unable to prevent the attacks
- NIST GGSS
- NIST Guide to General Server Security addresses general security issues related to typical servers.
- ENISA
- European Union Agency for Network and Information Security - ENISA is similar to NIST that focuses on information security enterprise for the EU.
- ISO/IEC
- Common Security Framework ISO/IEC
- ISO - International Standard Organization
- IEC - International Electrotechnical Commission
- ISO 21K
- ISO 21K is cyber security framework
- ISO 27K
- ISO 27K contains overall series of information security standards
- ISO 27001 information security management standards
- ISO 27002 provides best practices for information security controls
- ISO 27017 and 27018 references cloud security
- ISO 27701 focus on personal data and privacy
- ISO 31K
- ISO/IEC 31K is an international standard providing an overall framework for enterprise risk management practices - ERM, includes performing risk assessments
- CSA
- CSA is abbreviated as Cloud Security Alliance
- CSA is a non-profit organization to assist cloud service providers - CSP for providing secure platforms
- CCM - Cloud Controls Matrix, security guidance for using cloud platform and best practices to be followed
- CCM list of specific controls should be adopted by the CSPs.
- COBIT
- Control Objectives for Information and Related Technology - COBIT
- A set of best practices for IT management.
- COSO
- The Committee of Sponsoring Organizations (COSO) of the Treadway Commission for enterprise governance and risk management to reduce fraud in organizations.
- HITRUST CSF
- Health Information Trust Alliance Common Security Framework for healthcare information.
- SSAE
- The Statement on Standards for Attestation Engagements - SSAE
- Audit specifications developed by American Institute of Certified Public Accountants AICPA for the CSPs.
- SOC2 - Service Organization Controls, results in reports which evaluates the internal controls implemented; practices around confidentially, integrity, availability and privacy; by the service providers to ensure compliance with Trust Service Criteria - TSC where storing or processing customer data. Includes evaluating the firewalls, intrusion detection, multi factor authentication.
- SOC3 - a less detailed report of SOC2 for everyones knowledge.
- Type I audit
- Tests controls in place at a particular point in time.
- Type II
- Tests controls over a period of at least six consecutive months.
- CIS
- Centre of Internet Security, non profit institute developed by SANS Institution, maintaining the security controls.
- CIS CSC - Critical Security Controls for effective cyber defence. It is designed to improve cyber defences making it implementable for IT professionals.
- CIS RAM - Risk Assessment Method, can be used to perform an overall emulation of security.
- CIS CAT - Configuration Access Tool, can be used with automated vulnerability scanners to test compliance against the benchmarks
- STIG
- Security Technical Implementation Guides developed by Department of Defence Cyber Exchange, hardening guide for hardware and software
- OWASP
- Open Web Application Security Project - OWASP, is a non-profile community publishes best security practices and have built tools Zed Attack Proxy/Juice Shop to help to investigate security issues.
- OCTAVE
- Operational Critical Threat, Asset and Vulnerability Evaluation - OCTAVE
- For educational institution.
Security Job Roles
- CIO, CEO, CTO
- Liable for external and internal security
- Director of Security, Chief Security Officer, Chief Information Security Officer
- Overall responsibility for security
- Managers
- Responsible for the domain or section of the business/infra
- Information Security System Officer, Specialist
- Responsible for implementation, maintaining and monitoring
- Every Employee
- Responsible of the actions and needs to comply with the corporate policy
Information Security Business Units
Security Operation Centre (SOC)
- A location where the security professional monitor and protect critical information across organization.
- The physical entry and exit is usually for restricted for all, allowing only required employees.
DevSecOps
- Traditionally the software development involves only in developing code, with increasing cloud and container driven architecture there is more collaboration between developers and system administrators leading to DevOps.
- DevSecOps has extended the boundary to security specialities, making security as primary consideration in the development and deployment.
- DevSecOps comprises of Development, Security and Operations making the code move production faster and secure.
Incident Response
- Dedicated team responsible for handling security incidents.
- Acts as the single point of contact as a independent business unit, but at times handled as part of SOC.
- Teams are called as:
- CIRT - Cyber Incident Response Team
- CERT - Computer Emergency Response Team
- CSIRT - Computer Security Incident Response Team
Security Control Categories
Technical
- The control implemented as a system which could be hardware or software.
- Eg: firewall, anti-virus, logging, encryption, data classification system, access controls, security patches and updates, change the default authentications, hardening of systems - web application, os, application server, networking infrastructure devices
Operational
- The control implemented by people, forms outer line of defence includes physical controls and organization controls.
- Eg: security guards, training programs, protecting storage systems including backup systems, surveillance systems
Managerial
- The control gives oversight of the information system and address system design and implementation
- This is also called as Administration control
- Eg: risk identification, tools to evaluate or suggest security fixes, security awareness trainings, personnel background checks, change management process, security policies and procedures,
Security Control Function Types
Preventive
- The precaution taken to avoid an attack, physically control access in virtual world.
- Eg: ACL, firewalls, anti-virus, anti-malware - prevention from malicious content, control access including physical, door lock, security guard, IPS intrusion prevention system, firewalls, anti-malware.
Detective
- Identify the attack during the progress of an attack, here it may not prevent the attack.
- Eg: Log monitoring, motion detector, IDS, checksum, CCTV, alarms, security reviews and audit, mandatory vacation, rotation of duties, anti-malware - detection of malicious content in the existing system.
Corrective
- Correction or recovery made after an attack to mitigate the damage.
- Eg: Restore, patch management, backups can mitigate the attack, backup sites can provide control over natural or man made disaster, add IPS can block the attacker in future, anti-malware - fix infected files, vulnerability mitigation.
Physical
- Physical controls placed to avoid attacks in real world.
- Eg: Alarms, gateways, locks, security cameras, fences.
Deterrent
- Psychologically discourage the attacker to perform attacks, but may not directly prevent access.
- Deterrent, does not stop unauthorized access
- Eg: Warning boards, legal penalties, lights.
Compensating
- Controls which serves as the substitute if any of the primary controls are not in place, this does not prevent an attack but restores back to normal.
- Eg: Restore from the backups, hot-site, backup power systems.
Security Regulations, Laws and Standards
- SOX
- Sarbanes Oxley Act, developed by US governs the financial and accounting disclosure information to protect investors from fraudulent financial reporting by corporations, mandates the implementation for risk assessments, internal and audit controls.
- CSA
- Computer Security Act developed in 1987 requires federal agencies to develop security policies for confidential information.
- GDPR
- General Data Protection Regulations, developed by European Union for handling confidential data under data privacy act.
- User can control where the data goes, and have right to be forgotten.
- Each sites have privacy policy tells all in detail about the data gathered, data usage, data stored and user's privacy right.
- Privacy of individuals are protected which includes, Name, address, photo, mail address, bank details, identify proofs - PAN/Aadhar/SSN, medical information, IP address and so on.
- HIPAA
- Health Insurance Portability and Accountability Act, regulations for health organizations.
- PCI DSS
- Payment Card Industry Data Security Standard (PCI DSS) a standard for protecting credit cards in order to reduce fraud.
- Defines the safe handling and storage of financial information.
- Need to comply with PCI DSS if dealing with credit card in businesses.
- Six control objectives:
- Secure network
- Secure end-to-end card details
- Always patched
- Strong Access control measures
- Regular audit and monitor
- Maintain information security policy
- GLBA
- Gramm–Leach–Bliley Act (GLBA) establishes the privacy rules for financial services.
- CCPA
- California Consumer Privacy Act (CCPA), personal data regulations.
- FISMA
- Federal Information Security Act was introduced in 2002 to govern the data processed by federal agencies.
- PIPEDA
- Is a Canadian law that governs the collection and the use of personal information.
Security Policies
AUP - Acceptance Use Policy
- AUP provides a detailed documentation on how the company assets should be used, such mobile or laptop given from organization should not used for personal reasons.
- If any of the assets are misused, employer could take action against the violation.
- This policy will help the organization to minimize the risk.
Business Policies
- Job Rotation, not allowing one to be in same position for ling time.
- Mandatory Vacations, a person needs to leave their job and go for vacation for some time. As during this time the task will be handled by someone, removing the dependency and validate if there was any security violations limiting the ability to commit fraud.
- Separation of Duties, allowing to split knowledge such as to unlock a system keys from two or more persons are needed.
- Clean Desk Policy, no sensitive information should be easily or openly available, always locked both hard copies and soft copies locking the system.
- Least Privilege, only required access provided to perform the action.
- Background Checks, while hiring making sure of your history is clear.
- NDA - Non disclosure agreement, contract preventing employees sharing confidential information.
- Social Media Analysis, using individuals social media policy allowing one to hire or not.
- Onboarding Policy, steps needs to taken care while hiring a new employee such signing the AUP, access to the system, trainings and so on.
- Off-boarding Policy, steps needs to taken care while the employee leaves such as access restriction, preserving encryption keys and so on.
- User Training, below are the ways users needs to be trained to perform the job.
- Gamification
- CTF - Capture the Flag usually security related competition
- Phishing simulation
- CBT - Computer Based Test
- In Person
- Specialized training, before allowing to take the job to understand the role and security aspects.
- Vendor Policies
- Disciplinary and Adverse Actions, policies specify to consequences for violations.
- Exit Interviews, help to identify workplace factors that lead employee to leave the organization.
- Supply chain assessments, evaluate co-ordination and security process between groups.
- Business partners policies to handle risk effectively.
- SLA - Service Level Agreement, terms decided on the services uptime, response and so on from the service providers.
- MOU / MOA - Memorandum of Understanding / Memorandum of Agreement, consent signed between both the sides.
- MSA - Measurement System Analysis will assess the measurement process and calculate the uncertainty. Used with quality management systems such as Six Sigma.
- BPA - Business Partnership Agreement, policies such as decision making agreements, owner stake, financial contract.
- ISA - Interconnection Security Agreement, purposes the technical requirement of the interconnections between organizations using shared IT systems.
- EOL - End Of Life, manufacture may end but continue support
- EOSL - End of Service Life, no longer provide support and security patches.
Privacy VS Security
- The value of the information is determined in the impact of it being compromised.
- Data security is an important factor, but privacy is an equal factor as well.
- Privacy:
- Personnel data is any information about an identifiable individual.
- Data governance required when collecting and processing with personnel data.
- Privacy ensures there are required policies, to identify private data, storage, processing and retention.
- Limited access to the private data only to authorized persons.
- Security:
- Data security focus on CIA attributes.
- Data must kept securely while processing and storage.
- Identity management, allowing only authorized and authenticated person to read or write the data.
Information Life Cycle Management
- Creation
- Distribution
- Use
- Maintenance
- Archive
- Disposal
Data Roles and Responsibility
- Data governance
- Data owner
- Accountable for specific data often a senior officer
- Determine data classification
- Data steward
- Manages the data governance
- Responsible for data accuracy, privacy, compliance and security
- Data classification
- Maps sensitivity labels to the data
- Such as public, private, confidential, personnel, etc
- Data custodian/steward
- Implementing the data classification and security controls
- Data privacy officer (DPO)
- Responsible for the organizations's data security
- Sets policies, implements processes and procedures
- Data controller
- Manages the purposes and means by which personal data is processed.
- Data collector
- Data processor
- Processes the data on behalf of the data controller.
Data Classifications
- Public / Unclassified
- Non sensitive data
- Press releases, marketing materials
- Confidential
- Data reserved for certain employees with an organization
- Critical
- Data should always be available
- Proprietary
Data disclosed outside the organization on a limited basis. Eg: NDA
- Private / Personal / Restricted / Internal Use Only / Classified
- Data used within specific division, eg: payroll details of employees only for HR and respective individually
- Sensitive
- Severe impact to the organization if it were exposed
- Note
- Data classification should also consider data accuracy, integrity and availability.
- Eg: Publicly classified data should be accurate.
Data Policies
- Privacy Notices
- Data Retention
- Keeps the files that change frequently for version control
- Impact Assessments
- Data Sovereignty
- Geographical Considerations
- Data Sharing
- Privacy Terms of Agreement
- SLA
- ISA
- NDA
- DSUA
- Credential Policies
- General guidelines are password should not be embedded with the application, passwords in clear text much must not be saved nor be transferred over network.
- Every user needs to have its own user account and personal information should be access to him/her. Users should not have privileged access as this could lead the malware to run as the user easily.
- For administers also should have user account but for performing administration can use elevated access for each.
- Third party accounts can be created for additional vendor based applications access, but these accounts should also be never shared.
- Device accounts for accessing the device, holding the device certificate and require passwords for screen unlock. This can be managed through MDM, Mobile Device Management. For unlock could also include geolocation validation.
- Service accounts, access can be defined for a specific service and the password/key rotation policies should be place avoiding unexpected breaches.
- Administrator or root accounts, these accounts should not be used as normal administration.
- Change management policies ensuring the changes are planned, tested, frequency of the change, installation steps, fallback procedures and scrutiny plan has be done before making changes.
- Asset management, identify and track computing assets, making sure all the security patches are applied, track licenses.
- FRCP : The United States, Federal Rules of Civil Procedure. have implications for data retention policies.
- PII - Personally Identifiable Information
- Customer Data
- PHI - Personal Health Information
- Financial Information
- Government Data
Data Breach Consequences
- Organization Impact
- Reputation Damage
- Identity Theft
- Fines
- IP Theft
- Notification
- Escalation
- Public Notification and Disclosure
Data Protection
- Data at Rest
- Data in Transit
- Data in Use
- Data Exfiltration
- Rights Management Services
- Privacy Enhancing Technologies
- Data minimization
- Deidentification
- Data Masking
- Tokenization
- Aggregation/Banding
- Hashing and Salting
- Anonymization
- Making the data impossible to identify individual data from the dataset.
- The data cannot be reversed to actual data, no way to associate the data to the user.
- Pseudo anonymization
- Data Loss Prevention
- Policy Server
- Endpoint Agents
- Network Agents
Risk Management Process
Risk Assessment
- Identify Threat and Vulnerabilities
- External Threats
- Internal Threats
- Legacy Systems
- Multi Party Risk
- Intellectual Property Theft
- Software compliance/licenses
- Quantitative Risk Assessment
- ARO (Annualized Rate of Occurrence)
- Determine the likelihood of occurrence
- Is the estimation possibility of a specific threat taking place in a one-year time period
- SLE (Single Loss Expectancy)
- Determine the magnitude of the impact
- Monetary loss occurs every time
- Formula
- Asset Value * Exposure Factor = SLE
- ALE (Annualized Loss Expectancy)
- Determine the magnitude of the impact
- Formula
- SLE * ARO = ALE
- Qualitative Risk Assessment
- Risk Register
- Risk Matrix
- Risk Heat Map
- Site Risk Assessment
- Location level risk assessments.
- Recovery plan should include - applications, personal, equipment and work environment
- Insurance planning
- Privacy Impact Assessment - PIA
- Privacy risk needs to be identified in each initiative
- Privacy Threshold Assessment - PTA
- Used to determine system contains PII information for impact analysis and protection of the data.
- Eg: Distributing a questionnaire to system and application owner.
Risk Analysis
- Risk Register
- Risk Register is strategic component of an organization, providing single point of entry to record information about identified risks.
- Every project has some risk associated with it, identify and document the risk associated with each step.
- Apply all the possible solutions to the identified risks and monitor the risks.
- Helps the organization's risk tolerance and risk appetite are met.
- Risk Matrix / Risk Heat
- Visualize and view the result of the risk assessment, quantify the risk.
- Combines the likelihood (likely, possible, unlikely) of an event with potential impact (negligible, minor, major) and assists with making strategic decisions.
![]() |
| Credits: https://www.balbix.com/app/uploads/risk-heat-map-trimmed.png |
- Inherent Risk
- Risk exists in the absence of any controls take place to avoid risk.
- Residual Risk
- Risk exists after the necessary controls taken place.
- Risk appetite and Risk tolerance
- Risk the organization is willing to take.
- Risk Awareness
- Knowledge about the risk is crucial for everyone in the organization.
Risk Management Strategies
- Risk Mitigation/Deterrence
- Decrease the risk level, by investing in security systems
- Risk Avoidance
- Stop participating in a high risk activity
- Risk Transference
- Buy some cybersecurity insurance
- Risk Acceptance
- Business decision to accept the risk
- Control Risk
- Risk Awareness
- Documentation
- Term of Services / Term of Use / Terms and conditions
- Privacy notice / Privacy policy
Business Impact Analysis
- Process of determining the potential impacts resulting from the interruption of time sensitive or critical business process
- Risk assessment focuses on the relative likelihood of potential threats to an organization, a BIA focuses on the relative impact of the loss of operational capability on critical business functions.
- Ensure key business is continued:
- BCP - Business Continuity Plan
- COOP - Continuity of Operations of Plan
- ICS - Identification of Critical Systems
- Identify critical systems and components
- Alternative solutions needs to be planned on failure of these
- SPoF - Single Point Failure
- SPoF creates potential risk in bringing the entire system down
- Should be avoided with fault tolerance system and redundance
- MTD - Mobile Threat Defence
- RTO - Recovery Time Objective
- Specifies allowable time to recover
- WRT - Work Recovery Time
- RPO - Recovery Point Objective
- Specifies allowable data loss
- MTTF - Mean Time To Failure
- Length of the time system is expected to work with failures or crashes
- MTTF is collected by running many units and calculate the average based on when components fail
- MTTF is used for non repairable systems
- MTBF - Mean Time Between Failures
- Predict the time between outages or failures
- MTBF is used for repairable systems
- MTTR - Mean Time To Repair
- Time required to fix the issue
Disasters
- Internal Vs External
- Person Made
- Environmental
- Site Risk Assessment
- Disaster Recovery Plans
- Functional Recover Plans
- Mission Essential Functions








