Thursday, 17 November 2022

Incident Management

 


Introduction

Every organization irrespective how secure they are, there will be incidents occurring either internal or external. Planning for such incidents are vital. We will see life cycle which covers the responsibilities from identification to investigation and to mitigation. 


Incident Response

As a security engineer one might need to face and handle different security issues every day such as malware detection, buffer overflow attack, DDOS attack, data theft, access misuse, disruption, down time, ransom attack and so on.

NIST - National Institute of Security and Technology provides complete security handbook called "NIST Special Publication 800-61 Revision 2" - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf guidelines to handle the incident response lifecycle.

Incident Response Lifecycle

  • Preparation
  • Detection and Analysis
  • Containment, Eradication and Recovery
  • Post Incident Activity 


Incident Response Planning - Preparation

Incident response planning involves in preparation, roles, rules and procedures to tackle incident.
  • Documentation
    • Communication details and protocols
    • Documentation for incident analysis
    • Incident mitigation software
    • Capture the data, including hardware and software to use later as evidence
    • Policies while handling incidents
  • Roles and Responsibilities:
    • Incident Response Team - IRT, Cyber Incident Response Team - CIRT, SME plans and executes how to handle the intrusion. Trained team to handle the incidents for the entire cycle
    • IT security management, precaution and post action measures such as firewalls
    • Compliance officers, planning and communication
    • Technical staff, helps in resolving 
    • Users, awareness and training
    • Vendors, awareness and training
    • Management, strategies
    • Communications team, informing the press or infected parties
    • Legal team, decides when the information needs to be shared
    • CIO - Chief Information Officer, CISO - Chief Information Security Officer, mission, policies and decision making
  • Exercise
    • It is important to ensure effectiveness during an event or identify any deficiencies in the process that should be addressed.
    • Mock runs without impacting production or any system, rehearsal.
    • Functional exercises, run through actual drill as they would perform during actual emergency. 
    • Tabletop exercises as full drill would be time consuming and expensive, these would be in smaller simulated disaster version.
    • Walk through, discuss and test processes, procedure from the tabletop exercise.
    • Simulation, test the simulated event such as phishing attack
  • Training, is critical to be given periodically to each teams based on their roles and responsibilities. Hence each roles and responsibilities needs to be clearing defined.
  • Jump Kit
    • As like first-aid, jump kit is prepared and available for immediate use of an incident.
    • Communication
      • Contact list needs to be update to date and accessible for everyone.
    • Hardware and software for analysis and mitigation
      • Secure storage facility
      • Forensics workstations
      • Portable printer
      • Protocol analyzer
    • Ancillary analysis resources
      • Port lists
      • Network diagrams
      • Application architecture
  • Continuity or Recovery Plans
    • Disaster Recovery Plan
      • To ensure full recovery of operational capacity following the natural disaster.
      • Documentation, planning and periodic tests needs to be done.
    • BCP or COOP - Continuity of operations planning
      • Ensures the continuity of operations by restorations of an organization functions in the shortest time possible, even if the services resume at reduced level during emergency.
      • COOP is similar to BCP but primarily focus on government and public sectors.
    • Based on the incident either of the plan could be considered as part of recovery.
    • Fundamentals of any disaster recovery plan involves backups.
    • Retention Policies
      • Backup of copies
      • Regulatory compliance
      • Operational needs


Attack Frameworks

IRT needs to understand the process of attack, how they are executed, and how to prevent. Having knowledge of these frameworks are crucial.
  • Cyber Kill Chain
    • Lockheed Martin developed to defend its network based on chain of attacks made by the attacker.
    • Cyber kill chain adopts this process in cyber security.
    • The cyber kill chain has steps involved the attacker attacks the system from the beginning to end, as a security engineer one needs to break this chain as early as possible.
    • Lockheed Martin's cyber kill chain attack from the attacker's perspective in general includes below stages:
      • Reconnaissance: Identifying the target
      • Weaponization: Preparing for the attack
      • Delivery: Launching the attack
      • Exploitation: Gaining access from the attack
      • Installation: Establishing persistence
      • Command and Control: Enabling remote control for further manipulation
      • Actions: Achieving the goals
    • In order to defend, we need to understand the attacker's actions.
    • There are different tools and solutions used at each stage, to break the chain before the attack reaches the goal.
  • MITRE ATT&CK
    • MITRE ATT&CK - Adversarial Tactics, Techniques and Common Knowledge Framework was created by MITRE Non Profit Organization in 2013 to document attacker tactics and techniques based on real-world observations.
    • The document continues to evolve providing the organization's incident response team to understand the attackers behaviour and plan ahead to mitigate these attacks.
Credit: https://anomali.cdn.rackfoundry.net/images/uploads/research/mitre-attck-navigator.png
  • Diamond Model of Intrusion Analysis
    • Another similar framework to describe cyber attacks.
    • There are 4 parts giving a comprehensive view for cyber attacks.
      • Adversary
        • Details about the attacker, who, why or purpose of the attack
      • Infrastructure
        • Infected physical or logical systems or data leak details
      • Capability
        • Develop or deploy using the attack tools or techniques
      • Target
        • Affected area, data centre or country or region
    • The model provides flexible framework to analyze the threat as cognitive (understand interrelated logic) and as well as mathematical(improves strategic).
Credit: https://ars.els-cdn.com/content/image/1-s2.0-S0167404822002024-gr20.jpg


Incident Detection

  • Challenge
    • It is difficult to identify an incident has occurred as there is huge volume of data and hard to detect legitimate threats.
    • Incidents are complex extensive knowledge is needed.
  • Precursor
    • Sign that an incident might occur in future
    • Logs or vulnerability scanners giving the heads up incident
    • Network traffic deviate from normal flow
    • Unauthorized host configuration change alerts
  • Indicators
    • Sign of incident has occurred or may be occurring
    • Alarms from anti malware or anti virus software
    • Alerts from intrusion detection/prevention system
    • Exploit announcement
    • Direct contact from the attackers reach for ransom
  • Isolation and Containment
    • Sandboxes, to avoid malware spreading over the network it has brought to isolation run the malware and analyze the results
    • Malware are smart at times they run differently or destruct the running system if they are isolated or unable to connect to other systems in network.
  • Recovery after Incident
    • Removing the malware is important following one of the methods
      • Restore from backups
      • Rebuild from scratch
      • Replace compromised files
      • Disable breached user accounts and create new 
    • Tighten the system, such as 
      • Firewalls
      • Enable Multi Factor Authentication
      • Certificate changes
  • Reconstitution
    • Eradication means removing the element of the incident such as malware.
    • Recovery is restore systems to normally functional operations.
    • Not all the incidents requires eradication, for some only recovery but be good enough, and sometimes bother eradication and recovery needs to work hand in hand.
    • Eradication and recovery should be done in phased approach as recovery may take time and it needs to be efficient.
  • Documentation
    • Lessons learnt from the incident needs to be captured with all the details along with time and to be improved over a period of time.
      • Functional impact of the incident, categorization such high impact or low
      • Information impact of the incident, type of impact on the information, eg: data leak of PII can be classified as data breach
      • Recoverability from the incident
    • Post incident analysis documentation for future prevention.


Investigations

Suspected incident or indicators needs to analysed, first step would be to confirm if it is true positive. Different tools and frameworks are available to determine the scope of the incident. IRT will help the team to prioritize potential issue for deeper analysis or to take next action of incident mitigation.


Identify Vulnerability 

In the given system the vulnerability scanner will scan the entire device or application to check if there are any know vulnerabilities. In general these scanners will scan and match the signatures of existing identified vulnerabilities present in the device or it could warn us with the security controls not in place. 

After discovery we can read about the vulnerability and how to resolve this from different sources available in the internet or the vulnerability scanner itself can provide the details. One of the most popular site to refer is National Vulnerability Database at "https://nvd.nist.gov/vuln".

The scan report includes the issues such as malware found, firewall not configured, old version software found, unencrypted telnet server and much more. The report could produce false positives where it has identified a vulnerability but in reality it is not, which we need to be aware of. Sometimes it can have false negatives, the real issue is missed to report. To avoid such scenarios have the scanner up to date along with the signatures.

Credit: https://docs.gitlab.com/ee/user/application_security/vulnerability_report/img/project_level_vulnerability_report_v14_5.png


SIEM - Security Information and Event Management

SIEM is centralized log system, which will consolidate all the information and logs from different source systems such as operating systems, firewalls, routers, web servers, database servers, application servers and so on, to analyze from single reporting tool.

The logs are parsed and stored in common format, as each system would produce different style logs. As the single reporting system these information will converted and also tagged with different category, such as source system could tagged as linux, linux oracle server, and so on. Further each log entries would categorized as information, warnings, errors or urgent.

As these informations are collected over of a period of time it could be used to see the trends and proactively provide alerts or alarms. Additional reports and intelligence could be fed into these systems. SIEM provides interactive dashboards with charts, graphs, trends which can help investigator explore the data through interactive drilldowns.

Credit: https://www.softwaretestinghelp.com/wp-content/qa/uploads/2019/06/Splunk.png


Logging

Security monitoring process involves in creating and analyzing extensive logs and data. Log files will guide us where to look for the related data. Using these files we can gather information root cause information and plan for the solution. Hence while creating log files we  need to be careful as it takes up system resources - too much logs will be bog down the read operation though necessary information should be logged.

Log Files:
  • Network logs
    • Switch logs
    • Router logs
    • Firewall logs
    • DNS logs
  • Operating system logs
  • Application logs
  • Web application logs
  • Database logs
  • Audit logs
  • System logs
  • Call Manager logs
  • Bandwidth logs
  • Security logs
  • Access logs - requests and connections between systems
Log Management:
  • Syslogs
    • Transferring logs from one device to centralized database usually SIEM is called syslogs in Linux.
    • Logs come with different severity levels - debug, information, warning, error or fatal, we can configure to capture based on the level. Log level warning is good for the production and debug for development environment.
    • Daemons running syslog are:
      • syslog - syslog message includes the facility code and the severity level. A facility code is used to specify the type of system that is logging the message. Messages with different facilities may be handled differently. Eg: 0 - kernel messages, 1 - user messages, 2 - mail messages.
      • rsyslog - Rocket Fast System Log
      • syslog-ng - Logging with filter
      • nxlog - Multi operating system platform log collector
  • Journalctl
    • The journald daemon collects data from all available sources and stores them in a binary format for easy and dynamic manipulation.
    • Journalctl command is used to view, search and filter the logs stored in the binary format.
  • Metadata
    • The data that describes other data sources. Will be useful while performing the incident analysis.
    • Eg: for email we will have standard header storing the sending and destination address, in mobile having the gps locations, etc.
  • Network Activity
    • Netflow
      • Gathers the traffic statistics from all the traffic flow in the entire network.
    • IPFIX
      • IP Flow Information Export, tracks the IP actions in the network
      • IPFIX collects the data packets from across the network, organized by an Exporter which sends the compiled version to the Collector.
      • IPFIX provides the flexibility by customizing the templates, these templates outlines the data the user wants to collect.
      • Serves as industry standard for the export of flow information from network devices.
    • sFlow
      • Sampled Flow, used for monitoring high speed switched networks.
      • Packet sampling in embedded technology is used to monitor network devices such switches, routers, wireless access points.
      • Only the portion of the actual network traffic is captured, yet been found useful in getting the complete network visibility, for defence against security threats.
    • Protocol analyser
      • Able to analyse the traffic at packet level, several tools such as wireshark protocol analyser


Incident Mitigation

In the process of incident mitigation is a critical part of the incident response process. Applying mitigation techniques or controls in order to secure an environment is a key to containment, eradication and recovery phases.

Incident mitigation requires eradication or containment of the malware for securing an endpoint as a precaution. An endpoint could be desktop computer, laptop, smartphone or tablet. As a security team its our responsibility for monitoring all of these different devices.


Approach

Controlling the applications running on the endpoint, creates more secure and stable environment.
  • Allow List
    • Create a list of applications that are approved
    • Allow only the approved applications to run on the endpoint
    • Restrictive approach 
  • Deny List
    • Maintain deny list of applications
    • These list of applications will not be allowed to be executed on the endpoint
    • Anti-virus and anti-malware behaves the same
  • Quarantine
    • Applications suspected to be malicious will not be allowed to run.
    • It will move from that system and place it into a quarantine area, where no applications are allowed to run. This does not mean removing it or cleaning it, just in different area to avoid spread.
    • Later security team can perform additional analysis on the suspected application and this will avoid its spread if proven malignant. 


Criteria

An ability to run or not run an application in an operating system is commonly built into the core functionality of the os. Security team can enable to disable different parameters to allow certain software to run or deny.
  • Application Hash: Execute only if hash of the executable matches on the system.
  • Certificate: Execute only if the digital signature matches.
  • Path: Limit permissions to certain folders, allowing to be executed only from certain folders. Eg: one may run an application with local rights and accessing only those certain folders. Here this cannot extend accessing the folders belongs to root or other users.
  • Network zone: Set a policy that would allow or disallow an application to run based on the zone it is executing from. Eg: an application run in private area but prohibited to be executed in public zone. 


Controls

  • Firewalls
    • Allow or deny application traversing in the network
    • Block using rules such as ip address block or allow, zone wise allow or block
  • MDM - Mobile Device Manager
    • Have rules on the mobile devices that can allow or disallow access.
    • These rules or polices can be configured using MDM and only security administrator can set or unset the policies
  • DLP - Data Loss Prevention
    • DLP identifies and blocks the transfer of any PII - Personally Identifiable Information.
    • Eg: Credit card numbers, social security number, etc if it has been transferred outside will be blocked.
  • Content filter/URL filter
    • Restrict or allow only certain websites.
    • Many of the these URL filters can also be integrated with third party blocklists.
    • Blocklists can be updated constantly allowing real time blocking the malicious sites.
  • Certificates
    • Allow access from only trusted devices
    • Deny the access if it does not have trusted certificate on that device
  • Isolation
    • Isolation is a process where a device or application is moved into an area where it has limited or no access to other resources.
    • It is a key strategy while fighting against malicious software or software thats constantly trying to communicate back to a command and control location.
    • Network Isolation
      • Isolating device to a different network disabling the access to the rest of the network, when suspected malicious or not fully protected.
      • No communication to other devices.
    • Process Isolation
      • When a process running on the device seems to be suspicious, we can disallow any access from that process to the rest of the network.
      • This will limit application execution but allow device management.
  • Containment
    • Run each application in its own sandbox, limiting the interaction with the host operating system and other applications.
    • Here it prevents the spread of malicious software to prevent from jumping outside of that application to infect the local machine or other devices in the network.
  • Segmentation
    • In general extensive security is created between the outside of the network and internal network. But once the malicious software enters inside network it is able to traverse freely without any concern of being blocked.
    • To overcome this network administrators have started to create segmented networks within the network. 
    • Eg: Database is usually placed in a network where it can be accessed only from backend application. And web application servers can be accessed from internet but internally it can only interact with backend applications.
  • SOAR - Security, Orchestration, Automation and Response
    • As there are different and many controls needs to be taken care, it would be challenging and mistakes can occur if done manually.
    • To automate these processes we need SOAR.
    • Using SOAR, an admin can integrate multiple third party tools and have them all work together.
    • Runbooks
      • A runbook holds detailed steps on how to perform particular task
    • Playbooks
      • When a particular event occurs, a set of runbook together performed is called a playbook.


References and Credits

https://gluu.biz/wp-content/uploads/2020/05/incident-management.png
https://www.professormesser.com/security-plus/sy0-601/sy0-601-video/sy0-601-comptia-security-plus-course/

Thursday, 10 November 2022

Cloud Cybersecurity Solutions


 

Introduction

Cloud enables elasticity allowing users to dynamically avail resources based on the needs and only pay for what they use. Voila! a great invention for the digital world.

Allowing only authenticated services to scale up or down and ease of ramping up or down with immediate visibility to the authorized admins. The authentication, authorization, firewalls, audit and transaction visibility are crucial steps in cloud security. 

Though we technically own the servers, but as we know mostly we don't have physical control on the servers, leading to additional care. Cloud security it is shared responsibility of the customer and the cloud service provider - CSP. 

Today we shall discuss about cloud infrastructure and some of key elements in towards its security. 


Region and Availability Zones

Uptime and availability are one of the two important aspects of cloud security. Regions are different geographic locations the service providers maintain their infrastructure. For each region there can be more than one Availability Zones - AZ. For example a cloud service provider could support two regions India and Australia, and in each of the regions there could multiple AZs for instance in India two AZs in Mumbai but different parts.

Each of the AZs are self contained and independent. Each having different power providers, separate network confirmations and so on. Making in reliable, if any one AZs downtime will not affect the other AZ.

As user we can take advantage of this, and could configure our application to the nearest region of our users in order to reduce latency. Also load balance either through active/active or active/standby configuration. Providing the flexibility to switch when there is an issue or overload requests, enabling high availability.

Each region cost may different of the services and not all regions would provide all the services. Also while selecting the region the compliance regulations needs to be considered. 


Virtual Private Cloud (VPC)

In a public cloud space we can create a private isolated network known as VPC. It is just like the private cloud having both public and private subnets. The private does not exposing the IP addresses as public address and can be accessible only through restricted means. VPC is essentially at the network layer as a IAAS service. 

An analogy, in a IT parks we have different organizations having different facilities such as parks, auditorium but the work area is private only employees or restricted person can enter. Here private area is similar to VPC, we have major control over it and as well its considered to be secure. Separation is security opportunity, eg the web servers can be accessed from anywhere but the database should be accessed only by the backend application servers.

Multiple subnets could be created in the single VPC, definitely within the range of IP addresses the VPC is created with. The subnet could be either private or public, this draws the line for the servers in these network not to access from public network. 

VPC Gateway endpoints, allows connecting multiple VPCs keeping the data private without using the internet.

Virtual LAN (VLAN) is as like LAN way of partitioning the network as the group of servers connected can access each other without hitting internet. Here the partitioning occurs in the layer two of OSI model.

Virtual Private Network (VPN) uses encryption on top of the public network, making it secure and avoiding man-in-middle attacks.


Firewall

Security groups are acting as a “firewall” on instances. Using security group, we can control both the incoming and outgoing traffic. They are stateful, which means any traffic in is allowed to go out, can go back in. Supports only allow rules, means traffic cannot be explicitly blocked, rather only allow configured traffic in. 


NACLs are acting as a “firewall” at the subnet level. We can associate a single NACL to multiple subnets, but only one NACL can be assigned a subnet.


These stateless as the inbound and outbound rules apply for all traffic. For example, if the output traffic is allowed our request would reach out, but if expect a response, sorry it would need to have the outbound rules specified. Supports all both allow and deny rules for both inbound and outbound traffic. Here we can specify only reference a CIDR range (no hostname). 


Additionally we have services provided by CSPs to protect at different layers of OSI, such as WAF - web application firewall secures at layer 7, Network firewall protects at layer - 4 and so on. This could enhance the security blocking unusual API calls, not allowing or allowing access from certain geographic locations, track and report attempts made to access critical data.


IAM Policies

In cloud access to resources is governed by policies and their permissions centrally with audit enabled by default. Each policy can be attached to the entity, user, user group or a role.  

There are two basic policies either we call it identity based policy or resource based policy. Under identity based policy permissions are given to the user, user group or role. And for the resource based policy these policies define who can access and what activities they are allowed to perform.

Stating access will be granted only when both the policies allow, if either is denied access will not be granted. By default all the access would be denied, explicit allow only grants the access. But if there is explicit deny it will get higher precedence and access will be denied.

Granular access policies can be set such as allow or disallow certain IP addresses, data and time, group, geographic locations, etc. 


Managing Secrets

Applications that use API Keys, encryption keys or credentials should not have it hard coded. Cloud provides services to handle the secrets elegantly. Secrets are encrypted at rest and in transit. 

Secrets management protects and manages the access to the applications and services. IAM policies makes sure one has access to secrets. 


Central Logging

Monitoring and audit is crucial phase of cybersecurity. Cloud provides framework and services to manage and enable monitoring granular level. 

IAM access, policy change, infrastructure changes are some of the common tasks where the logging is default enabled and aggregated in the central location. But these would not be sufficient, cloud provides APIs to write more and customized logs based on the user's requirement.

These centralized logs can be further used for further inspecting and analysis, as well integrate with any SEIM Solution. Intuitive reports could be created from these logs. 


Cloud Access Security Broker (CASB)

Each cloud service provider provides a set of tools enabling the security tools. But there could be gaps or the requirements could not be matched by them. And as the data resides with the cloud service provider maintaining security and adhering security policies becomes important. In such scenarios on premises or third party offerings - CASB come to a rescue, fill in the gaps and compliment cloud security services. This is placed between the cloud consumer and cloud provider.  

CASB provides security software as a service addressing cloud service risks, enforce security policy, threat protection, data security, comply with regulations. This can be implemented as software running either locally or in cloud. CASB operates on four primary characteristics:
  • Visibility: Visibility on the entire processes running on cloud and if it authorized. Validation and avoiding misconfigurations.
  • Compliance: Following organization own or mandated policies, like HIPAA, PCI
  • Threat prevention: Allow only authenticated and authorized users to the granular level, including multi level approvals or multi factor authentication.
  • Data security: Protect and encrypt the sensitive data at rest and in transit. Ensure APIs is secure, where the attackers can exploit the interfaces.

CASB along with next-generation secure-web gateways (SWGs) monitoring and management of web APIs and user/entity behaviour analytics (UEBA) provide the capability to deliver static and dynamic access to the management.  

CASB is evolving into on huge service known as Secure Access Service Edge (SASE) architecture. SASE combines multiple security and networking technologies to provide comprehensive web and cloud security. Security Service Edge (SSE) is the convergence of multiple cloud-based security services as part of a Secure Access Service Edge (SASE) architecture. 


Security Awareness

Structural awareness solutions help manage risk and apply protections to systems and data.

  • Cloud compliance and best practices: Visualization and continual assessment of the environment, including the ability to enforce known good standards
  • Instance and container visibility: Monitoring and protection of containers through their life cycle
  • Virtual private network: Secure access to applications running in a VPC for remote employees
  • Secure data: Encryption and key management solutions to protect data and meet regulatory compliance standards
  • Vulnerability assessment and management: Visibility into the attack surface to discover and resolve security issues
  • Software composition analysis: Management and security for open-source licenses
  • Operational intelligence: Aggregation and correlation for the analysis of data across security, performance, and availability
  • DevSecOps: Automated and continuous process management for continual integration and delivery of secure applications
  • Cyber risk management: Prioritized insight into the threats, vulnerabilities, and impacts of cloud assets
  • Container security: Minimal or hardened operating system that is specifically designed to run containers. Running similar security demand services on a same host, limit the scope of intrusion.
  • Backup: Maintaining backups ensuring availability by following the legal requirements such as holding information for 7 years, data should saved our of country.
  • Permissions: Authentication and authorization at granular level and constant audit to ensure there is no break.

Situational awareness solutions detect security events and are capable of responding, recovering, and helping with continual improvement. 

  • Firewalls and proxies: Provide fine-grained inspection of traffic for potential threats at both the network and application levels
  • Endpoint detection and response: Protect endpoints, including cloud workloads from zero-day and other attacks
  • Intrusion detection systems: Monitor networks and workloads for security events
  • Backup and restoration: Protect data from errors, failures, and accidental deletion
  • Disaster recovery: Provides additional flexibility to quickly recover from a disaster, ensuring that cloud workloads are available
  • Security information and event management: Ingests, correlates, and prioritizes events for deeper visibility into anomalous behavior and threat mitigation
  • Workload isolation: Provides dynamic security control for microservices, containers, and other workloads


References and Credits

https://www.cloudcodes.com/blog/wp-content/uploads/2020/05/cloud-security-for-dummies.png'
https://www.cloudflare.com/en-in/learning/cloud/what-is-a-virtual-private-cloud/
https://www.professormesser.com/security-plus/sy0-601/sy0-601-video/cloud-security-controls/

Thursday, 3 November 2022

Information Security - Governance, Risk, and Compliance

  

Security is an ongoing process, it needs to present in every phase in an organization. Risk is impossible to avoid, but we can always take necessary precautions by preventing if not by minimize the impact and limit the damage. This process is known as security controls. Managing risk is an important aspect for any organization, it requires strong governance by understand the goals, critical functions performed by an organization. Meeting the compliance standards of laws, policies and regulations is very essential to avoid fines, incarceration or loss of business or employment, all this includes reputational damage. Scope of laws covers the state, territory, national or international based on organization. Today we will see highlights from the shoes of security consultant.

Information Security

Information should be protected in all the terms on rest, in transit and while processing. We have below properties to call when the data is secure from both hardware or software.
  • Confidentiality
    • Only required party should know the data
  • Integrity
    • No data is tampered, against the will
  • Availability
    • Information accessible when required
  • Non Repudiation
    • Cannot deny on the action performed

Risk Management Components

  • Policy: Proposes principle of actions on which an organization is built, using to make decisions.
  • Standard: Set of requirements which must be mandatory to be adhered by everyone.
  • Guideline: Provides recommendations or suggestions and best practices.
  • Procedure: Provides step by step instructions on how the policy, standard or guideline needs to be implemented. Also known as Standard Operating Procedure - SOP but tend to have more specific details on the instructions.
Credit: https://www.ccexpert.us/firewall-fundamentals/the-difference-between-policies-standards-guidelines-and-procedures.html



Security Framework and Standards 

    Security framework is list of actions takes to mitigate risk. The use of the framework allows the organization to set benchmarks in terms of security, define tasks, prioritize projects and allocate required funds to achieve. Organizations follow these frameworks based on the org's location, size, type of industry to ensure legal compliance and strengthen org's security. It is important to build security framework personalised for each organization as each is unique but following the best practices from the industry standards it good to start.  

    Below are few secure frameworks for both organisation and cloud.
    • NIST
      • NIST is abbreviated as National Institute of Standards Technology.
      • Developed for US and US government, but can be applicable for other countries as well.
      • NIST Risk Management Framework (RMF), specifically used for federal agencies, and mandatory for US federal agencies. 
        • Six step process:
          1. Categorize or define environment
          2. Select appropriate controls
          3. Implement controls
          4. Assess controls
          5. Authorize a system
          6. Monitor for ongoing compliance
      • NIST is responsible for issuing Federal Information Processing Standards (FIPS).
      • NIST is also responsible for issuing advisory guides called as Special Publications.
      • NIST provides a list of checklists and benchmarks for variety of operating system and applications called National Checklist Program (NCP)
      • NIST Cyber Security Framework (CSF), is responsible to mitigate cybersecurity risks. CSF is can be classified as five functions, which is developed by the NIST.
        • Identity
          • Develop security systems to mitigate risk, threats, vulnerabilities
        • Protect
          • Build secure systems at every phase
        • Detect
          • Perform ongoing monitoring which are capable to identify and protect against  different and new threats
        • Respond
          • Action against the detected risk, threats, vulnerabilities
        • Recover
          • Restore system or data if unable to prevent the attacks
      • NIST GGSS
        • NIST Guide to General Server Security addresses general security issues related to typical servers.
    • ENISA
      • European Union Agency for Network and Information Security - ENISA is similar to NIST that focuses on information security enterprise for the EU.
    • ISO/IEC
      • Common Security Framework ISO/IEC
      • ISO - International Standard Organization
      • IEC - International Electrotechnical Commission
    • ISO 21K
      • ISO 21K is cyber security framework
    • ISO 27K
      • ISO 27K contains overall series of information security standards
      • ISO 27001 information security management standards
      • ISO 27002 provides best practices for information security controls
      • ISO 27017 and 27018 references cloud security
      • ISO 27701 focus on personal data and privacy
    • ISO 31K
      • ISO/IEC 31K is an international standard providing an overall framework for enterprise risk management practices - ERM, includes performing risk assessments
    • CSA
      • CSA is abbreviated as Cloud Security Alliance
      • CSA is a non-profit organization to assist cloud service providers - CSP for providing secure platforms
      • CCM - Cloud Controls Matrix, security guidance for using cloud platform and best practices to be followed
      • CCM list of specific controls should be adopted by the CSPs.
    • COBIT
      • Control Objectives for Information and Related Technology - COBIT
      • A set of best practices for IT management.
    • COSO
      • The Committee of Sponsoring Organizations (COSO) of the Treadway Commission for enterprise governance and risk management to reduce fraud in organizations.
    • HITRUST CSF
      • Health Information Trust Alliance Common Security Framework for healthcare information.
    • SSAE
      • The Statement on Standards for Attestation Engagements - SSAE
      • Audit specifications developed by American Institute of Certified Public Accountants AICPA for the CSPs.
      • SOC2 - Service Organization Controls, results in reports which evaluates the internal controls implemented; practices around confidentially, integrity, availability and privacy; by the service providers to ensure compliance with Trust Service Criteria - TSC where storing or processing customer data. Includes evaluating the firewalls, intrusion detection, multi factor authentication.
      • SOC3 - a less detailed report of SOC2 for everyones knowledge.
      • Type I audit
        • Tests controls in place at a particular point in time.
      • Type II
        • Tests controls over a period of at least six consecutive months.
    • CIS
      • Centre of Internet Security, non profit institute developed by SANS Institution,  maintaining the security controls.
      • CIS CSC - Critical Security Controls for effective cyber defence. It is designed to improve cyber defences making it implementable for IT professionals.
      • CIS RAM - Risk Assessment Method, can be used to perform an overall emulation of security.
      • CIS CAT - Configuration Access Tool, can be used with automated vulnerability scanners to test compliance against the benchmarks
    • STIG
      • Security Technical Implementation Guides developed by Department of Defence Cyber Exchange, hardening guide for hardware and software
    • OWASP
      • Open Web Application Security Project - OWASP, is a non-profile community publishes best security practices and have built tools Zed Attack Proxy/Juice Shop to help to investigate security issues. 
    • OCTAVE
      • Operational Critical Threat, Asset and Vulnerability Evaluation - OCTAVE
      • For educational institution.

    Security Job Roles

    The role of a security engineer differs from organization to organization, also based on the size and nature of the business. 
    • CIO, CEO, CTO
      • Liable for external and internal security
    • Director of Security, Chief Security Officer, Chief Information Security Officer
      • Overall responsibility for security
    • Managers
      • Responsible for the domain or section of the business/infra
    • Information Security System Officer, Specialist
      • Responsible for implementation, maintaining and monitoring
    • Every Employee
      • Responsible of the actions and needs to comply with the corporate policy

    Information Security Business Units

    Units within the organization to represent security function.

    Security Operation Centre (SOC)

    • A location where the security professional monitor and protect critical information across organization.
    • The physical entry and exit is usually for restricted for all, allowing only required employees.

    DevSecOps

    • Traditionally the software development involves only in developing code, with increasing cloud and container driven architecture there is more collaboration between developers and system administrators leading to DevOps.
    • DevSecOps has extended the boundary to security specialities, making security as primary consideration in the development and deployment.
    • DevSecOps comprises of Development, Security and Operations making the code move production faster and secure.
    Credits: https://gigaom.com/2020/12/11/security-by-design-why-devsecops-is-so-important/

    Incident Response

    • Dedicated team responsible for handling security incidents.
    • Acts as the single point of contact as a independent business unit, but at times handled as part of SOC.
    • Teams are called as:
      • CIRT - Cyber Incident Response Team
      • CERT - Computer Emergency Response Team
      • CSIRT - Computer Security Incident Response Team

    Security Control Categories

    Security is met by implementation of the security controls, handling the properties of confidentiality, integrity, availability and non-repudiation. A control is the defence or countermeasure put in place to manage risk. 

    Below are three major categories controls are classified into to protect data and systems. By adding multiple layers of control types, we are building a stronger system to avoid intrusion. This technique is called as layered defensive strategy or defence in depth.

    Technical

    • The control implemented as a system which could be hardware or software.
    • Eg: firewall, anti-virus, logging, encryption, data classification system, access controls, security patches and updates, change the default authentications, hardening of systems - web application, os, application server, networking infrastructure devices


    Operational

    • The control implemented by people, forms outer line of defence includes physical controls and organization controls. 
    • Eg: security guards, training programs, protecting storage systems including backup systems, surveillance systems 


    Managerial

    • The control gives oversight of the information system and address system design and implementation
    • This is also called as Administration control
    • Eg: risk identification, tools to evaluate or suggest security fixes, security awareness trainings, personnel background checks, change management process, security policies and procedures, 

    Security Control Function Types

    The security controls can further be classified in types based on the function they perform. We would ideally need to have prevention as its better than cure, but in reality we should be ready and have controls in place to take address all the mishaps.

    Preventive

    • The precaution taken to avoid an attack, physically control access in virtual world.
    • Eg: ACL, firewalls, anti-virus, anti-malware - prevention from malicious content, control access including physical, door lock, security guard, IPS intrusion prevention system, firewalls, anti-malware.


    Detective

    • Identify the attack during the progress of an attack, here it may not prevent the attack.
    • Eg: Log monitoring, motion detector, IDS, checksum, CCTV, alarms, security reviews and audit, mandatory vacation, rotation of duties, anti-malware - detection of malicious content in the existing system.


    Corrective

    • Correction or recovery made after an attack to mitigate the damage.
    • Eg: Restore, patch management, backups can mitigate the attack, backup sites can provide control over natural or man made disaster, add IPS can block the attacker in future, anti-malware - fix infected files, vulnerability mitigation.


    Physical

    • Physical controls placed to avoid attacks in real world.
    • Eg: Alarms, gateways, locks, security cameras, fences.


    Deterrent

    • Psychologically discourage the attacker to perform attacks, but may not directly prevent access.
    • Deterrent, does not stop unauthorized access
    • Eg: Warning boards, legal penalties, lights.


    Compensating

    • Controls which serves as the substitute if any of the primary controls are not in place, this does not prevent an attack but restores back to normal.
    • Eg: Restore from the backups, hot-site, backup power systems.

    Security Regulations, Laws and Standards

    Organizations needs to follow compliance guidelines, based on the scope of the business which needs to cover international, national, territory and state laws. Compliance means meeting the standards of laws, policies and regulations. Laws associated to security has been created if breached will be held for fines, loss of employment, civil or criminal liabilities. 
    • SOX
      • Sarbanes Oxley Act, developed by US governs the financial and accounting disclosure information to protect investors from fraudulent financial reporting by corporations, mandates the implementation for risk assessments, internal and audit controls.
    • CSA
      • Computer Security Act developed in 1987 requires federal agencies to develop security policies for confidential information. 
    • GDPR
      • General Data Protection Regulations, developed by European Union for handling confidential data under data privacy act.
      • User can control where the data goes, and have right to be forgotten.
      • Each sites have privacy policy tells all in detail about the data gathered, data usage, data stored and user's privacy right.
      • Privacy of individuals are protected which includes, Name, address, photo, mail address, bank details, identify proofs - PAN/Aadhar/SSN, medical information, IP address and so on.
    • HIPAA
      • Health Insurance Portability and Accountability Act, regulations for health organizations.
    • PCI DSS
      • Payment Card Industry Data Security Standard (PCI DSS) a standard for protecting credit cards in order to reduce fraud.
      • Defines the safe handling and storage of financial information.
      • Need to comply with PCI DSS if dealing with credit card in businesses.
      • Six control objectives:
        • Secure network
        • Secure end-to-end card details
        • Always patched
        • Strong Access control measures
        • Regular audit and monitor
        • Maintain information security policy
    • GLBA
      • Gramm–Leach–Bliley Act (GLBA) establishes the privacy rules for financial services.
    • CCPA
      • California Consumer Privacy Act (CCPA), personal data regulations.
    • FISMA
      • Federal Information Security Act was introduced in 2002 to govern the data processed by federal agencies.
    • PIPEDA
      • Is a Canadian law that governs the collection and the use of personal information.

    Security Policies

    AUP - Acceptance Use Policy

    • AUP provides a detailed documentation on how the company assets should be used, such mobile or laptop given from organization should not used for personal reasons.
    • If any of the assets are misused, employer could take action against the violation.
    • This policy will help the organization to minimize the risk.

    Business Policies

    Below covers following policies to increase the stability and decrease risk in an organization.
    • Job Rotation, not allowing one to be in same position for ling time.
    • Mandatory Vacations, a person needs to leave their job and go for vacation for some time. As during this time the task will be handled by someone, removing the dependency and validate if there was any security violations limiting the ability to commit fraud.
    • Separation of Duties, allowing to split knowledge such as to unlock a system keys from two or more persons are needed.
    • Clean Desk Policy, no sensitive information should be easily or openly available, always locked both hard copies and soft copies locking the system.
    • Least Privilege, only required access provided to perform the action.
    • Background Checks, while hiring making sure of your history is clear.
    • NDA - Non disclosure agreement, contract preventing employees sharing confidential information.
    • Social Media Analysis, using individuals social media policy allowing one to hire or not.
    • Onboarding Policy, steps needs to taken care while hiring a new employee such signing the AUP, access to the system, trainings and so on.
    • Off-boarding Policy, steps needs to taken care while the employee leaves such as access restriction, preserving encryption keys and so on.
    • User Training, below are the ways users needs to be trained to perform the job.
      • Gamification
      • CTF - Capture the Flag usually security related competition
      • Phishing simulation
      • CBT - Computer Based Test
      • In Person 
      • Specialized training, before allowing to take the job to understand the role and security aspects.
    • Vendor Policies
    • Disciplinary and Adverse Actions, policies specify to consequences for violations.
    • Exit Interviews, help to identify workplace factors that lead employee to leave the organization.
    • Supply chain assessments, evaluate co-ordination and security process between groups.
    • Business partners policies to handle risk effectively. 
    • SLA - Service Level Agreement, terms decided on the services uptime, response and so on from the service providers.
    • MOU / MOA - Memorandum of Understanding / Memorandum of Agreement, consent signed between both the sides.
    • MSA - Measurement System Analysis will assess the measurement process and calculate the uncertainty. Used with quality management systems such as Six Sigma.
    • BPA - Business Partnership Agreement, policies such as decision making agreements, owner stake, financial contract.
    • ISA - Interconnection Security Agreement, purposes the technical requirement of the interconnections between organizations using shared IT systems.
    • EOL - End Of Life, manufacture may end but continue support
    • EOSL - End of Service Life, no longer provide support and security patches.

    Privacy VS Security

    • The value of the information is determined in the impact of it being compromised.
    • Data security is an important factor, but privacy is an equal factor as well.
    • Privacy: 
      • Personnel data is any information about an identifiable individual.
      • Data governance required when collecting and processing with personnel data.
      • Privacy ensures there are required policies, to identify private data, storage, processing and retention.
      • Limited access to the private data only to authorized persons.
    • Security:
      • Data security focus on CIA attributes.
      • Data must kept securely while processing and storage.
      • Identity management, allowing only authorized and authenticated person to read or write the data.

    Information Life Cycle Management

    • Creation
    • Distribution
    • Use
    • Maintenance
    • Archive
    • Disposal


    Data Roles and Responsibility

    • Data governance
    • Data owner
      • Accountable for specific data often a senior officer
      • Determine data classification
    • Data steward
      • Manages the data governance
      • Responsible for data accuracy, privacy, compliance and security
      • Data classification
        • Maps sensitivity labels to the data
        • Such as public, private, confidential, personnel, etc
    • Data custodian/steward
      • Implementing the data classification and security controls
    • Data privacy officer (DPO)
      • Responsible for the organizations's data security
      • Sets policies, implements processes and procedures
    • Data controller
      • Manages the purposes and means by which personal data is processed.
    • Data collector
    • Data processor
      • Processes the data on behalf of the data controller.

    Data Classifications

    • Public / Unclassified
      • Non sensitive data
      • Press releases, marketing materials
    • Confidential
      • Data reserved for certain employees with an organization
    • Critical
      • Data should always be available
    • Proprietary
      • Data disclosed outside the organization on a limited basis. Eg: NDA

    • Private / Personal / Restricted / Internal Use Only / Classified
      • Data used within specific division, eg: payroll details of employees only for HR and respective individually
    • Sensitive
      • Severe impact to the organization if it were exposed
    • Note
      • Data classification should also consider data accuracy, integrity and availability.
      • Eg: Publicly classified data should be accurate.

    Data Policies

    • Privacy Notices
    • Data Retention
      • Keeps the files that change frequently for version control
    • Impact Assessments
    • Data Sovereignty 
    • Geographical Considerations
    • Data Sharing
    • Privacy Terms of Agreement
      • SLA
      • ISA
      • NDA
      • DSUA
    • Credential Policies
      • General guidelines are password should not be embedded with the application, passwords in clear text much must not be saved nor be transferred over network.
      • Every user needs to have its own user account and personal information should be access to him/her. Users should not have privileged access as this could lead the malware to run as the user easily.
      • For administers also should have user account but for performing administration can use elevated access for each.
      • Third party accounts can be created for additional vendor based applications access, but these accounts should also be never shared.
      • Device accounts for accessing the device, holding the device certificate and require passwords for screen unlock. This can be managed through MDM, Mobile Device Management. For unlock could also include geolocation validation.
      • Service accounts, access can be defined for a specific service and the password/key rotation policies should be place avoiding unexpected breaches.
      • Administrator or root accounts, these accounts should not be used as normal administration.
    • Change management policies ensuring the changes are planned, tested, frequency of the change, installation steps, fallback procedures and scrutiny plan has be done before making changes.
    • Asset management, identify and track computing assets, making sure all the security patches are applied, track licenses. 
    • FRCP : The United States, Federal Rules of Civil Procedure. have implications for data retention policies.

    Data Types
    • PII - Personally Identifiable Information
    • Customer Data
    • PHI - Personal Health Information
    • Financial Information
    • Government Data

    Data Breach Consequences

    • Organization Impact
      • Reputation Damage
      • Identity Theft
      • Fines
      • IP Theft
    • Notification
    • Escalation
    • Public Notification and Disclosure

    Data Protection

    • Data at Rest
    • Data in Transit
    • Data in Use
    • Data Exfiltration
    • Rights Management Services
    • Privacy Enhancing Technologies
      • Data minimization
      • Deidentification
        • Data Masking
        • Tokenization
        • Aggregation/Banding
        • Hashing and Salting
      • Anonymization
        • Making the data impossible to identify individual data from the dataset.
        • The data cannot be reversed to actual data, no way to associate the data to the user.
      • Pseudo anonymization
    • Data Loss Prevention
      • Policy Server
      • Endpoint Agents
      • Network Agents

    Risk Management Process

    Risk management process is to identify assets and threats, and risk (high, medium, low) associated to it that could be affected by an attack. Including the total risk to the organization, to make future plans.

    Risk can be calculated:
        Risk = Threat * Vulnerability * Impact 


    Risk Assessment

    • Identify Threat and Vulnerabilities
      • External Threats
      • Internal Threats
      • Legacy Systems
      • Multi Party Risk
      • Intellectual Property Theft
      • Software compliance/licenses
    • Quantitative Risk Assessment
      • ARO (Annualized Rate of Occurrence)
        • Determine the likelihood of occurrence
        • Is the estimation possibility of a specific threat taking place in a one-year time period
      • SLE (Single Loss Expectancy)
        • Determine the magnitude of the impact
        • Monetary loss occurs every time
        • Formula
          • Asset Value * Exposure Factor = SLE
      • ALE (Annualized Loss Expectancy) 
        • Determine the magnitude of the impact
        • Formula
          • SLE * ARO = ALE
    • Qualitative Risk Assessment
      • Risk Register
      • Risk Matrix
      • Risk Heat Map
    • Site Risk Assessment
      • Location level risk assessments.
      • Recovery plan should include - applications, personal, equipment and work environment
      • Insurance planning
    • Privacy Impact Assessment - PIA
      • Privacy risk needs to be identified in each initiative
    • Privacy Threshold Assessment - PTA
      • Used to determine system contains PII information for impact analysis and protection of the data.
      • Eg: Distributing a questionnaire to system and application owner. 


    Risk Analysis

    • Risk Register
      • Risk Register is strategic component of an organization, providing single point of entry to record information about identified risks.
      • Every project has some risk associated with it, identify and document the risk associated with each step.
      • Apply all the possible solutions to the identified risks and monitor the risks.
      • Helps the organization's risk tolerance and risk appetite are met.
    • Risk Matrix / Risk Heat
      • Visualize and view the result of the risk assessment, quantify the risk.
      • Combines the likelihood (likely, possible, unlikely) of an event with potential impact (negligible, minor, major) and assists with making strategic decisions.
    Credits: https://www.balbix.com/app/uploads/risk-heat-map-trimmed.png
    • Inherent Risk
      • Risk exists in the absence of any controls take place to avoid risk.
    • Residual Risk
      • Risk exists after the necessary controls taken place. 
    • Risk appetite and Risk tolerance
      • Risk the organization is willing to take.
    • Risk Awareness
      • Knowledge about the risk is crucial for everyone in the organization.


      Risk Management Strategies

      • Risk Mitigation/Deterrence
        • Decrease the risk level, by investing in security systems
      • Risk Avoidance
        • Stop participating in a high risk activity
      • Risk Transference
        • Buy some cybersecurity insurance
      • Risk Acceptance
        • Business decision to accept the risk
      • Control Risk
      • Risk Awareness
      • Documentation
        • Term of Services / Term of Use / Terms and conditions
        • Privacy notice / Privacy policy


      Business Impact Analysis 

      • Process of determining the potential impacts resulting from the interruption of time sensitive or critical business process
      • Risk assessment focuses on the relative likelihood of potential threats to an organization, a BIA focuses on the relative impact of the loss of operational capability on critical business functions.
      • Ensure key business is continued:
        • BCP - Business Continuity Plan
        • COOP - Continuity of Operations of Plan
      • ICS - Identification of Critical Systems
        • Identify critical systems and components
        • Alternative solutions needs to be planned on failure of these
      • SPoF - Single Point Failure
        • SPoF creates potential risk in bringing the entire system down
        • Should be avoided with fault tolerance system and redundance
      • MTD - Mobile Threat Defence
      • RTO - Recovery Time Objective
        • Specifies allowable time to recover
      • WRT - Work Recovery Time
      • RPO - Recovery Point Objective
        • Specifies allowable data loss
      • MTTF - Mean Time To Failure
        • Length of the time system is expected to work with failures or crashes
        • MTTF is collected by running many units and calculate the average based on when components fail
        • MTTF is used for non repairable systems
      • MTBF - Mean Time Between Failures
        • Predict the time between outages or failures
        • MTBF is used for repairable systems
      • MTTR - Mean Time To Repair
        • Time required to fix the issue


      Disasters

      • Internal Vs External
      • Person Made
      • Environmental
      • Site Risk Assessment
      • Disaster Recovery Plans
      • Functional Recover Plans
      • Mission Essential Functions


      References and Credits

      https://purplesec.us/wp-content/uploads/2020/02/types-of-security-controls.png
      CompTIA Security Plus several notes

      Scarcity Brings Efficiency: Python RAM Optimization

        In today’s world, with the abundance of RAM available, we rarely think about optimizing our code. But sooner or later, we hit the limits a...