· 9 years ago · May 27, 2017, 01:18 PM
1198 Chapter 4
2Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
3Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
44
5executives might feel that their function is the most critical to the organization, it might
6prove to be less critical in the event of a major incident or disaster. Senior management
7must arbitrate these inevitable conflicts about priority because it has the perspective to
8make such trade-off decisions.
9When organizations consider recovery criticality, key recovery measures are usually
10described in terms of how much of the asset they must recover within a specified time
11frame. The terms most commonly used to describe these values are shown in the following
12text box of key terms defined by NIST:
13â—
14Maximum tolerable downtime (MTD): The total amount of time the system owner or
15authorizing official is willing to accept for a mission/business process outage or dis-
16ruption, including all impact considerations.
17â—
18Recovery time objective (RTO): The maximum amount of time that a system resource
19can remain unavailable before there is an unacceptable impact on other system
20resources, supported mission/business processes, and the MTD.
21â—
22Recovery point objective (RPO): The point in time prior to a disruption or system
23outage to which mission/business process data can be recovered after an outage (given
24the most recent backup copy of the data). 31
25â—
26Work recovery time (WRT): The amount of effort (expressed as elapsed time) neces-
27sary to make the business function operational after the technology element is recov-
28ered (as identified with RTO). Tasks include testing and validation of the system.
29Planners should determine the optimal point for recovering the information system to meet
30BIA-mandated recovery needs while balancing the cost of system inoperability against the
31cost of resources required for restoring systems. This work must be done in the context of
32critical business processes identified by the BIA, and can be shown with a simple chart (see
33Figure 4-15).
34The longer system availability is interrupted, the more impact it will have on the organiza-
35tion and its operations. Costs will increase as well. When plans require a short RTO, the
36required solutions are usually more expensive to design and use. For example, if a system
37must be recovered immediately, it will have an RTO of 0. These types of solutions will
38require fully redundant alternative processing sites and will therefore have much higher
39costs. On the other hand, a longer RTO would allow a less expensive recovery system.
40Identify Recovery Priorities for System Resources As the CPMT conducts
41the BIA, it will assess priorities and relative values for mission/business processes. To do so,
42it needs to understand the information assets used by those processes. The presence of high-
43value information assets may influence the valuation of a particular business process. Nor-
44mally, this task would be performed as part of the risk assessment function within the risk
45management process. The organization should identify, classify, and prioritize its informa-
46tion assets, placing classification labels on each collection or repository of information to
47better understand its value and prioritize its protection. If the organization has not per-
48formed this task, the BIA process is the appropriate time to do so.
49Identify Resource Requirements Once the organization has created a prioritized
50list of its mission and business processes, it needs to determine which resources would be
51required to recover those processes and associated assets. Some processes are resource
52Continuity Strategies 199
53Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
54Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
55intensive, like IT functions. Supporting customer data, production data, and other organiza-
56tional information requires extensive quantities of information processing, storage, and
57transmission (through networking). Other business production processes require complex or
58expensive components to operate. For each process and information asset identified in the
59previous BIA stage, the organization should identify and describe the relevant resources
60needed to provide or support that process.
61‡ Incident Response Planning
62Incident response planning includes the identification and classification of an incident and the
63response to it. The IR plan is made up of activities that must be performed when an incident
64has been identified. Before developing such a plan, you should understand the philosophical
65approach to incident response planning.
66If an action that threatens information occurs and is completed, it is classified as an incident.
67All of the threats identified in earlier chapters could result in attacks that would be classified
68as information security incidents. For purposes of this discussion, however, adverse events are
69classified as incidents if they have the following characteristics:
70â—
71They are directed against information assets.
72â—
73They have a realistic chance of success.
74â—
75They could threaten the confidentiality, integrity, or availability of information
76resources.
77Incident response planning focuses on detecting and correcting the impact of an incident on
78information assets. Prevention is purposefully omitted, as this activity is more a function of
79general information security than of incident response. In other words, IR is more reactive
80than proactive, with the exception of the planning that must occur to prepare IR teams to
81react to an incident.
82IR consists of the following four phases:
831. Planning
842. Detection
853. Reaction
864. Recovery
87Incident Response Policy An important early step for the IR team is to develop
88an IR policy. NIST’s Special Publication 800-61, Rev. 2, The Computer Security Incident
89Handling Guide, identifies the following key components of a typical IR policy:
901. Statement of management commitment
912. Purpose and objectives of the policy
923. Scope of the policy (to whom and what it applies and under what circumstances)
934. Definition of InfoSec incidents and related terms
945. Organizational structure and definition of roles, responsibilities, and levels of authority;
95should include the authority of the incident response team to confiscate or disconnect
96equipment and to monitor suspicious activity, and the requirements for reporting
97200 Chapter 4
98Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
99Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
1004
101certain types of incidents, the requirements and guidelines for external communications
102and information sharing (what can be shared with whom, when, and over what chan-
103nels), and the handoff and escalation points in the incident management process
1046. Prioritization or severity ratings of incidents
1057. Performance measures (discussed in Chapter 6)
1068. Reporting and contact forms 32
107Like all policies, IR policy must have the full support of top management and be clearly
108understood by all affected parties. It is especially important to gain the support of communi-
109ties of interest that must alter business practices or make changes to their IT infrastructures.
110For example, if the IR team determines that the only way to stop a massive denial-of-service
111attack is to sever the organization’s connection to the Internet, it should have a signed docu-
112ment locked in an appropriate filing cabinet to authorize such action. This document
113ensures that the IR team is performing authorized actions, and it protects IR team members
114and the organization from misunderstanding and potential liability.
115Incident Planning Planning for an incident requires a detailed understanding of the
116scenarios developed for the BIA. With this information in hand, the planning team can
117develop a series of predefined responses that guide the organization’s IR team and informa-
118tion security staff. These responses enable the organization to react quickly and effectively to
119the detected incident. This discussion assumes that the organization has an IR team and that
120the organization can detect the incident.
121The IR team consists of people who must be present to handle systems and functional areas
122that can minimize the impact of an incident as it takes place. Picture a military movie in
123which U.S. forces have been attacked. If the movie is accurate in its portrayal of IR teams,
124you saw the military version of an IR team verifying the threat, determining the appropriate
125response, and coordinating the actions necessary to deal with the situation.
126Incident Response Plan The idea of military team responses can be used to guide
127incident response planners. The planners should develop a set of documents that direct the
128actions of each person who must help the organization react to and recover from the inci-
129dent. These plans must be properly organized and stored to be available when and where
130they are needed, and in a useful format.
131Format and Content The IR plan must be organized to support quick and easy access to
132required information. The simplest measure is to create a directory of incidents with tabbed
133sections for each incident. To respond to an incident, the responder simply opens the binder,
134flips to the appropriate section, and follows the clearly outlined procedures for an assigned
135role. This means that planners must develop the detailed procedures necessary to respond to
136each incident. These procedures must include the actions to take during the incident and
137afterward as well. In addition, the document should prepare the staff for the incident by pro-
138viding procedures to perform before it occurs.
139Storage Information in the IR plan is sensitive and should be protected. If attackers learn
140how a company responds to a particular incident, they can improve their chances of success.
141On the other hand, the organization needs to have this information readily available to those
142Continuity Strategies 201
143Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
144Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
145who must respond to the incident. This typically means storing the IR plan within arm’s
146reach of the information assets that must be modified or manipulated during or immediately
147after the attack. The organization could use physical binders stored adjacent to the adminis-
148trator’s workstation or in a bookcase in the server room. An even more effective solution is
149an encrypted file stored on an online resource. The bottom line is that the people who
150respond to the incident should not have to search frantically for the needed information.
151Testing An untested plan is not a useful plan. Or, in military vernacular, “Train as you
152fight, and fight as you train.†Even if an organization has an effective IR plan on paper, the
153procedures may be ineffective unless the plan has been practiced or tested. A plan can be
154tested in many different ways using one or more testing strategies. Five common testing strat-
155egies are presented here. 33
1561. Checklist: Copies of the IR plan are distributed to each person who has a role to play
157during an actual incident. Each person reviews the plan and identifies any inaccurate
158components for correction. Although the checklist is not a true test, it is an important
159step in reviewing the document before it is actually needed.
1602. Structured walk-through: In a walk-through, each involved person practices the steps he
161or she will take during an actual event. Team members can conduct an “on-
162the-ground†walk-through, in which everyone discusses required actions at each loca-
163tion and juncture, or they can conduct a “talk-through,†in which all team members sit
164around a conference table and discuss how they would act as the incident unfolded.
1653. Simulation: Here, each involved person works individually rather than in conference,
166simulating the performance of each task required to react to and recover from a simu-
167lated incident. The simulation stops short of the physical tasks required, such as instal-
168ling a backup or disconnecting a communications circuit. The major difference between
169a walk-through and a simulation is the independence of individual performers as they
170work on their own tasks and assume responsibility for identifying faults in their own
171procedures.
1724. Parallel: In the parallel test, team members act as if an actual incident occurred, per-
173forming their required tasks and executing the necessary procedures. The difference is
174that the normal operations of the business do not stop. The business continues to func-
175tion even though the IR team acts to contain the test incident. Great care must be taken
176to ensure that the procedures do not halt the operation of business functions and
177thereby create an actual incident.
1785. Full interruption: The final, most comprehensive and realistic test is to react to a mock
179incident as if it were real. In a full interruption test, team members follow every proce-
180dure, including interruption of service, restoration of data from backups, and notifica-
181tion of appropriate people, as discussed in subsequent sections. This test is often per-
182formed after normal business hours in organizations that cannot afford to disrupt
183business functions or simulate disruption. This test is the best practice the team can
184get, but it is too risky for most businesses.
185At a minimum, organizations should conduct periodic walk-throughs or talk-throughs of the
186IR plan. Because business and information resources change quickly, a failure to update the
187IR plan can result in inability to react effectively to an incident or possibly cause greater dam-
188age than the incident itself. If this plan sounds like a major training effort, note the following
189202 Chapter 4
190Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
191Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
1924
193sayings from author Richard Marcinko, a former Navy SEAL. These remarks have been
194paraphrased (and somewhat sanitized) for your edification. 34
195â—
196The more you sweat in training, the less you bleed in combat.
197â—
198Training and preparation hurt.
199â—
200Lead from the front, not the rear.
201â—
202You don’t have to like it, just do it.
203â—
204Keep it simple.
205â—
206Never assume.
207â—
208You are paid for your results, not your methods.
209Incident Detection
210Key Terms
211incident candidate An adverse event that has strong potential to meet the criteria to become
212an incident.
213incident classification The process of examining an incident candidate and determining
214whether it constitutes an actual incident.
215Members of an organization sometimes notify systems administrators, security administra-
216tors, or their managers of an unusual occurrence. This occurrence most often causes a com-
217plaint to the help desk from one or more users about a technology service. Complaints are
218often collected by the help desk, and can include reports such as “the system is acting
219unusual,†“programs are slow,†“my computer is acting weird,†or “data is not available.â€
220Incident detection relies on either a human or automated system (often the help desk staff)
221to identify an unusual occurrence and classify it properly. The mechanisms that might detect
222an incident include intrusion detection and prevention systems (both host-based and
223network-based), virus detection software, systems administrators, and even end users. Intru-
224sion detection systems and virus detection software are examined in detail in later chapters.
225This chapter focuses on the human element.
226Note that an incident, as previously defined, is any clearly identified attack on the organiza-
227tion’s information assets. An ambiguously identified event could be an actual attack, a prob-
228lem with heavy network traffic, or even a computer malfunction. Only by carefully training
229users, the help desk, and all security personnel to analyze and identify attacks can the
230organization hope to identify and classify an incident quickly. Once an attack is properly
231identified through incident classification, the organization can effectively execute the corre-
232sponding procedures from the IR plan. Anyone with the appropriate level of knowledge
233can classify an incident. Typically, a help desk operator brings the issue to a help desk
234supervisor, the security manager, or a designated incident watch manager. Once an incident
235candidate has been classified as an actual incident, the responsible manager must decide
236whether to implement the incident response plan.
237Incident Indicators Several occurrences signal the presence of an incident candidate.
238Unfortunately, many of them are similar to the actions of an overloaded network, computer,
239or server, and some are similar to the normal operation of these information assets.
240Continuity Strategies 203
241Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
242Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
243Other incident candidates resemble a misbehaving computing system, software package, or
244other less serious threat. Donald Pipkin, an IT security expert, identifies three categories of
245incident indicators: possible, probable, and definite. 35 The indicators identified by Pipkin are
246not exhaustive; each organization adds indicators based on its own context and experience.
247The following four types of events are possible incident indicators:
2481. Presence of unfamiliar files: If users discover new files in their home directories or on
249their office computers, or administrators find files that do not seem to have been placed
250in a logical location or were not created by an authorized user, an incident may have
251occurred.
2522. Presence or execution of unknown programs or processes: If users or administrators
253detect unfamiliar programs running or processes executing on office machines or net-
254work servers, an incident may have occurred.
2553. Unusual consumption of computing resources: Many computer operating systems can
256monitor the consumption of resources. Windows 2000 and XP, as well as many UNIX
257variants, allow users and administrators to monitor CPU and memory consumption.
258Most computers can monitor available hard drive space. Servers maintain logs of file
259creation and storage. The sudden consumption of resources can indicate a candidate
260incident.
2614. Unusual system crashes: Some computer systems crash on a regular basis. Older operat-
262ing systems running newer programs are notorious for locking up or rebooting when
263the OS is unable to execute a requested process or service. Many people are familiar
264with system error messages such as Unrecoverable Application Error and General Pro-
265tection Fault, and many unfortunate users have seen the infamous NT Blue Screen of
266Death. However, if a computer system seems to be crashing, hanging, rebooting, or
267freezing more than usual, it could be a candidate incident.
268The following four types of events are probable indicators of incidents:
2691. Activities at unexpected times: If traffic levels on the organization’s network exceed the
270measured baseline values, an incident is probably under way. If this surge in activity
271occurs when few members of the organization are at work, an incident is even more
272likely to be occurring. Similarly, if systems are accessing drives when the operator is
273not using them, an incident may be in progress.
2742. Presence of new accounts: Periodic review can reveal an account (or accounts) that the
275administrator does not remember creating, or accounts that are not logged in the
276administrator’s journal. Even one unlogged new account is a candidate incident. An
277unlogged new account with root or other special privileges has an even higher probabil-
278ity of being an actual incident.
2793. Reported attacks: If users of the system report a suspected attack, there is a high proba-
280bility that an incident is under way or has already occurred. When considering the
281probability of an attack, you should consider the technical sophistication of the person
282making the report.
2834. Notification from IDPS: If the organization has installed host-based or network-based
284intrusion detection and prevention systems, and they are correctly configured, a notifi-
285cation from the IDPS indicates a strong likelihood that an incident is in progress. The
286problem with most IDPSs is that they are seldom configured optimally, and even when
287204 Chapter 4
288Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
289Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
2904
291they are, they tend to issue many false positives or false alarms. The administrator must
292determine whether the notification is significant or the result of a routine operation by a
293user or other administrator.
294The following five types of events are definite indicators of incidents. Definite indicators are
295activities that clearly signal an incident is in progress or has occurred:
2961. Use of dormant accounts: Many network servers maintain default accounts that came
297with the system from the manufacturer. Although industry best practices dictate that
298these accounts should be changed or removed, some organizations ignore these practices
299by making the default accounts inactive. In addition, systems may have any number of
300accounts that are not actively used, such as those for previous employees, employees on
301extended vacation or sabbatical, or dummy accounts set up to support system testing. If
302any of these dormant accounts suddenly becomes active without a change in user status,
303an incident has almost certainly occurred.
3042. Changes to logs: The smart administrator backs up systems logs as well as systems data.
305As part of a routine incident scan, these logs may be compared to an online version to
306determine whether they have been modified. If logs have been modified and the systems
307administrator cannot determine explicitly that an authorized person modified them, an
308incident has occurred.
3093. Presence of hacker tools: Hacker tools can be installed or stored on office computers so
310internal computers and networks can be scanned periodically to determine what a
311hacker can see. These tools are also used to support research into attack profiles.
312When a computer contains such tools, its antivirus program detects them as threats to
313the system every time the computer is booted. If users did not know they had installed
314the tools, their presence would constitute an incident. Many organizations have policies
315that explicitly prohibit the installation of such tools without the written permission of
316the CISO. Installing these tools without proper authorization is a policy violation and
317should result in disciplinary action. Most organizations that have sponsored and
318approved penetration-testing operations require all related tools in this category to be
319confined to specific systems that are not used on the general network unless active pen-
320etration testing is under way.
3214. Notifications by partner or peer: Many organizations have business partners, upstream
322and downstream value-chain associations, and superior or subordinate organizations. If
323one of these organizations indicates that it is being attacked and that the attackers are
324using your computing systems, an incident has probably occurred or is likely in progress.
3255. Notification by hacker: Some hackers enjoy taunting their victims. If your Web page sud-
326denly begins displaying a “gotcha†from a hacker, an incident has occurred. If you
327receive an e-mail from a hacker that contains information from your “secured†corporate
328e-mail account, an incident has occurred. If you receive an extortion request for money in
329exchange for your customers’ credit card files, an incident has occurred. Even if proof of
330loss is elusive, such claims can have an impact on an organization’s reputation.
331Several other situations are definite incident indicators:
3321. Loss of availability: Information or information systems become unavailable.
3332. Loss of integrity: Users report corrupt data files, garbage where data should be, or data
334that looks wrong.
335Continuity Strategies 205
336Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
337Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
3383. Loss of confidentiality: You are notified of sensitive information leaks or informed that
339information you thought was protected has been disclosed.
3404. Violation of policy: Organizational policies that address information or information
341security have been violated.
3425. Violation of law: The law has been broken, and the organization’s information assets
343are involved.
344Incident Reaction
345Key Terms
346alert message A scripted description of the incident that usually contains just enough
347information so that each person knows what portion of the IR plan to implement without
348slowing down the notification process.
349alert roster A document that contains contact information for people to be notified in the
350event of an incident.
351hierarchical roster An alert roster in which the first person calls a few other people on the
352roster, who in turn call others. This method typically uses the organizational chart as a structure.
353sequential roster An alert roster in which a single contact person calls each person on the roster.
354Incident reaction consists of actions outlined in the IR plan that guide the organization in
355attempting to stop the incident, mitigate its impact, and provide information for recovery.
356These actions take place as soon as the incident is over. Several actions must occur quickly,
357including notification of key personnel and documentation of the incident. These actions should
358be prioritized and documented in the IR plan for quick use in the heat of the moment.
359Notification of Key Personnel As soon as the help desk, a user, or a systems administra-
360tor determines that an incident is in progress, the right people must immediately be notified in
361the right order. Most organizations, including the military, maintain an alert roster
362for just such an emergency. There are two types of alert rosters: sequential and hierarchical. The
363hierarchical roster works faster, with more people calling at the same time, but the message may
364get distorted as it is passed from person to person. The sequential roster is more accurate because
365the contact person provides each person with the same alert message, but it takes longer.
366As with any document, the alert roster must be maintained and tested to ensure accuracy. The
367notification process must be periodically rehearsed to ensure that it is effective and efficient.
368Other personnel must also be notified in reaction to an incident, but they may not be part of
369the scripted alert notification because they are not needed until preliminary information has
370been collected and analyzed. Management must be notified, of course, but not so early that
371it causes undue alarm, especially if the incident is minor or turns out to be a false alarm. On
372the other hand, notification cannot be so late that the media or other external sources learn
373of the incident before management. Some incidents are disclosed to employees in general as
374a lesson in security, and some are not, as a measure of security. If the incident spreads
375beyond the target organization’s information resources, or if the incident is part of a large-
376scale assault, it may be necessary to notify other organizations. An example of a large-scale
377assault is Mafiaboy’s DDoS attack on multiple Web-based vendors in 1999. In such cases,
378the IR plan development team must determine who to notify and when to offer guidance
379about additional notification steps.
380206 Chapter 4
381Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
382Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
3834
384Documenting an Incident As soon as an incident or disaster has been declared, key per-
385sonnel must be notified and documentation of the unfolding event must begin. There are
386many reasons to document the event. First, it enables an organization to learn what hap-
387pened, how it happened, and what actions were taken. The documentation records the who,
388what, when, where, why, and how of the event. Therefore, it can serve as a case study that
389the organization can use to determine if the right actions were taken and if they were effec-
390tive. Second, documenting the event can prove that the organization did everything possible
391to prevent the spread of the incident if the response is questioned later. From a legal stand-
392point, the standards of due care protect the organization in cases where an incident affects
393people inside and outside the organization or other organizations that use the targeted sys-
394tems. Finally, the documentation of an incident can be used to run a simulation in future
395training sessions.
396Incident Containment Strategies The first priority of incident reaction is to stop
397the incident or contain its scope or impact. Unfortunately, the most direct means of contain-
398ment, sometimes known as “cutting the wire,†is often not an option for an organization.
399Incident containment strategies vary depending on the incident and on the amount of dam-
400age it causes or may cause. Before an incident can be contained, an organization needs to
401determine which information and information systems have been affected. This is not the
402time to conduct a detailed analysis of the affected areas; such analysis is typically performed
403after the fact in the forensics process. Instead, the organization needs to determine what
404kind of containment strategy is best and which systems or networks need to be contained.
405In general, incident containment strategies focus on two tasks: stopping the incident and
406recovering control of the systems.
407The organization can stop the incident and attempt to recover control using several strategies:
408â—
409If the incident originates outside the organization, the simplest and most straightfor-
410ward approach is to sever the affected communication circuits. However, if the orga-
411nization’s lifeblood runs through those circuits, such a drastic measure may not be
412feasible. If the incident does not threaten the most critical functional areas, it may be
413more feasible to monitor the incident and contain it in another way. One approach is
414to apply filtering rules dynamically to limit certain types of network access. For exam-
415ple, if a threat agent is attacking a network by exploiting a vulnerability in the Simple
416Network Management Protocol (SNMP), applying a blocking filter for the commonly
417used IP ports stops the attack without compromising other network services. Depend-
418ing on the nature of the attack and the organization’s technical capabilities, such ad
419hoc controls can sometimes buy valuable time to devise a more permanent control
420strategy.
421â—
422If the incident involves the use of compromised accounts, those accounts can be
423disabled.
424â—
425If the incident involves bypassing a firewall, the firewall can be reconfigured to block
426that traffic.
427â—
428If the incident involves using a particular service or process, it can be disabled
429temporarily.
430â—
431If the incident involves using the organization’s e-mail system to propagate itself, the
432application or server that supports e-mail can be taken down.
433Continuity Strategies 207
434Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
435Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
436The ultimate containment option, which is reserved for only the most drastic scenarios,
437involves a full stop of all computers and network devices in the organization. Obviously,
438this step is taken only when all control of the infrastructure has been lost, and the only
439hope is to preserve the data stored on those computers so it can possibly be used in the
440future to restore operations.
441The bottom line is that containment consists of isolating affected channels, processes, ser-
442vices, or computers and stopping the losses. Taking down the entire system, servers, and net-
443work may accomplish this objective. The incident response manager, with the guidance of
444the IR plan, determines the length of the interruption.
445Incident Recovery
446Key Terms
447after-action review A detailed examination and discussion of the events that occurred, from
448first detection to final recovery.
449computer forensics The process of collecting, analyzing, and preserving computer-related
450evidence.
451differential backup The archival of all files that have changed or been added since the last full
452backup.
453evidence A physical object or documented information that proves an action occurred or
454identifies the intent of a perpetrator.
455full backup A complete backup of the entire system, including all applications, operating
456systems components, and data.
457incident damage assessment The rapid determination of how seriously a breach of
458confidentiality, integrity, and availability affected information and information assets during an
459incident or just following one.
460incremental backup A backup that archives only the files that have been modified since the
461previous incremental backup.
462Once the incident has been contained and control of the systems is regained, the next stage
463of the IR plan is incident recovery. This stage of the plan must be executed immediately. As
464with incident reaction, the first task is to identify needed human resources and launch them
465into action. Almost simultaneously, the organization must assess the full extent of the dam-
466age to determine how to restore the system to a fully functional state. Next, the process of
467computer forensics determines how the incident occurred and what happened. These facts
468emerge from a reconstruction of the data recorded before and during the incident. Next,
469the organization repairs vulnerabilities, addresses any shortcomings in its safeguards, and
470restores systems data and services.
471Prioritization of Efforts As the dust settles from the incident, a state of confusion and
472disbelief may follow. The fallout from stressful workplace activity is well-documented; the
473common view is that cyberattacks, like conflicts of all kinds, affect everyone involved. To
474recover from the incident, the organization must keep people focused on the task ahead and
475make sure that the necessary personnel begin recovery operations according to the IR plan.
476Damage Assessment An incident damage assessment may take only moments, or it may
477take days or weeks, depending on the extent of the damage. The damage caused by an incident
478208 Chapter 4
479Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
480Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
4814
482can range from the minor effects of a curious hacker snooping around to extremely severe—a
483credit card number theft or the infection of hundreds of computer systems by a worm or virus.
484Several sources of information can be used to determine the type, scope, and extent of damage,
485including system logs, intrusion detection logs, configuration logs and documents, documenta-
486tion from the incident response, and the results of a detailed assessment of systems and
487data storage. Using these logs and documentation as a basis for comparison, the IR team can
488evaluate the current state of the information and systems. A related part of incident damage
489assessment is the field of computer forensics. Computer evidence must be carefully collected,
490documented, and maintained to be usable in formal or informal proceedings. Organizations
491may conduct informal proceedings when dealing with internal violations of policy or standards
492of conduct. They may also need to use evidence in formal administrative or legal proceedings.
493Sometimes the fallout from an incident lands in a courtroom for a civil trial. In each of these cir-
494cumstances, the people who examine the damage incurred must receive special training so that if
495an incident becomes part of a crime or civil action, they are adequately prepared to participate.
496Recovery Once the extent of the damage has been determined, the recovery process can
497begin in earnest. Full recovery from an incident requires the following actions:
4981. Identify the vulnerabilities that allowed the incident to occur and spread. Resolve them.
4992. Address the safeguards that failed to stop or limit the incident, or that were missing
500from the system in the first place. Install, replace, or upgrade these safeguards.
5013. Evaluate monitoring capabilities if they are present. Improve their detection and report-
502ing methods or install new monitoring capabilities.
5034. Restore the data from backups. See the following Technical Details features for more
504information on data storage and management, system backups and recovery, and
505redundant array of independent disks (RAID). Restoration requires the IR team to
506understand the organization’s backup strategy, restore the data contained in backups,
507and then recreate the data that was created or modified since the last backup.
5085. Restore the services and processes in use. Compromised services and processes must be
509examined, cleaned, and then restored. If services or processes were interrupted while
510regaining control of the systems, they need to be brought back online.
5116. Continuously monitor the system. If an incident happened once, it can easily happen
512again. Just because the incident is over doesn’t mean the organization is in the clear.
513Hackers frequently boast of their abilities in chat rooms and dare peers to match their
514efforts. If word gets out, others may be tempted to try their hands at similar attacks.
515Therefore, it is important to maintain vigilance during the entire IR process.
5167. Restore confidence to the organization’s communities of interest. It may be advisable to
517issue a short memorandum that outlines the incident and assures everyone that it was
518controlled with as little damage as possible. If the incident was minor, the organization
519should say so. If the incident was major or severely damaged the systems or data, users
520should be reassured that they can expect operations to return to normal shortly. The
521objective is not to placate or lie, but to prevent panic or confusion from causing addi-
522tional disruptions to the organization’s operations.
523Before returning to routine duties, the IR team must conduct an after-action review or AAR.
524All key players review their notes and verify that the IR documentation is accurate and precise.
525Continuity Strategies 209
526Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
527Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
528All team members review their actions during the incident and identify areas in which the IR plan
529worked, didn’t work, or should be improved. This approach allows team members to update the
530IR plan while the needed changes are fresh in their minds. The AAR is documented and can serve
531as a training case for future staff. The finished AAR completes the actions of the IR team.
532Backup Media The following Technical Details feature provides additional insight into
533backup management and strategies. The most common types of local backup media include
534digital audio tapes (DAT), quarter-inch cartridge drives (QIC), 8-mm tape, and digital linear
535tape (DLT). Each type of tape has its restrictions and advantages. Backups can also be per-
536formed with CD-ROM and DVD options (CD-R, CD-RW, and DVD-RW), specialized drives
537(solid state flash drives), or tape arrays.
538Online and Cloud Backup Many organizations are abandoning physical, local backup
539media in favor of online or cloud backups. One of the newest forms of data backup is online
540backup to a third-party data storage vendor. Several backup software and service providers
541now offer multi-terabyte online data storage anywhere. Even for the home user, companies
542like Memeo (www.memeo.com), Dropbox (www.dropbox.com), and Google (Google Drive,
543at http://drive.google.com) offer options that range from free accounts for minimal amounts
544of storage to inexpensive multi-gigabyte and terabyte solutions.
545For the corporate user, this online storage is sometimes referred to as data storage in the
546cloud. This option is more commonly associated with the leasing of computing resources
547from a third party, as in cloud computing, but many organizations also lease data storage
548from cloud vendors. Cloud computing is most commonly described in three offerings:
549â—
550Software as a Service (SaaS), in which applications are provided for a fee but hosted
551on third-party systems and accessed over the Internet and the Web.
552â—
553Platform as a Service (PaaS), in which development platforms are available to develo-
554pers for a fee and are hosted by third parties.
555â—
556Infrastructure as a Service (IaaS), which is informally known as Everything as a
557Service, provides hardware and operating systems resources to host whatever the orga-
558nization wants to implement. Again, the service is hosted by a third party for a fee.
559Organizations can easily lease SaaS online backup services and receive data storage as part of
560the package. From an ownership perspective, clouds can be public, community, private, or
561some combination of the three:
562â—
563Public clouds: The most common implementation, in which a third party makes ser-
564vices available via the Internet and Web to anyone who needs them.
565â—
566Community clouds: A collaboration between a few entities for their sole benefit.
567â—
568Private clouds: An extension of an organization’s intranet applied to cloud computing;
569this option technically negates one of the benefits of cloud computing, which is that it
570requires little or no capital investment. Some larger organizations choose to deploy
571cloud architectures and implement the services across subordinate organizations.
572From a security perspective, the leasing of third-party services is always a challenge. If the
573organization doesn’t own the hardware, software, and infrastructure, it can’t guarantee effec-
574tive security. Therefore, security must be obtained through a warranty; the organization must
575scrutinize the service agreement and insist on minimal standards of due care.
576210 Chapter 4
577Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
578Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
5794
580Data Storage and Management
581To better understand what happens during data restoration in an incident response
582or disaster recovery, you should understand how system backups are created. Data
583backup is a complex operation that involves selecting the backup type, establishing
584backup schedules, and even duplicating data automatically using a redundant array
585of independent disks (see the next Technical Details feature).
586There are three basic types of backups: full, differential, and incremental. The
587advantage of a full backup is that it takes a comprehensive snapshot of the organi-
588zation’s system. The primary disadvantages are that a lot of media are required to
589store such a large archive and the backup can be time consuming. The differential
590backup updates the backup set only with files that have changed since the last full
591backup. This method is faster and uses less storage space than the full backup, but
592each daily differential backup is larger and slower than that of the previous day.
593For example, if you conduct a full backup on Sunday, then Monday’s backup
594contains all the files that have changed since Sunday, as does Tuesday’s backup. By
595Friday, the file size will have grown substantially. Also, if one backup is corrupt, the
596previous day’s backup contains almost all of the same information.
597The third type of backup is the incremental backup. It captures files that have
598changed since the last incremental backup and requires less space and time than
599the differential method. The downside to incremental backups is that multiple
600backups would be needed to restore the full system if an incident occurs.
601The first component of a backup and recovery system is scheduling and storing
602the backups. The most common schedule is a daily onsite incremental or differential
603backup and a weekly off-site full backup. Most backups are conducted overnight,
604when systems activity is lowest and the probability of user interruption is limited.
605There are many methods for selecting files to back up and determining where to
606store various versions of the backups. Organizations will choose methods that best
607balance security needs against allowing ready accessibility for less severe recovery
608needs.
609Regardless of the strategy employed, some fundamental principles remain the
610same. For example, all onsite and off-site storage must be secured. Fireproof safes
611or filing cabinets are commonly used to store tapes. Off-site storage in particular
612requires a safe location, such as a bank’s safety deposit box or a professional
613backup and recovery service. (The trunk of the administrator’s car is not secure off-
614site storage.) Tapes require a conditioned environment—preferably an airtight,
615humidity-free, static-free storage container. Each tape must be clearly labeled and
616write-protected. Because tapes frequently wear out, they should be retired periodi-
617cally and replaced with new media.
618TECHNICAL DETAILS
619Continuity Strategies 211
620Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
621Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
622Automated Response New technologies are emerging in the field of incident response.
623Some of them build on existing technologies and extend their capabilities and functions. Tra-
624ditional systems were configured to detect incidents and then notify a human administrator,
625but new systems can respond to the incident threat autonomously, based on preconfigured
626options. A more complete discussion of these technologies is presented in Chapter 7.
627The disadvantages of current automated response systems may outweigh their benefits. For exam-
628ple, legal issues of tracking suspects with these systems have yet to be resolved. What if the
629“hacker†turns out to be a compromised system running an automated attack? What are the
630legal liabilities of a counterattack? How can security administrators condemn a hacker when they
631may have illegally hacked systems themselves to track the hacker? These issues are complex, but
632they must be resolved to give security professionals better tools to combat incidents.
633TECHNICAL DETAILS
634System Backups and Recovery—RAID
635Key Terms
636disk duplexing Disk mirroring in which each drive has its own controller to provide additional
637redundancy.
638disk mirroring A RAID implementation (typically referred to as RAID Level 1) in which the
639computer records all data to twin drives simultaneously, providing a backup if the primary drive
640fails.
641disk striping A RAID implementation (typically referred to as RAID Level 0) in which one
642logical volume is created by storing data across several available hard drives in segments called
643stripes.
644hot swap A hard drive feature that allows individual drives to be replaced without fault and
645without powering down the entire system.
646redundant array of independent disks (RAID) A system of drives that stores information
647across multiple units to spread out data and minimize the impact of a single drive failure.
648server fault tolerance A level of redundancy provided by mirroring entire servers called
649redundant servers.
650One form of data backup for online usage is the redundant array of independent disks
651(RAID). Unlike tape backups, RAID uses several hard drives to store information across mul-
652tiple units, which spreads out data and minimizes the impact of a single drive failure. There
653are nine established RAID configurations, many of which are illustrated in Figure 4-16.
654RAID Level 0: RAID 0 is not actually a form of redundant storage—it creates one
655large logical volume and stores the data in segments called stripes across all avail-
656able hard disk drives in the array. This method is also often called disk striping
657without parity, and it is frequently used to combine smaller drive volumes into
658fewer, larger volumes. Unfortunately, failure of one drive may make all data inac-
659cessible. This type of RAID is useful when larger aggregate volume sizes are needed
660without regard for redundancy or reliability.
661212 Chapter 4
662Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
663Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
664RAID Level 1: Commonly called disk mirroring, RAID Level 1 uses twin drives in a
665computer system. The computer records all data to both drives simultaneously, pro-
666viding a backup if the primary drive fails. However, RAID 1 is a rather expensive and
667inefficient use of media. A variation of mirroring called disk duplexing provides
668additional redundancy by incorporating separate controllers for each drive. Mirror-
669ing is often used to create duplicate copies of operating system volumes for high-
670availability systems. This type of RAID is useful when a high degree of redundancy
671and improved access performance are required.
672RAID Level 2: This specialized form of disk striping with parity is not widely
673employed. It uses a specialized parity coding mechanism known as the Hamming
674Code to store stripes of data on multiple data drives and corresponding redundant
675error correction on separate error-correcting drives. This approach allows the recon-
676struction of data if some of the data or redundant parity information is lost. There
677are no commercial implementations of RAID Level 2.
678RAID Levels 3 and 4: RAID 3 is byte-level striping of data and RAID 4 is block-level
679striping, in which data is stored in segments on dedicated data drives and parity
680information is stored on a separate drive. As with RAID 0, one large volume is used
681for the data, but the parity drive operates independently to provide error recovery.
682Block 7
683Disk 1
684Block 5
685Block 3
686Block 1
687Block 8
688Disk 2
689Block 6
690Block 4
691Block 2
692RAID 0
693Striping
694Parity 4
695Disk 1
696Block 3a
697Block 2a
698Block 1a
699Block 4a
700Disk 2
701Parity 3
702Block 2b
703Block 1b
704RAID 5
705Striped parity
706Block 4b
707Disk 3
708Block 3b
709Parity 2
710Block 1c
711Block 4c
712Disk 4
713Block 3c
714Block 2c
715Parity 1
716Block 4
717Disk 1
718Block 3
719Block 2
720Block 1
721Block 4
722Disk 2
723Block 3
724Block 2
725Block 1
726RAID 1
727Mirroring
728Block 7
729Disk 1
730Block 5
731Block 3
732Block 1
733Block 8
734Disk 2
735Block 6
736Block 4
737Block 2
738RAID 01 (0+1)
739Striping then mirroring
740Block 7
741Disk 3
742Block 5
743Block 3
744Block 1
745Block 8
746Disk 4
747Block 6
748Block 4
749Block 2
750Figure 4-16 Common RAID implementations
751© Cengage Learning 2015
7524
753(continues)
754Continuity Strategies 213
755Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
756Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
757‡ Disaster Recovery Planning
758An event can be categorized as a disaster when an organization is unable to mitigate the
759impact of an incident while it is occurring and the level of damage or destruction is so severe
760that the organization is unable to recover quickly. The difference between an incident and a
761disaster may be subtle; the contingency planning team must make the distinction between
762the two, which may not be possible until an attack occurs. Often an event that is initially
763classified as an incident is later determined to be a disaster. When this happens, the organiza-
764tion must change its response and secure its most valuable assets to preserve their value for
765the long term, even at the risk of more short-term disruption.
766Disaster recovery (DR) planning is the process of preparing an organization to handle a disaster
767and recover from it, whether the disaster is natural or man-made. The key emphasis of a DR plan
768is to reestablish operations at the primary site, the location at which the organization performs its
769business. The goal of the plan is to make things whole, or as they were before the disaster.
770The Disaster Recovery Plan Similar in structure to the IR plan, the DR plan pro-
771vides detailed guidance in the event of a disaster. It is organized by the type or nature of
772the disaster, and it specifies recovery procedures during and after each type of disaster. It
773also provides details about the roles and responsibilities of the people involved in the DR
774effort, and it identifies the personnel and agencies that must be notified. The DR plan must
775be tested using the same testing mechanisms as the IR plan. At a minimum, the DR plan
776must be reviewed periodically during a walk-through or talk-through.
777Many of the same precepts of incident response apply to disaster recovery:
778â—
779Priorities must be clearly established. The first priority is always the preservation of
780human life. The protection of data and systems immediately falls to the wayside if
781This level of RAID is used when an organization requires a trade-off between disk
782capacity usage and reliability of recovery.
783RAID Level 5: This form of RAID is most commonly used in organizations that
784balance safety and redundancy against the costs of acquiring and operating the
785systems. It is similar to RAID 3 and 4 in that it stripes the data across multiple drives,
786but there is no dedicated parity drive. Instead, segments of data are interleaved
787with parity data and are written across all of the drives in the set. RAID 5 drives
788can also be hot swapped, which improves the organization’s chances of regaining
789full capability, compared with a RAID 3 or 4 implementation.
790RAID Level 6: RAID 5 with two sets of parity for each parcel of data, which pro-
791vides an additional level of protection.
792RAID Level 7: This is a variation on RAID 5, in which the array works as a single
793virtual drive. RAID Level 7 is sometimes performed by running special software
794over RAID 5 hardware.
795RAID Level 10: This is a combination of RAID 1 and RAID 0 (0+1: mirroring then
796striping).
797Additional redundancy can be provided by mirroring entire servers called redun-
798dant servers or server fault tolerance.
799214 Chapter 4
800Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
801Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
8024
803the disaster threatens the lives, health, or welfare of the organization’s employees or
804community. Only after all employees and neighbors have been safeguarded can the
805disaster recovery team attend to protecting other assets.
806â—
807Roles and responsibilities must be clearly delineated. All members of the DR team
808should be aware of their expected actions during a disaster. Some people are responsi-
809ble for coordinating with local authorities, such as fire, police, and medical staff.
810Others are responsible for the evacuation of personnel, if required. Still others are
811tasked simply to pack up and leave.
812â—
813Someone must initiate the alert roster and notify key personnel, including the fire,
814police, or medical authorities mentioned earlier, as well as insurance agencies, disaster
815teams like the Red Cross, and management teams.
816â—
817Someone must be tasked with documenting the disaster. As with an IR reaction, some-
818one must begin recording what happened to serve as a basis for later determining why
819and how the event occurred.
820â—
821If possible, attempts must be made to mitigate the impact of the disaster on the orga-
822nization’s operations. If everyone is safe and all needed authorities have been notified,
823some employees can be tasked with the evacuation of physical assets. Some can be
824responsible for making sure all systems are securely shut down to prevent further loss
825of data.
826Recovery Operations Reactions to a disaster can vary so widely that it is impossible
827to describe the process with any accuracy. Each organization must examine the scenarios
828developed at the start of contingency planning and determine how to respond.
829Should the physical facilities be spared after the disaster, the disaster recovery team should
830begin restoring systems and data to reestablish full operational capability. If the organiza-
831tion’s facilities do not survive, alternative actions must be taken until new facilities can be
832acquired. When a disaster threatens the viability of the organization at the primary site, the
833disaster recovery process transitions into the process of business continuity planning.
834‡ Business Continuity Planning
835Business continuity planning prepares an organization to reestablish or relocate critical busi-
836ness operations during a disaster that affects operations at the primary site. If a disaster has
837rendered the current location unusable, a plan must be in place to allow the business to con-
838tinue to function. Not every business needs such a plan or such facilities. Small companies or
839fiscally sound organizations may have the latitude to cease operations until the physical facili-
840ties can be restored. Manufacturing and retail organizations may not have this option because
841they depend on physical commerce and may not be able to relocate operations.
842Developing Continuity Programs Once the incident response and disaster recov-
843ery plans are in place, the organization needs to consider finding temporary facilities to
844support its continued viability in a disaster. A BC plan is somewhat simpler to develop
845than an IR plan or DR plan because it consists primarily of selecting a continuity strategy
846and integrating the off-site data storage and recovery functions into this strategy. Some
847components of the BC plan, such as an off-site backup service, could already be integral
848to the organization’s normal operations. Other components require special consideration
849and negotiation.
850Continuity Strategies 215
851Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
852Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
853The first part of business continuity planning is performed when the joint DR/BC plan is
854developed. The identification of critical business functions and the resources needed to sup-
855port them is the cornerstone of the BC plan. When a disaster strikes, these functions are the
856first to be reestablished at the alternate site. The contingency planning team needs to
857appoint a group of people to evaluate and compare various alternatives and recommend
858which strategy should be selected and implemented. The selected strategy usually involves
859some form of off-site facility, which should be inspected, configured, secured, and tested on
860a periodic basis. The selection should be reviewed periodically to determine if a superior
861alternative has emerged or if the organization needs a different solution.
862Site and Data Contingency Strategies
863Key Terms
864cold site An exclusive-use contingency strategy in which an organization leases a redundant
865facility without any systems, services, or equipment, requiring substantial purchases and effort to
866resume operations. Essentially, a cold site is an empty set of offices or rooms.
867database shadowing An improvement to the process of remote journaling, in which databases
868are backed up in near-real time to multiple servers at both local and remote sites.
869electronic vaulting The transfer of large batches of data to an off-site facility, typically during
870off-peak hours.
871hot site An exclusive-use contingency strategy in which an organization leases a redundant
872facility complete with all systems, services, and equipment needed to resume operations with
873minimal delay.
874mutual agreement A contractual relationship between two or more organizations that
875specifies how each will assist the other in the event of a disaster; unaffected organizations are
876required to provide any needed resources to maintain the organization affected by the disaster.
877remote journaling The transfer of live transactions rather than archived data to an off-site
878facility in near-real time.
879service bureau An agency that provides physical facilities in a disaster for a fee.
880time-share The business continuity strategy that allows an organization to co-lease a hot, warm,
881or cold site in conjunction with one or more business partners or other organizations.
882warm site An exclusive-use contingency strategy in which an organization leases a redundant
883facility complete with some systems, services, and equipment needed to resume operations with
884a reasonable delay.
885An organization can choose from several strategies when planning for business continuity.
886The determining factor when selecting a strategy is usually cost. In general, organizations
887have three exclusive options: hot sites, warm sites, and cold sites. Options are also available
888for three shared functions: time-shares, service bureaus, and mutual agreements.
889Hot Sites A hot site is a fully configured computer facility with all services, communica-
890tions links, and physical plant operations, including heating and air conditioning. Hot sites
891duplicate computing resources, peripherals, phone systems, applications, and workstations.
892A hot site is the pinnacle of contingency planning; it is a duplicate facility that needs only
893the latest data backups and personnel to become a fully operational twin of the original. A
894hot site can be operational in a matter of minutes, and in some cases it may be built to pro-
895vide a process that is seamless to system users by picking up the processing load from a fail-
896ing site. (This process is sometimes called a seamless fail-over.) The hot site is therefore the
897216 Chapter 4
898Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
899Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
9004
901most expensive alternative available. Other disadvantages include the need to provide mainte-
902nance for all systems and equipment in the hot site, as well as physical and information secu-
903rity. However, if the organization needs a 24/7 capability for near real-time recovery, a hot
904site is the best option.
905Warm Sites The next step down from the hot site is the warm site. A warm site provides
906many of the same services and options as the hot site. However, it typically does not include
907the actual applications the company needs, or the applications may not yet be installed and con-
908figured. A warm site frequently includes computing equipment and peripherals with servers, but
909not client workstations. A warm site has many of the advantages of a hot site, but at a lower
910cost. The downside is that a warm site requires hours, if not days, to become fully functional.
911Cold Sites The final dedicated site option is the cold site. A cold site provides only rudi-
912mentary services and facilities. No computer hardware or peripherals are provided. All com-
913munications services must be installed after the site is occupied. Basically, a cold site is an
914empty room with heating, air conditioning, and electricity. Everything else is an option.
915Although the obvious disadvantages may preclude its selection, a cold site is better than noth-
916ing. The main advantage of cold sites over hot and warm sites is the cost. If the warm or hot
917site is a shared arrangement, not having to contend with other organizations and their equip-
918ment after a widespread disaster may make the cold site a better option, albeit slower. In
919spite of these advantages, some organizations feel it would be easier to lease a new space on
920short notice than pay maintenance fees on a cold site.
921Time-shares A time-share allows the organization to maintain a disaster recovery and
922business continuity option by sharing the cost of a hot, warm, or cold site with one or more
923partners. The time-share has the same advantages as the type of site selected (hot, warm, or
924cold). The primary disadvantage is the possibility that more than one organization involved
925in the time-share may need the facility simultaneously. Other disadvantages include the need
926to stock the facility with equipment and data from all organizations involved, the negotia-
927tions for arranging the time-share, and additional agreements if one or more parties decide
928to cancel the agreement or sublease its options. A time-share is like agreeing to co-lease an
929apartment with a group of friends. The participating organizations need to remain on amia-
930ble terms because they would have physical access to each other’s data.
931Service Bureaus In case of a disaster, a service bureau agrees to provide physical facilities.
932These types of agencies also frequently provide off-site data storage for a fee. Contracts can
933be carefully created with service bureaus to specify exactly what the organization needs with-
934out having to reserve dedicated facilities. A service agreement usually guarantees space when
935needed, even if the service bureau has to acquire additional space in the event of a wide-
936spread disaster. This option is much like the rental car clause in your car insurance policy.
937The disadvantage is that the bureau is a service and must be renegotiated periodically. Also,
938using a service bureau can be quite expensive.
939Mutual Agreements Mutual agreements stipulate that participating unaffected organiza-
940tions are obligated to provide necessary facilities, resources, and services until the receiving
941Continuity Strategies 217
942Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
943Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
944organization can recover from the disaster. This type of arrangement is like moving in with
945relatives or friends: it doesn’t take long to outstay your welcome. The problem with this
946approach is that many organizations balk at the idea of having to fund duplicate services
947and resources for other parties, even in the short term. The arrangement is ideal if you need
948the assistance, but not if you are the host. Still, mutual agreements between divisions of the
949same parent company, between subordinate and superior organizations, or between business
950partners can be a cost-effective solution.
951Other Options Specialized alternatives are available, such as a rolling mobile site config-
952ured in the payload area of a tractor or trailer, or externally stored resources. These resources
953can consist of a rental storage area that contains duplicate or second-generation equipment to
954be extracted in an emergency. An organization can also contract with a prefabricated building
955company for immediate, temporary facilities (mobile offices) that can be placed onsite in the
956event of a disaster. These alternatives should be considered when evaluating strategy options.
957Off-site Disaster Data Storage To get continuity sites up and running quickly, the
958organization must be able to move data into the new site’s systems. Besides the traditional
959backup methods mentioned earlier, several more options are available, and some can be
960used for purposes other than restoring continuity:
961â—
962Electronic vaulting transfers data off-site in batches, usually through leased lines or ser-
963vices provided for a fee. The receiving server archives the data until the next electronic
964vaulting process is received. Some disaster recovery companies specialize in electronic
965vaulting services.
966â—
967Remote journaling differs from electronic vaulting in that only transactions are trans-
968ferred, not archived data; also, the transfer is in real time. Electronic vaulting is much
969like a traditional backup, with a dump of data to the off-site storage, but remote jour-
970naling involves activities at a systems level, much like server fault tolerance, with data
971written to two locations simultaneously.
972â—
973An improvement to the process of remote journaling, database shadowing combines
974the server fault tolerance mentioned earlier with remote journaling, writing three or
975more copies of the database simultaneously to backup systems locally and at one or
976more remote locations.
977‡ Crisis Management
978Key Term
979crisis management The set of actions taken by an organization in response to an emergency to
980minimize injury or loss of life, preserve the organization’s image and market share, and
981complement its disaster recovery and business continuity processes.
982Disasters, of course, are larger in scale and less manageable than incidents, but the planning
983processes for both are the same and in many cases are conducted simultaneously. What may
984truly distinguish an incident from a disaster are the actions of the response teams. An
985218 Chapter 4
986Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
987Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
9884
989incident response team typically rushes to duty stations or to the office from home. The first
990act is to reach for the IR plan. A disaster recovery team may not have the luxury of flipping
991through a binder to see what must be done. Disaster recovery personnel must know their
992roles without any supporting documentation. This knowledge is a function of preparation,
993training, and rehearsal. You probably remember frequent fire, tornado, or hurricane drills—
994or even nuclear blast drills—from your school days. Moving from school to the business
995world doesn’t lessen the threat of a fire or other disaster.
996The actions taken during and after a disaster are referred to as crisis management. Crisis
997management differs dramatically from incident response, as it focuses first and foremost on
998the people involved. The disaster recovery team works closely with the crisis management
999team. According to Gartner Research, the crisis management team is:
1000responsible for managing the event from an enterprise perspective and covers the
1001following major activities:
1002â—
1003Supporting personnel and their loved ones during the crisis
1004â—
1005Determining the event’s impact on normal business operations and, if nec-
1006essary, making a disaster declaration
1007â—
1008Keeping the public informed about the event and the actions being taken to
1009ensure the recovery of personnel and the enterprise
1010â—
1011Communicating with major customers, suppliers, partners, regulatory
1012agencies, industry organizations, the media, and other interested parties. 36
1013The crisis management team should establish a base of operations or command center to
1014support communications until the disaster has ended. The crisis management team includes
1015people from all functional areas of the organization to facilitate communications and cooper-
1016ation. Some key areas of crisis management include the following:
1017â—
1018Verifying personnel head count: Everyone must be accounted for, including people on
1019vacations, leaves of absence, and business trips.
1020â—
1021Checking the alert roster: Alert rosters and general personnel phone lists are used to
1022notify people whose assistance may be needed or simply to tell employees not to report
1023to work until the crisis or event is over.
1024â—
1025Checking emergency information cards: It is important that each employee has two
1026types of emergency information cards. The first is personal information that includes
1027next of kin and other contacts in case of an emergency, medical conditions, and a form
1028of identification. The second is a set of instructions for what to do in an emergency.
1029This mini-snapshot of the disaster recovery plan should contain at least a contact
1030number or hotline number; emergency services numbers for fire, police, and medical
1031assistance; evacuation and assembly locations, such as storm shelters; the name and
1032number of the disaster recovery coordinator; and any other needed information.
1033Crisis management must balance the needs of employees with the needs of the business in
1034providing personnel with support at home during disasters.
1035‡ The Consolidated Contingency Plan
1036Using the strategy described earlier and illustrated in Figure 4-14, an organization can build a
1037single document that combines all aspects of the contingency policy and plan, incorporating
1038Continuity Strategies 219
1039Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1040Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
1041the IR, DR, and BC plans. In large organizations, such a document may be massive; because
1042it would be unwieldy in physical form, it is often created and stored electronically in a safe
1043and secure off-site location. The document should be online and easily accessible via the
1044Internet by appropriate employees in time of need. The document may be stored in an
1045encrypted file and within a password-protected repository.
1046Small and medium-sized organizations can use the same approach, but they may also store hard
1047copies of the document both within and outside the organization, at the residences of people
1048who may need them.
1049All contingency planners live by the following words: plan for the worst and hope for the best.
1050‡ Law Enforcement Involvement
1051Sometimes, an attack, breach of policy, or other incident constitutes a violation of law. Per-
1052haps the incident was originally considered an accident, but turns out to have been an
1053attempt at corporate espionage, sabotage, or theft. When an organization considers involving
1054law enforcement in an incident, several questions must be answered. When should the orga-
1055nization get law enforcement involved? What level of law enforcement agency should be
1056involved—local, state, or federal? What happens when a law enforcement agency is involved?
1057Some of these questions are best answered by the organization’s legal department, but orga-
1058nizations should be prepared to address them in the absence of legal staff. These incidents
1059often occur under circumstances that do not allow for leisurely decision making. Some agen-
1060cies that may be involved were discussed in detail in Chapter 3.
1061Benefits and Drawbacks of Law Enforcement Involvement The involve-
1062ment of law enforcement agencies has advantages and disadvantages. The agencies may be
1063much more capable of processing evidence than an organization. In fact, unless the organi-
1064zation’s security forces have been trained in processing evidence and computer forensics,
1065they may do more harm than good when extracting the necessary information to legally
1066convict a suspected criminal. Law enforcement agencies can issue the warrants and subpoe-
1067nas necessary to document a case, and are adept at obtaining statements from witnesses,
1068affidavits, and other required documents. Law enforcement personnel can be a security
1069administrator’s greatest ally in the war on computer crime. Therefore, organizations should
1070get to know the local and state officials charged with enforcing information security laws
1071before having to make a call to report a suspected crime.
1072Once a law enforcement agency takes over a case, however, the organization cannot entirely
1073control the chain of events, the collection of information and evidence, and the prosecution
1074of suspects. A suspect who might face censure and dismissal by an organization may also
1075face criminal charges and all the attendant publicity. The organization may not be informed
1076about the case’s progress for weeks or even months. Equipment that is vital to the organiza-
1077tion’s business may be tagged as evidence and then removed, stored, and preserved until it is
1078no longer needed for the criminal case. In fact, the equipment may never be returned.
1079If an organization detects a criminal act, it is legally obligated to involve appropriate law
1080enforcement officials. Failure to do so can subject the organization and its officers to prose-
1081cution as accessories to the crimes or as impediments to an investigation. The security
1082administrator must ask law enforcement officials when their agencies need to become
1083involved and which crimes need to be addressed by each agency.
1084220 Chapter 4
1085Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1086Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
10874
1088Selected Readings
1089Many excellent sources of additional information are available in the area of information
1090security. The following can add to your understanding of this chapter’s content:
1091â—
1092Information Security Governance: Guidance for Boards of Directors and Executive
1093Management, available by searching at www.isaca.org.
1094â—
1095Information Security Governance: A Call to Action, available from www.cccure.org/
1096Documents/Governance/InfoSecGov4_04.pdf.
1097â—
1098Information Security Policies Made Easy, Version 10, by Charles Cresson Wood.
10992005. Information Shield.
1100â—
1101Management of Information Security, by Michael E. Whitman and Herbert J. Mattord.
11022013. Cengage Learning.
1103â—
1104Principles of Incident Response and Disaster Recovery, by Michael E. Whitman and
1105Herbert J. Mattord. 2013. Cengage Learning.
1106Chapter Summary
1107â– Information security governance is the application of the principles of corporate
1108governance to the information security function. These principles include executive
1109management’s responsibility to provide strategic direction, ensure the accomplishment
1110of objectives, oversee that risks are appropriately managed, and validate responsible
1111resource use.
1112â– Management must use policies as the basis for all information security planning,
1113design, and deployment. Policies direct how issues should be addressed and technolo-
1114gies should be used.
1115â– Standards are more detailed than policies and describe the steps that must be taken to
1116conform to policies.
1117â– Management must define three types of security policies: general or security program
1118policies, issue-specific security policies, and systems-specific security policies.
1119â– The enterprise information security policy (EISP) should be a driving force in the
1120planning and governance activities of the organization as a whole.
1121â– Several published information security frameworks by government organizations,
1122private organizations, and professional societies supply information on best practices
1123for their members.
1124â– One of the foundations of security architectures is the layered implementation of
1125security. This layered approach is referred to as defense in depth.
1126â– Information security policy is best disseminated in a comprehensive security education,
1127training, and awareness (SETA) program. A security awareness program is one of the
1128least frequently implemented but most beneficial programs in an organization. A
1129security awareness program is designed to keep information security at the forefront of
1130users’ minds.
1131Chapter Summary 221
1132Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1133Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
1134â– Contingency planning (CP) comprises a set of plans designed to ensure effective reac-
1135tions to an attack and recovery from it. These plans also help restore an organization
1136to normal modes of business operations.
1137â– Organizations must develop disaster recovery plans, incident response plans, and busi-
1138ness continuity plans using a business impact analysis (BIA). This process consists of
1139five stages: identification and prioritization of the threat attack, business unit analysis
1140and prioritization, attack success scenario development, potential damage assessment,
1141and subordinate plan classification.
1142â– Incident response planning consists of four phases: incident planning, incident detec-
1143tion, incident reaction, and incident recovery.
1144â– Disaster recovery planning outlines the response to a disaster and recovery from it,
1145whether the disaster is natural or man-made.
1146â– Business continuity planning includes the steps organizations take so they can function
1147when business cannot be resumed at the primary site.
1148â– Crisis management refers to the actions an organization takes during and immedi-
1149ately after a disaster. Crisis management focuses first and foremost on the people
1150involved.
1151â– It is important to understand when and if to involve law enforcement in a corporate
1152incident. Getting to know local and state law enforcement can assist organizations in
1153these decisions.
1154Review Questions
11551. How can a security framework assist in the design and implementation of a security
1156infrastructure? What is information security governance? Who in the organization
1157should plan for it?
11582. Where can a security administrator find information on established security frameworks?
11593. What is the ISO 27000 series of standards? Which individual standards make up the
1160series?
11614. What are the inherent problems with ISO 17799, and why hasn’t the United States
1162adopted it? What are the recommended alternatives?
11635. What documents are available from the NIST Computer Security Resource Center, and
1164how can they support the development of a security framework?
11656. What benefit can a private, for-profit agency derive from best practices designed for
1166federal agencies?
11677. What Web resources can aid an organization in developing best practices as part of a
1168security framework?
11698. Briefly describe management, operational, and technical controls, and explain when
1170each would be applied as part of a security framework.
1171222 Chapter 4
1172Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1173Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
11744
11759. What are the differences between a policy, a standard, and a practice? What are the
1176three types of security policies? Where would each be used? What type of policy
1177would be needed to guide use of the Web? E-mail? Office equipment for personal use?
117810. Who is ultimately responsible for managing a technology? Who is responsible for
1179enforcing policy that affects the use of a technology?
118011. What is contingency planning? How is it different from routine management planning?
1181What are the components of contingency planning?
118212. When is the IR plan used?
118313. When is the DR plan used?
118414. When is the BC plan used? How do you determine when to use the IR, DR, and BC
1185plans?
118615. What are the five elements of a business impact analysis?
118716. What are Pipkin’s three categories of incident indicators?
118817. What is containment, and why is it part of the planning process?
118918. What is computer forensics? When are the results of computer forensics used?
119019. What is an after-action review? When is it performed? Why is it done?
119120. List and describe the six site and data contingency strategies identified in the text.
1192Exercises
11931. Using a graphics program, design several security awareness posters on the following
1194themes: updating antivirus signatures, protecting sensitive information, watching out for
1195e-mail viruses, prohibiting the personal use of company equipment, changing and pro-
1196tecting passwords, avoiding social engineering, and protecting software copyrights.
1197What other themes can you imagine?
11982. Search the Web for security education and training programs in your area. Keep a list
1199and see which category has the most examples. See if you can determine the costs asso-
1200ciated with each example. Which do you think would be more cost-effective in terms of
1201both time and money?
12023. Search the Web for examples of issue-specific security policies. What types of policies
1203can you find? Using the format provided in this chapter, draft a simple issue-specific
1204policy that outlines fair and responsible use of computers at your college, based on the
1205rules and regulations of your institution. Does your school have a similar policy? Does
1206it contain all the elements listed in the text?
12074. Use your library or the Web to find a reported natural disaster that occurred at least six
1208months ago. From the news accounts, determine whether local or national officials had pre-
1209pared disaster plans and if the plans were used. See if you can determine how the plans
1210helped officials improve disaster response. How do the plans help the recovery?
1211Exercises 223
1212Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1213Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
12145. Classify each of the following occurrences as an incident or disaster. If an occurrence is
1215a disaster, determine whether business continuity plans would be called into play.
1216a. A hacker breaks into the company network and deletes files from a server.
1217b. A fire breaks out in the storeroom and sets off sprinklers on that floor. Some compu-
1218ters are damaged, but the fire is contained.
1219c. A tornado hits a local power station, and the company will be without power for
1220three to five days.
1221d. Employees go on strike, and the company could be without critical workers for
1222weeks.
1223e. A disgruntled employee takes a critical server home, sneaking it out after hours.
1224For each of the scenarios (a–e), describe the steps necessary to restore operations. Indicate
1225whether law enforcement would be involved.
1226Case Exercises
1227Charlie sat at his desk the morning after his nightmare. He had answered the most pressing
1228e-mails in his inbox and had a piping hot cup of coffee at his elbow. He looked down at a
1229blank legal pad, ready to make notes about what to do in case his nightmare became reality.
1230Discussion Questions
12311. What would be the first note you wrote down if you were Charlie?
12322. What else should be on Charlie’s list?
12333. Suppose Charlie encountered resistance to his plans to improve continuity planning.
1234What appeals could he use to sway opinions toward improved business continuity
1235planning?
1236Ethical Decision Making
1237The policies that organizations put in place are similar to laws, in that they are directives for
1238how to act properly. Like laws, policies should be impartial and fair, and are often founded
1239on ethical and moral belief systems of the people who create them.
1240In some cases, especially when organizations expand into foreign countries, they experience a
1241form of culture shock when the laws of their new host country conflict with their internal
1242policies. Suppose that SLS has expanded its operations in France. Setting aside any legal
1243requirements that SLS make its policies conform to French law, does SLS have an ethical
1244imperative to modify its policies to better meet the needs of its stakeholders in the new
1245country?
1246Suppose SLS has altered its policies for all operations in France and that the changes are
1247much more favorable to employees—such as a requirement to provide child and elder-care
1248services at no cost to the employee. Is SLS under any ethical burden to offer the same benefit
1249to employees in its original country?
1250224 Chapter 4
1251Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1252Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
12534
1254Endnotes
12551. IT Governance Institute. Board Briefing on IT Governance, 2nd Edition. 2003. The
1256Chartered Institute of Management Accountants (CIMA) and the International Federa-
1257tion of Accountants (IFAC) also adopted this definition in 2004. Accessed 30 January
12582014 from www.itgi.org.
12592. ITGI. “Information Security Governance: Guidance for Information Security Managers.â€
1260Accessed 30 January 2014 from www.isaca.org.
12613. Wood, Charles Cresson. “Integrated Approach Includes Information Security.†Secu-
1262rity 37, no. 2 (February 2000): 43–44.
12634. “Former Andersen Auditor Admits to Breaking Law.†14 May 2002. Accessed
126430 January 2014 from www.pbs.org/newshour/updates/business-jan-june02-ander
1265sen_05-14/.
12665. Beltran, Luisa. “Andersen Exec: Shredding Began after E-mail.†21 January 2002.
1267Accessed 30 January 2014 from http://money.cnn.com/2002/01/21/companies/enron_
1268odom/.
12696. US-CERT. “Security Recommendations to Prevent Cyber Intrusions.†Accessed 19 July
12702011 from www.us-cert.gov/ncas/alerts/TA11-200A.
12717. National Institute of Standards and Technology. An Introduction to Computer Secu-
1272rity: The NIST Handbook. SP 800-12. Gaithersburg, MD, 1996.
12738. Aalberts, Robert J., Townsend, Anthony M., and Whitman, Michael E. “Considera-
1274tions for an Effective Telecommunications Use Policy.†Communications of the ACM
127542, no. 6 (June 1999): 101–109.
12769. Ibid.
127710. Derived from a number of sources, the most notable of which was accessed 30 January
12782014 from www.wustl.edu/policies/infosecurity.html.
127911. National Institute of Standards and Technology. An Introduction to Computer Secu-
1280rity: The NIST Handbook. SP 800-12. Gaithersburg, MD, 1996.
128112. NetIQ Security Technologies, Inc. User Guide, NetIQ. August 2011. Accessed 30
1282January 2014 from https://www.netiq.com/documentation/vigilent-policy-center/
1283pdfdoc/vigilent-policy-center-user-guide/vigilent-policy-center-user-guide.pdf
128413. National Institute of Standards and Technology. International Standard ISO/IEC
128517799:2000 Code of Practice for Information Security Management. November 2002.
1286Accessed 30 January 2014 from http://csrc.nist.gov/publications/secpubs/otherpubs/
1287reviso-faq-110502.pdf.
128814. Compiled from a number of sources, including: “ISO/IEC 27002:2013 Information
1289technology—Security techniques—Code of practice for information security controls.â€
1290Accessed 30 January 2014 from www.iso27001security.com/html/27002
1291.html; “Introduction to ISO 27002.†Accessed 30 January 2014 from www.27000
1292.org/iso-27002.htm; and “ISO 27002:2013 Version Change Summary.†Accessed 30
1293January 2014 from www.informationshield.com/papers/ISO27002-2013%20Version
1294%20Change%20Summary.pdf.
1295Endnotes 225
1296Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1297Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
129815. National Institute of Standards and Technology. Information Security Management,
1299Code of Practice for Information Security Management. ISO/IEC 17799. 6 December
13002001. Geneva, Switzerland.
130116. Adapted from diagram of ISO 27001:2013 implementation process. Accessed 30
1302January 2014 from www.iso27001standard.com/en/free-downloads.
130317. About the ISO27k standards. Accessed 21 January 2014 from www.iso27001security
1304.com/html/iso27000.html.
130518. National Institute of Standards and Technology. Generally Accepted Principles and
1306Practices for Securing Information Technology Systems. SP 800-14. September 1996.
1307Gaithersburg, MD.
130819. National Institute of Standards and Technology. Guide for Applying the Risk Manage-
1309ment Framework to Federal Information Systems: A Security Life Cycle Approach.
1310Accessed February 2010 at http://csrc.nist.gov/publications/nistpubs/800-37-rev1/
1311sp800-37-rev1-final.pdf.
131220. National Institute of Standards and Technology. “Framework for Improving Critical
1313Infrastructure Cybersecurity, Version 1.0.†12 February 2014. Accessed 2 June 2014
1314from www.nist.gov/cyberframework/upload/cybersecurity-framework-021214-final.pdf.
131521. Ibid.
131622. Ibid.
131723. Ibid.
131824. National Institute of Standards and Technology. “Roadmap for Improving Critical
1319Infrastructure Cybersecurity.†12 February 2014. Accessed 2 June 2014 from www
1320.nist.gov/cyberframework/upload/roadmap-021214.pdf.
132125. National Institute of Standards and Technology. An Introduction to Computer Secu-
1322rity: The NIST Handbook. SP 800-12. Gaithersburg, MD, 1996.
132326. Ibid.
132427. King, William R., and Gray, Paul. The Management of Information Systems. 1989.
1325Chicago: Dryden Press, 359.
132628. Swanson, M., Bowen, P., Phillips, A., Gallup, D., and Lynes, D. National Institute of
1327Standards and Technology. Contingency Planning Guide for Federal Information Systems.
1328SP 800-34, Rev. 1. Accessed 17 February 2013 at http://csrc.nist.gov/publications/nistpubs/
1329800-34-rev1/sp800-34-rev1_errata-Nov11-2010.pdf.
133029. Zawada, B., and Evans, L. “Creating a More Rigorous BIA.†CPM Group. November/
1331December 2002. Accessed 12 May 2005 at www.contingencyplanning.com/archives/
13322002/novdec/4.aspx.
133330. Swanson, M., Bowen, P., Phillips, A., Gallup, D., and Lynes, D. National Institute of
1334Standards and Technology. Contingency Planning Guide for Federal Information Systems.
1335SP 800-34, Rev. 1. Accessed 17 February 2013 at http://csrc.nist.gov/publications/nistpubs/
1336800-34-rev1/sp800-34-rev1_errata-Nov11-2010.pdf.
133731. Ibid.
133832. Cichonski, P., Millar, T., Grance, T., and Scarfone, K. National Institute of Standards
1339and Technology. Computer Security Incident Handling Guide. SP 800-61, Rev. 2.
1340226 Chapter 4
1341Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1342Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
13434
1344August 2012. Accessed 17 February 2103 at http://csrc.nist.gov/publications/nistpubs/
1345800-61rev2/SP800-61rev2.pdf.
134633. Krutz, Ronald L., and Vines, Russell Dean. The CISSP Prep Guide: Mastering the Ten
1347Domains of Computer Security. 2001. New York: John Wiley and Sons Inc., 288.
134834. Marcinko, Richard, and Weisman, John. Designation Gold. 1998. New York: Pocket
1349Books, preface.
135035. Pipkin, D. L. Information Security: Protecting the Global Enterprise. 2000. Upper Saddle
1351River, NJ: Prentice Hall, 256.
135236. Witty, Roberta. “What is Crisis Management?†Gartner Online. 19 September 2001.
1353Accessed 30 April 2007 from www.gartner.com/DisplayDocument?id=340971.
1354Endnotes 227
1355Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1356Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
1357Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1358Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
1359chapter 5
1360Risk Management
1361Once we know our weaknesses, they cease to do us any harm.
1362G.C. (GEORG CHRISTOPH) LICHTENBERG (1742–1799),
1363GERMAN PHYSICIST, PHILOSOPHER
1364Charlie Moody called the meeting to order. The conference room was full of developers,
1365systems analysts, and IT managers, as well as staff and management from Sales and other
1366departments.
1367“All right everyone, let’s get started. Welcome to the kickoff meeting of our new project
1368team, the Sequential Label and Supply Information Security Task Force. We’re here today to
1369talk about our objectives and to review the initial work plan.â€
1370“Why is my department here?†asked the Sales manager. “Isn’t security a problem for the IT
1371department?â€
1372Charlie explained, “Well, we used to think so, but we’ve come to realize that information
1373security is about managing the risk of using information, which involves almost everyone in
1374the company. In order to make our systems more secure, we need the participation of repre-
1375sentatives from all departments.â€
1376Charlie continued, “I hope everyone read the packets we sent out last week describing the
1377legal requirements we face in our industry and the background articles on threats and
1378attacks. Today we’ll begin the process of identifying and classifying all of the information
1379technology risks that face our organization. This includes everything from fires and
1380floods that could disrupt our business to hackers who might try to steal or destroy our data.
1381229
1382Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1383Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
1384Once we identify and classify the risks facing our assets, we can discuss how to reduce or
1385eliminate these risks by establishing controls. Which controls we actually apply will depend
1386on the costs and benefits of each control.â€
1387“Wow, Charlie!†said Amy Windahl from the back of the room. “I’m sure we need to do
1388it—I was hit by the last attack, just as everyone here was—but we have dozens of systems.â€
1389“It’s more like hundreds,†said Charlie. “That’s why we have so many people on this team,
1390and why the team includes members of every department.â€
1391Charlie continued, “Okay, everyone, please open your packets and take out the project plan
1392with the work list showing teams, tasks, and schedules. Any questions before we start
1393reviewing the work plan?â€
1394LEARNING OBJECTIVES:
1395Upon completion of this material, you should be able to:
1396• Define risk management, risk identification, and risk control
1397• Describe how risk is identified and assessed
1398• Assess risk based on probability of occurrence and likely impact
1399• Explain the fundamental aspects of documenting risk via the process of risk assessment
1400• Describe various options for a risk mitigation strategy
1401• Identify the categories that can be used to classify controls
1402• Discuss conceptual frameworks for evaluating risk controls and formulate a cost-benefit analysis
1403Introduction
1404Key Terms
1405avoidance of competitive disadvantage The adoption and implementation of a business
1406model, method, technique, resource, or technology to prevent being outperformed by a
1407competing organization; working to keep pace with the competition through innovation, rather
1408than falling behind.
1409competitive advantage The adoption and implementation of an innovative business model,
1410method, technique, resource, or technology in order to outperform the competition.
1411As an aspiring information security professional, you will play a key role in risk management.
1412The upper management of an organization is responsible for structuring IT and information
1413security functions to defend its information assets—information and data, hardware, software,
1414procedures, networks, and people. The IT community must serve the information technology
1415needs of the entire organization and at the same time leverage the special skills and insights
1416of the information security community. The information security team must lead the way
1417with skill, professionalism, and flexibility as it works with other communities of interest to
1418balance the usefulness and security of the information system.
1419In the early days of information technology, corporations used IT systems mainly to gain a
1420definitive advantage over the competition. Establishing a superior business model, method, or
1421230 Chapter 5
1422Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1423Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
14245
1425technique enabled an organization to provide a product or service that created a competitive
1426advantage. These days, however, all competitors have reached a certain level of technological
1427resilience. IT is now readily available to all organizations that make the investment, allowing
1428them to react quickly to changes in the market. In this highly competitive environment, orga-
1429nizations cannot expect the implementation of new technologies to provide a competitive lead
1430over others in the industry. Instead, the concept of avoidance of competitive disadvantage—
1431working to prevent falling behind the competition—has emerged. Effective IT-enabled organi-
1432zations quickly absorb relevant emerging technologies not just to gain or maintain competitive
1433advantage, but to avoid loss of market share from an inability to maintain the highly respon-
1434sive services required in today’s marketplace.
1435To keep up with the competition, organizations must design and create safe environments in
1436which their business processes and procedures can function. These environments must main-
1437tain confidentiality and privacy and assure the integrity of an organization’s data—objectives
1438that are met by applying the principles of risk management.
1439This chapter explores a variety of risk identification approaches, and follows with a discussion
1440of how risk can be assessed. The chapter finishes with a section on maintaining effective con-
1441trols in the modern organization.
1442An Overview of Risk Management
1443Key Terms
1444risk assessment A determination of the extent to which an organization’s information assets
1445are exposed to risk.
1446risk control The application of controls that reduce the risks to an organization’s information
1447assets to an acceptable level.
1448risk identification The enumeration and documentation of risks to an organization’s
1449information assets.
1450risk management The process of identifying risk, assessing its relative magnitude, and taking
1451steps to reduce it to an acceptable level.
1452In Chapter 1, you learned about the C.I.A. triangle. Each of the three elements in the triangle
1453is an essential part of every IT organization’s ability to sustain long-term competitiveness.
1454When an organization depends on IT-based systems to remain viable, information security
1455and the discipline of risk management must become an integral part of the economic basis
1456for making business decisions. These decisions are based on trade-offs between the costs of
1457applying information system controls and the benefits of using secured, available systems.
1458Risk management involves three major undertakings: risk identification, risk assessment, and
1459risk control. Initially, the organization must identify and understand the risk it faces, espe-
1460cially the risk to information assets. Once identified, risk must be assessed, measured, and
1461evaluated. The key determination is whether the risk an organization faces exceeds its comfort
1462level. If not, the organization is satisfied with the risk management process. Otherwise, the
1463organization needs to do something to reduce risk to an acceptable level. The various compo-
1464nents of risk management and their relationships to each other are shown in Figure 5-1.
1465An Overview of Risk Management 231
1466Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1467Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
1468An observation made over 2,500 years ago by Chinese general Sun Tzu Wu has direct rele-
1469vance to information security today (see Figure 5-2).
1470If you know the enemy and know yourself, you need not fear the result of a hun-
1471dred battles. If you know yourself but not the enemy, for every victory gained
1472you will also suffer a defeat. If you know neither the enemy nor yourself, you
1473will succumb in every battle. 1
1474Consider the similarities between information security and warfare. Information security man-
1475agers and technicians are the defenders of information. The many threats discussed in Chapter 2
1476constantly attack the defenses surrounding information assets. Defenses are built in layers by
1477placing safeguard upon safeguard. The defenders attempt to prevent, protect, detect, and recover
1478from a seemingly endless series of attacks. Moreover, those defenders are legally prohibited from
1479deploying offensive tactics, so the attackers have no need to expend resources on defense. To be
1480victorious, defenders must know themselves and their enemy.
1481For more information on Sun Tzu’s The Art of War, visit http://suntzusaid.com/.
1482‡ Know Yourself
1483You must identify, examine, and understand the current information and systems in your
1484organization. To protect information assets, which were defined earlier in this book as infor-
1485mation and the systems that use, store, and transmit information, you must know what those
1486assets are, where they are, how they add value to the organization, and the vulnerabilities to
1487which they are susceptible. Once you know what you have, you can identify what you are
1488Risk Management
1489Risk
1490Identification
1491Classify, Value, &
1492Prioritize Assets
1493Identify, Inventory, &
1494Categorize Assets
1495Risk Control Risk Assessment
1496Identify & Prioritize
1497Threats
1498Specify Asset
1499Vulnerabilities
1500Evaluate Loss
1501Magnitude
1502Determine Loss
1503Frequency
1504Calculate Risk
1505Assess Risk
1506Acceptability
1507Justify Controls
1508Select Control
1509Strategies
1510Implement, Monitor, &
1511Assess Controls
1512Figure 5-1 Components of risk management
1513© Cengage Learning 2015
1514232 Chapter 5
1515Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1516Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
15175
1518already doing to protect it. Just because a control is in place does not necessarily mean that
1519the asset is protected. Frequently, organizations implement control mechanisms but then
1520neglect the necessary periodic review, revision, and maintenance. The policies, education and
1521training programs, and technologies that protect information must be carefully maintained
1522and administered to ensure that they remain effective.
1523‡ Know the Enemy
1524Having identified your organization’s assets and weaknesses, you move on to Sun Tzu’s second
1525step: Know the enemy. This means identifying, examining, and understanding the threats facing
1526the organization. You must determine which threat aspects most directly affect the security of
1527the organization and its information assets, and then use this information to create a list of
1528threats, each one ranked according to the importance of the information assets that it threatens.
1529‡ The Roles of the Communities of Interest
1530Each community of interest has a role to play in managing the risks that an organization
1531encounters. Because members of the information security community best understand the
1532threats and attacks that introduce risk into the organization, they often take a leadership role
1533in addressing risk to information assets. Management and users, when properly trained and
1534kept aware of the threats the organization faces, play a part in early detection and response.
1535Figure 5-2 Sun Tzu’s The Art of War. Part of the University of California, Riverside Collection
1536Source: Wikimedia Commons. 2
1537An Overview of Risk Management 233
1538Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1539Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
1540Management must also ensure that sufficient money, personnel, and other resources are allo-
1541cated to the information security and information technology groups to meet the organiza-
1542tion’s security needs. Users work with systems and data and are therefore well positioned to
1543understand the value these information assets offer the organization. Users also understand
1544which assets are the most valuable. The information technology community of interest must
1545build secure systems and operate them safely. For example, IT operations ensure good back-
1546ups to control the risk of data loss due to hard drive failure. The IT community can provide
1547both valuation and threat perspectives to management during the risk management process.
1548All communities of interest must work together to address all levels of risk, which range from
1549disasters that can devastate the whole organization to the smallest employee mistakes. The
1550three communities of interest are also responsible for the following:
1551â—
1552Evaluating the risk controls
1553â—
1554Determining which control options are cost effective for the organization
1555â—
1556Acquiring or installing the needed controls
1557â—
1558Ensuring that the controls remain effective
1559All three communities of interest must conduct periodic managerial reviews or audits, with
1560general management usually providing oversight and access to information retained outside
1561the IT department. The first managerial review is of the asset inventory. On a regular basis,
1562management must ensure that the completeness and accuracy of the asset inventory is veri-
1563fied, usually through an IT audit. In addition, IT and information security must review and
1564verify threats and vulnerabilities in the asset inventory, as well as current controls and mitiga-
1565tion strategies. They must also review the cost effectiveness of each control and revisit deci-
1566sions for deploying controls. Furthermore, managers at all levels must regularly verify the
1567ongoing effectiveness of every deployed control. For example, a business manager might
1568assess control procedures by walking through the office before the workday starts, ensuring
1569that all classified information was locked up the night before, that all workstations were
1570shut down, that all users were logged off, and that offices were secured. Managers may fur-
1571ther ensure that no sensitive information is discarded in trash or recycling bins. Such controls
1572are effective ways for managers and employees alike to ensure that no information assets are
1573placed at risk. Other controls include following policy, promoting training and awareness,
1574and employing appropriate technologies.
1575‡ Risk Appetite and Residual Risk
1576Key Terms
1577residual risk The amount of risk that remains to an information asset even after the
1578organization has applied its desired level of controls.
1579risk appetite The amount of risk an organization is willing to accept.
1580Risk appetite defines the quantity and nature of risk that organizations are willing to accept as
1581they evaluate the trade-offs between perfect security and unlimited accessibility. For instance, a
1582financial services company that is regulated by government and conservative by nature may seek
1583to apply every reasonable control and even some invasive controls to protect its information
1584assets. Less regulated organizations may also be conservative by nature, and seek to avoid the
1585234 Chapter 5
1586Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1587Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
15885
1589negative publicity associated with the perceived loss of integrity from an exploited vulnerability.
1590Thus, a firewall vendor may install a set of firewall rules that are far stricter than normal because
1591the negative consequence of being hacked would be catastrophic in the eyes of its customers.
1592Other organizations may take on dangerous risks through ignorance. The reasoned approach
1593to risk is one that balances the expense of controlling vulnerabilities against possible losses if
1594the vulnerabilities are exploited. (Note that expenses in this context are considered both in
1595terms of finance and the usability of information assets.) As mentioned in Chapter 1, James
1596Anderson, former vice president of information security at Emagined Security, Inc., believes
1597that information security in today’s enterprise is a “well-informed sense of assurance that
1598the information risks and controls are in balance.†The key for the organization is to find
1599balance in its decision-making and feasibility analyses, which ensures that its risk appetite is
1600based on experience and facts instead of ignorance or wishful thinking.
1601Residual Risk When vulnerabilities have been controlled as much as possible, any
1602remaining risk that has not been removed, shifted, or planned for is called residual risk. To
1603express the concept another way, “residual risk is a combined function of (1) a threat less
1604the effect of threat-reducing safeguards, (2) a vulnerability less the effect of vulnerability-
1605reducing safeguards, and (3) an asset less the effect of asset value-reducing safeguards.†3
1606Figure 5-3 illustrates how residual risk remains after safeguards are implemented.
1607The significance of residual risk must be judged within the context of the organization.
1608Although it might seem counterintuitive, the goal of information security is not to bring
1609residual risk to zero; it is to bring residual risk into line with an organization’s comfort
1610zone or risk appetite. If decision makers have been informed of uncontrolled risks and the
1611Residual risk — the risk that
1612has not been covered by
1613one of the safeguards
1614Amount of vulnerability
1615reduced by safeguards
1616Amount of asset value
1617protected by safeguards
1618Amount of threat
1619reduced by safeguards
1620Risk Facing an Information Asset’s Value
1621Total Risk Facing the Asset
1622Figure 5-3 Residual risk
1623© Cengage Learning 2015
1624An Overview of Risk Management 235
1625Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1626Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
1627proper authorities within the communities of interest decide to leave residual risk in place,
1628the information security program has accomplished its primary goal.
1629Finally, when management requires details about a specific risk to the organization, risk
1630assessment may be documented in a topic-specific report. These reports are usually prepared
1631at the direction of senior management to focus on a narrow area of operational risk to an
1632information system. For example, an emergent vulnerability might be reported to manage-
1633ment, which then asks for a specific risk assessment. For a more complete treatment of doc-
1634umenting the results of risk management activities, see Chapter 12.
1635For a list of risk management methods and tools, visit the ISO 27k FAQ site at http://www
1636.iso27001security.com/html/risk_mgmt.html.
1637Risk Identification
1638A risk management strategy requires that information security professionals know their orga-
1639nizations’ information assets—that is, how to identify, classify, and prioritize them. Once the
1640organizational assets have been identified, a threat assessment process is used to identify and
1641quantify the risks facing each asset.
1642The components of risk identification are shown in Figure 5-4.
1643‡ Planning and Organizing the Process
1644As with any major undertaking in information security, the first step in risk identification is
1645to follow your project management principles. You begin by organizing a team, which typi-
1646cally consists of representatives from all affected groups. Because risk can exist everywhere
1647in the organization, representatives will come from every department and will include users,
1648managers, IT groups, and information security groups. The process must then be planned,
1649with periodic deliverables, reviews, and presentations to management. Once the project is
1650ready to begin, the team can organize a meeting like the one Charlie is conducting in the
1651opening case. Tasks are laid out, assignments are made, and timetables are discussed. Only
1652then is the organization ready to begin the next step—identifying and categorizing assets.
1653Plan & organize
1654the process
1655Identify, inventory,
1656& categorize assets
1657Classify, value, &
1658prioritize assets
1659Identify & prioritize
1660threats
1661Specify asset
1662vulnerabilities
1663Figure 5-4 Components of risk identification
1664© Cengage Learning 2015
1665236 Chapter 5
1666Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1667Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
16685
1669‡ Identifying, Inventorying, and Categorizing Assets
1670This iterative process begins with the identification and inventory of assets, including all ele-
1671ments of an organization’s system, such as people, procedures, data and information, soft-
1672ware, hardware, and networking elements (see Table 5-1). Then, you categorize the assets,
1673adding details as you dig deeper into the analysis. The objective of this process is to establish
1674the relative priority of assets to the success of the organization.
1675People, Procedures, and Data Asset Identification Identifying assets for human
1676resources, documentation, and data is more difficult than identifying hardware and software
1677assets. People with knowledge, experience, and judgment should be assigned the task. As
1678assets for people, procedures, and data are identified, they should be recorded using a reli-
1679able data-handling process. Regardless of the record keeping mechanism you use, make
1680sure it has the flexibility to allow specification of attributes for a particular type of asset.
1681Some attributes are unique to a class of elements. When deciding which information assets
1682to track, consider the following asset attributes:
1683â—
1684People: Position name, number, or ID (avoid using people’s names and stick to identi-
1685fying positions, roles, or functions); supervisor; security clearance level; special skills
1686â—
1687Procedures: Description; intended purpose; relationship to software, hardware, and
1688networking elements; storage location for reference; storage location for update
1689â—
1690Data: Classification; owner, creator, and manager; size of data structure; data struc-
1691ture used (sequential or relational); online or offline; location; backup procedures
1692employed. As you develop the data-tracking process, consider carefully how much data
1693Traditional system
1694components SecSDLC components Risk management system components
1695People Employees Trusted employees
1696Other staff
1697Nonemployees People at trusted organizations
1698Strangers and visitors
1699Procedures Procedures IT and business standard procedures
1700IT and business-sensitive procedures
1701Data Information Transmission
1702Processing
1703Storage
1704Software Software Applications
1705Operating systems
1706Security components
1707Hardware System devices and peripherals Systems and peripherals
1708Security devices
1709Networking components Intranet components
1710Internet or DMZ components
1711Table 5-1 Categorizing the Components of an Information System
1712© Cengage Learning 2015
1713Risk Identification 237
1714Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1715Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
1716should be tracked and for which specific assets. Most large organizations find that
1717they can effectively track only a few valuable facts about the most critical devices. For
1718instance, a company may only track the IP address, server name, and device type for
1719its mission-critical servers. The company may forego the tracking of additional details
1720on all devices and completely forego the tracking of desktop or laptop systems.
1721Hardware, Software, and Network Asset Identification Which attributes of
1722hardware, software, and network assets should be tracked? It depends on the needs of the
1723organization and its risk management efforts, as well as the preferences and needs of the
1724information security and information technology communities. You may want to consider
1725including the following asset attributes:
1726â—
1727Name: Use the most common device or program name. Organizations may have sev-
1728eral names for the same product. For example, a software product might have a nick-
1729name within the company while it is in development, as well as a formal name used by
1730marketing staff and vendors. Make sure that the names you choose are meaningful to
1731all the groups that use the information. You should adopt naming standards that do
1732not convey information to potential system attackers. For instance, a server named
1733CASH1 or HQ_FINANCE may entice attackers to take a shortcut to that system.
1734â—
1735IP address: This can be a useful identifier for network devices and servers, but it does not usu-
1736ally apply to software. You can, however, use a relational database to track software instances
1737on specific servers or networking devices. Also, many organizations use the Dynamic Host
1738Configuration Protocol (DHCP) within TCP/IP that reassigns IP numbers to devices as
1739needed, which creates a problem for using IP numbers as part of the asset identification pro-
1740cess. IP address use in inventory is usually limited to devices that use static IP addresses.
1741â—
1742Media access control (MAC) address: MAC addresses are sometimes called electronic
1743serial numbers or hardware addresses. As part of the TCP/IP standard, all network
1744interface hardware devices have a unique number. The MAC address number is used
1745by the network operating system to identify a specific network device. It is used by the
1746client’s network software to recognize traffic that it must process. In most settings,
1747MAC addresses can be a useful way to track connectivity. However, they can be
1748spoofed by some hardware and software combinations.
1749â—
1750Element type: For hardware, you can develop a list of element types, such as servers, desk-
1751tops, networking devices, or test equipment. The list can have any degree of detail you
1752require. For software elements, you may develop a list of types that includes operating sys-
1753tems, custom applications by type (accounting, HR, or payroll, for example), packaged
1754applications, and specialty applications, such as firewall programs. The needs of the orga-
1755nization determine the degree of specificity. For instance, types may need to be recorded at
1756two or more levels of specificity. If so, record one attribute that classifies the asset at a high
1757level and then add attributes for more detail. For example, one server might be listed as:
1758â—
1759DeviceClass ¼ S (server)
1760â—
1761DeviceOS ¼ W2K (Windows 2000)
1762â—
1763DeviceCapacity ¼ AS (advanced server)
1764â—
1765Serial number: For hardware devices, the serial number can uniquely identify a specific
1766device. Some software vendors also assign a software serial number to each instance of
1767the program licensed by the organization.
1768238 Chapter 5
1769Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1770Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
17715
1772â—
1773Manufacturer name: Record the manufacturer of the device or software component.
1774This can be useful when responding to incidents that involve the device or when cer-
1775tain manufacturers announce specific vulnerabilities.
1776â—
1777Manufacturer’s model number or part number: Record the model or part number of
1778the element. This exact record of the element can be very useful in later analysis of
1779vulnerabilities, because some vulnerability instances apply only to specific models of
1780certain devices and software components.
1781â—
1782Software version, update revision, or FCO number: Whenever possible, document
1783the specific software or firmware revision number and, for hardware devices, the
1784current field change order (FCO) number. An FCO is an authorization issued by an
1785organization for the repair, modification, or update of a piece of equipment. The
1786equipment is not returned to the manufacturer, but is usually repaired at the custo-
1787mer’s location, often by a third party. Documenting the revision number and FCO is
1788particularly important for networking devices that function mainly via the software
1789running on them. For example, firewall devices often have three versions: an oper-
1790ating system (OS) version, a software version, and a basic input/output system
1791(BIOS) firmware version. Depending on your needs, you may have to track all three
1792version numbers.
1793â—
1794Physical location: Note the element’s physical location. This information may not
1795apply to software elements, but some organizations have license terms that specify
1796where software can be used. This information falls under asset inventory, which can be
1797performed once the identification process is started.
1798â—
1799Logical location: Note where the element can be found on the organization’s network.
1800The logical location is most useful for networking devices and indicates the logical
1801network where the device is connected. Again, this information is an inventory item
1802that is important to track for identification purposes.
1803â—
1804Controlling entity: Identify which organizational unit controls the element. Sometimes
1805a remote location’s onsite staff controls a networking device, and sometimes the cen-
1806tral network team controls other devices of the same make and model. You should try
1807to specify which group or unit controls each specific element because that group may
1808want a voice in determining how much risk the device can tolerate and how much
1809expense they can sustain to add controls.
1810For a listing of software that can assist in the asset management inventory, visit http://en
1811.wikipedia.org and search on “Open source configuration management software.†You can also
1812go to www.techrepublic.com and search on “Top apps for managing inventory.â€
1813Asset Inventory Creating an inventory of information assets is a critical function of
1814understanding what the organization is protecting. Unless the information assets are identi-
1815fied and inventoried, they cannot be effectively protected. The inventory process is critical
1816in determining where information is located; most commonly it is in storage. Not all infor-
1817mation is stored in databases. A great deal of an organization’s information is stored in
1818hard copy—in filing cabinets, desks, and in employee hands and briefcases. Even more
1819information is stored on portable hard drives, flash drives, laptops, smartphones, and other
1820mobile devices. While it may be impossible to completely control where information is
1821Risk Identification 239
1822Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1823Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
1824located, policy and training programs can assist in informing employees where information
1825should and should not be stored.
1826The inventory process involves formalizing the identification process in some form of orga-
1827nizational tool. At this point in the process, simple spreadsheets and database tools can pro-
1828vide effective record keeping. The inventory information can be updated later with classifica-
1829tion and valuation data. Automated tools can sometimes identify the system elements that
1830make up hardware, software, and network components. For example, many organizations
1831use automated asset inventory systems. The inventory listing is usually available in a data-
1832base, or it can be exported to a database for custom information about security assets.
1833Once stored, the inventory listing must be kept current, often by means of a tool that peri-
1834odically refreshes the data. When you move to the later steps of risk management, which
1835involve calculations of loss and projections of costs, the case for using automated risk man-
1836agement tools to track information assets becomes stronger.
1837Asset Categorization Table 5-1, shown earlier, compares the categorizations of a
1838standard information system (people, procedures, data and information, software, and hard-
1839ware) with those in an enhanced version that incorporates risk management and the
1840SecSDLC approach. As you can see, the SecSDLC and risk management categorizations
1841introduce several new subdivisions:
1842â—
1843People comprise employees and nonemployees. There are two subcategories of
1844employees: those who hold trusted roles and have correspondingly greater authority
1845and accountability, and other staff who have assignments without special privileges.
1846Nonemployees include contractors and consultants, members of other trusted organi-
1847zations, and strangers.
1848â—
1849Procedures essentially belong in one of two categories: procedures that do not
1850expose knowledge a potential attacker might find useful, and sensitive procedures
1851that could allow an adversary to gain an advantage or craft an attack against the
1852organization’s assets. These business-sensitive procedures may introduce risk to the
1853organization if they are revealed to unauthorized people. For example, BellSouth
1854discovered several years ago that someone had stolen the documentation for its
1855E911 system. 4 This documentation revealed the inner workings of a critical phone
1856system.
1857â—
1858Data components account for the management of information in all its states: trans-
1859mission, processing, and storage. These expanded categories solve the problem posed
1860by the term data, which is usually associated with databases and not the full range of
1861modalities of data and information used by a modern organization.
1862â—
1863Software components are assigned to one of three categories: applications, operating
1864systems, or security components. Security components can be applications or operating
1865systems, but they are categorized as part of the information security control environ-
1866ment and must be protected more thoroughly than other system components.
1867â—
1868Hardware is assigned to one of two categories: the usual system devices and their per-
1869ipherals, and devices that are part of information security control systems. The latter
1870must be protected more thoroughly than the former because networking subsystems
1871are often the focal point of attacks against the system; they should be considered spe-
1872cial cases rather than combined with general hardware and software components.
1873240 Chapter 5
1874Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1875Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
18765
1877‡ Classifying, Valuing, and Prioritizing Information Assets
1878Key Term
1879data classification scheme A formal access control methodology used to assign a level of
1880confidentiality to an information asset and thus restrict the number of people who can access it.
1881Most organizations further subdivide the categories listed in Table 5-1. For example, the
1882Hardware category can be subdivided into servers, networking devices (routers, hubs,
1883switches), protection devices (firewalls, proxies), and cabling. Each of the other categories can
1884be similarly subdivided as needed by the organization. You should also include a dimension to
1885represent the sensitivity and security priority of the data and the devices that store, transmit,
1886and process the data—that is, a data classification scheme. Examples of data classification
1887categories are confidential, internal, and public. A data classification scheme generally requires
1888a corresponding structure for personnel security clearance, which determines the level of infor-
1889mation that employees are authorized to view based on what they need to know.
1890Any classification method must be specific enough to enable determination of priority levels,
1891because the next step in risk assessment is to rank the components. It is also important that
1892the categories be comprehensive and mutually exclusive. Comprehensive means that all infor-
1893mation assets must fit in the list somewhere, and mutually exclusive means that an informa-
1894tion asset should fit in only one category. For example, suppose an organization has a public
1895key infrastructure certificate authority, which is a software application that provides crypto-
1896graphic key management services. Using a purely technical standard, an analysis team could
1897categorize the certificate authority as software in the asset list of Table 5-1. Then, within the
1898software category, the certificate authority could be listed either as an application or a security
1899component. However, a certificate authority should actually be categorized as a software secu-
1900rity component because it is part of the security infrastructure and must be protected carefully.
1901Data Classification and Management Corporate and government organizations
1902use a variety of classification schemes. Many corporations use a data classification scheme
1903to help secure the confidentiality and integrity of information.
1904A simplified information classification scheme would have three categories: confidential, inter-
1905nal, and external. Information owners must classify the information assets for which they are
1906responsible. At least once a year, information owners must review their classifications to ensure
1907that the information is still classified correctly and the appropriate access controls are in place.
1908The information classifications are as follows:
1909â—
1910Confidential: Used for the most sensitive corporate information that must be tightly
1911controlled, even within the company. Access to information with this classification is
1912strictly on a need-to-know basis or as required by the terms of a contract. Information
1913with this classification may also be referred to as “sensitive†or “proprietary.â€
1914â—
1915Internal: Used for all internal information that does not meet the criteria for the confi-
1916dential category. Internal information is to be viewed only by corporate employees,
1917authorized contractors, and other third parties.
1918â—
1919External: All information that has been approved by management for public release.
1920Risk Identification 241
1921Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1922Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
1923As you might expect, the U.S. Classified National Security Information (NSI) system uses more
1924complex categorization than most corporations. The U.S. government and the Department of
1925Defense (DoD), with all of its military branches, are perhaps the best-known users of data classi-
1926fication schemes. To maintain protection of the confidentiality of information, the government
1927and the DoD have invested heavily in INFOSEC (information security), OPSEC (operations
1928security), and COMSEC (communications security). In fact, many developments in data com-
1929munications and information security are the result of government-sponsored research and
1930development. For most NSI, which is vital to the security of the nation, the government uses a
1931three-level classification scheme: Top Secret, Secret and Confidential.
1932â—
1933“‘Top Secret’ shall be applied to information, the unauthorized disclosure of which
1934reasonably could be expected to cause exceptionally grave damage to the national
1935security that the original classification authority is able to identify or describe.
1936â—
1937‘Secret’ shall be applied to information, the unauthorized disclosure of which reason-
1938ably could be expected to cause serious damage to the national security that the origi-
1939nal classification authority is able to identify or describe.
1940â—
1941‘Confidential’ shall be applied to information, the unauthorized disclosure of which
1942reasonably could be expected to cause damage to the national security that the original
1943classification authority is able to identify or describe.†5
1944This classification system comes with the general expectation of “crib-to-grave†protection,
1945meaning that all people entrusted with classified information are expected to retain this
1946level of confidence for their lifetimes, or at least until the information is officially unclassi-
1947fied. The government also has some specialty classification ratings, such as Personnel Infor-
1948mation and Evaluation Reports, to protect related areas of information.
1949Federal agencies such as the NSA, FBI, and CIA also use specialty classification schemes, like Com-
1950partmented Information (in other words, Named Projects). Compartmented information represents
1951clearance levels based on an extreme need-to-know basis. When an operation, project, or set of clas-
1952sified data is created, the project is assigned a code name, such as Operation Phoenix. Next, a list of
1953authorized people is created and assigned to the Compartmented category, and the list is maintained
1954to restrict access to this category of material. The only way a person outside the original list can
1955access this information is to be authorized by a top-level official to be “read in†to the information.
1956For non-NSI material, other classification schemes are employed. Each of these is defined below.
1957â—
1958Sensitive but Unclassified data (SBU): Information that if lost, misused, accessed with-
1959out authorization, or modified might adversely affect U.S. interests, the conduct of
1960DoD programs, or the privacy of DoD personnel. Common SBU categories include
1961Restricted, For Official Use Only, Not for Public Release, and For Internal Use Only. 6
1962â—
1963Unclassified data: Information that can generally be distributed to the public without
1964any threat to U.S. interests.
1965In the United Kingdom, the Government Protective Marketing Scheme is a five-layer model
1966that incorporates categories similar to those in the combined NSI and non-NSI U.S. govern-
1967ment models. This scheme has recently been revised to a much simpler model known as the
1968Government Security Classification Policy, with Confidential, Restricted (SBU), and Unclas-
1969sified levels merged into a single Official category. The result is a simpler, three-layer model
1970with Top-Secret, Secret, and Official categories for all U.K. government information.
1971242 Chapter 5
1972Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1973Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
19745
1975Most organizations do not need the detailed level of classification used by the government or DoD
1976agencies. However, a simple scheme that uses the Confidential, Internal, and External classifica-
1977tions discussed earlier can allow an organization to protect sensitive information such as market-
1978ing or research data, personnel data, customer data, and general internal communications.
1979For a listing of federal statutes, regulations, and directives for data classification programs, visit
1980http://energy.gov/hss/statutes-regulations-and-directives-classification-program.
1981Security Clearances
1982Key Term
1983security clearance A component of a data classification scheme that assigns a status level to
1984employees to designate the maximum level of classified data they may access.
1985Corresponding to the data classification scheme is the personnel security clearance structure.
1986In organizations that require security clearances, all users of data must be assigned authoriza-
1987tion levels that indicate what types of classified data they are authorized to view. This struc-
1988ture is usually accomplished by assigning each employee to a named role, such as data entry
1989clerk, development programmer, information security analyst, or even CIO. Most organiza-
1990tions have a set of roles and associated security clearances. Overriding an employee’s security
1991clearance requires that the employee meet the need-to-know standard described earlier. In
1992fact, this standard should be met regardless of an employee’s security clearance. This extra
1993level of protection ensures that confidentiality of information is properly maintained.
1994Management of Classified Data
1995Key Terms
1996clean desk policy An organizational policy that specifies employees must inspect their work
1997areas and ensure that all classified information, documents, and materials are secured at the end
1998of every work day.
1999dumpster diving An information attack that involves searching through a target organization’s
2000trash and recycling bins for sensitive information.
2001Management of classified data includes its storage, distribution, transportation, and destruction. All
2002information that is not unclassified or public must be clearly marked as such, as shown in the gov-
2003ernment examples in Figure 5-5. The government also uses color-coordinated cover sheets to pro-
2004tect classified information from the casual observer, with Orange (Top Secret), Red (Secret), and
2005Blue (Confidential) borders and fonts. In addition, each classified document should contain the
2006appropriate designation at the top and bottom ofeach page. When classified data is stored, it must
2007be available only to authorized personnel. This storage usually requires locking file cabinets, safes,
2008or other protective devices for hard copies and systems. When a person carries classified informa-
2009tion outside the organization, it should be inconspicuous, as in a locked briefcase or portfolio.
2010One important control policy that is often difficult to enforce is the clean desk policy, which
2011is designed to ensure that all classified information is secured at the end of every day. When
2012copies of classified information are no longer valuable or excess copies exist, proper care
2013should be taken to destroy them, usually after double signature verification. Documents can
2014be destroyed by means of shredding, burning, or transferring them to a service that offers
2015Risk Identification 243
2016Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2017Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
2018authorized document destruction. As you can see in Figure 5-6, this type of policy does not
2019mean the office itself is clean, but only that all classified data has been secured. It is important
2020to enforce policies to ensure that no classified information is discarded in trash or recycling
2021areas. Some people search trash and recycling bins—a practice known as dumpster diving—to
2022retrieve information that could embarrass a company or compromise information security.
2023Information Asset Valuation
2024Key Term
2025asset valuation The process of assigning financial value or worth to each information asset.
2026Figure 5-5 Government data classification cover sheets
2027© Cengage Learning 2015
2028244 Chapter 5
2029Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2030Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
20315
2032One of the toughest tasks of information security in general and risk management in
2033particular is information asset valuation. While most organizations have a general under-
2034standing of the relative worth of their information assets, it is much more difficult to
2035place a specific financial value on an information asset. For example, what’s the worth
2036of the chemical formula for a drug that could cure cancer? What about an organization’s
2037strategic plan for the next five years? The Sales department’s marketing plan for next
2038quarter? As a result, many organizations use categorical values to provide ranges of
2039values for assets, or they use other qualitative measures, as discussed later in the section
2040on qualitative versus quantitative assessments.
2041To assist in the process of assigning values to information assets for risk assessment
2042purposes, you can pose several questions and collect your answers on a worksheet
2043(see Figure 5-7) for later analysis. Before beginning the inventory process, the organiza-
2044tion should determine which criteria can best establish the value of the information
2045assets.
2046Among the criteria to be considered are:
2047â—
2048Which information asset is most critical to the organization’s success? When deter-
2049mining the relative importance of each asset, refer to the organization’s mission
2050statement or statement of objectives to determine which elements are essential,
2051which are supportive, and which are merely adjuncts. For example, a manufacturing
2052company that makes aircraft engines might find that its process control systems for
2053machine tools on the assembly line are of the first order of importance. Although
2054Figure 5-6 Clean desk policy violation?
2055© Cengage Learning 2015
2056Risk Identification 245
2057Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2058Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
2059shipping and receiving data-entry consoles are important, they are less critical
2060because alternatives are available or can be easily arranged. Another example is an
2061online organization such as Amazon.com. The Web servers that advertise Amazon’s
2062products and receive orders 24 hours a day are critical to the success of the busi-
2063ness, whereas the desktop systems used by the customer service department to
2064answer e-mails are less important.
2065â—
2066Which information asset generates the most revenue? You can also determine which
2067information assets are critical by evaluating how much of the organization’s revenue
2068depends on a particular asset. For nonprofit organizations, you can determine which
2069assets are most critical to service delivery. In some organizations, different systems are
2070in place for each line of business or service offering.
2071â—
2072Which of these assets plays the biggest role in generating revenue or delivering ser-
2073vices? Which information asset generates the most profitability? Organizations
2074should evaluate how much of the organization’s profitability depends on a particu-
2075lar asset. For instance, at Amazon.com, some servers support sales operations,
2076others support the auction process, and others support the customer review data-
2077base. Which of these servers contributes most to the profitability of the business?
2078Although important, the customer review database server does not directly add to
2079System Name:
2080Date Evaluated:
2081Evaluated By:
2082Information assets Data classification Impact to profitability
2083Information Transmitted:
2084EDI Document Set 1—Logistics BOL
2085to outsourcer (outbound)
2086EDI Document Set 2—Supplier orders
2087(outbound)
2088EDI Document Set 2—Supplier
2089fulfillment advice (inbound)
2090Customer order via SSL (inbound)
2091Customer service request via e-mail
2092(inbound)
2093DMZ Assets:
2094Edge router
2095Web server #1—home page and core
2096site
2097Web server #2—Application server
2098Confidential
2099Confidential
2100Confidential
2101Confidential
2102Private
2103Public
2104Public
2105Private
2106High
2107High
2108Medium
2109Critical
2110Medium
2111Critical
2112Critical
2113Critical
2114Notes: BOL: Bill of Lading
2115DMZ: Demilitarized Zone
2116EDI: Electronic Data Interchange
2117SSL: Secure Sockets Layer
2118SLS E-Commerce
2119February 2012
2120D. Jones
2121Figure 5-7 Sample inventory worksheet
2122© Cengage Learning 2015
2123246 Chapter 5
2124Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2125Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
21265
2127profitability, at least not to the same degree as the sales operations servers. Note
2128that some services may have large revenue values, but are operating on such thin
2129margins that they do not generate a profit. Nonprofit organizations can determine
2130what percentage of their clientele receives services from the information asset being
2131evaluated.
2132â—
2133Which information asset would be the most expensive to replace? Sometimes an
2134information asset acquires special value because it is unique. For example, if an
2135enterprise still uses a Model 129 keypunch machine to create special punch-card
2136entries for a critical batch run, that machine may be worth more than its cost
2137because spare parts or service providers may longer be available for it. Another
2138example is a specialty device with a long acquisition lead time because of
2139manufacturing or transportation requirements. After the organization has identified
2140the unique value of this device, it can address ways to control the risk of losing
2141access to the unique asset. An organization can also control the risk of loss for such
2142an asset by buying and storing a backup device.
2143â—
2144Which information asset would be the most expensive to protect? In this case, you
2145are determining the cost of providing controls. Some assets are difficult to protect by
2146their nature. Finding a complete answer to this question may have to be delayed
2147beyond the risk identification phase because the costs of controls cannot be com-
2148puted until the controls are identified later in the risk management process. However,
2149information about the difficulty of establishing controls should be collected in the
2150identification phase.
2151â—
2152Which information asset would most expose the company to liability or embarrass-
2153ment if revealed? Almost every organization is aware of its local, national, and inter-
2154national image. For many organizations, the compromise of certain assets could prove
2155especially damaging to this image. The image of Microsoft, for example, was tarnished
2156when one of its employees became a victim of the QAZ Trojan and the (then) latest
2157version of Microsoft Office was stolen. 7
2158When it is necessary to calculate, estimate, or derive values for information assets, you
2159might give consideration to the following:
2160â—
2161Value retained from the cost of creating the information asset: Information is created
2162or acquired at some cost to the organization. This cost can be calculated or estimated.
2163One category of this cost is software development, and another is data collection and
2164processing. Many organizations have developed extensive accounting practices to cap-
2165ture the costs associated with the collection and processing of data as well as the costs
2166of software development and maintenance.
2167â—
2168Value retained from past maintenance of the information asset: It is estimated that for
2169every dollar spent developing an application or acquiring and processing data, many
2170more dollars are spent on maintenance over the useful life of the data or software.
2171Such costs can be estimated by quantifying the human resources used to continually
2172update, support, modify, and service the applications and systems associated with a
2173particular information asset.
2174â—
2175Value implied by the cost of replacing the information: Another important cost associ-
2176ated with the loss or damage to information is the cost of replacing or restoring it.
2177This includes the human resource time needed to reconstruct, restore, or regenerate the
2178Risk Identification 247
2179Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2180Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
2181information from backups, independent transaction logs, or even hard copies of
2182data sources. Most organizations rely on routine media backups to protect their
2183information, but lost real-time information may not be recoverable from a tape
2184backup unless journaling capabilities are built into the system. To replace informa-
2185tion in the system, it may have to be reconstructed, and the data might have to be
2186reentered into the system and validated. This restoration can take longer than it
2187took to create the data.
2188â—
2189Value from providing the information: Separate from the cost of developing or main-
2190taining information is the cost of providing it to the users who need it. This cost
2191includes the value associated with delivery of information via databases, networks, and
2192hardware and software systems. It also includes the cost of the infrastructure necessary
2193to provide access and control of the information.
2194â—
2195Value incurred from the cost of protecting the information: This value is a recursive
2196dilemma. In other words, the value of an asset is based in part on the cost of protect-
2197ing it, while the amount of money spent to protect an asset is based in part on its
2198value. While this is a seemingly unsolvable circle of logic, it is possible to estimate the
2199value of protection for an information asset to better understand the value associated
2200with its potential loss. The values listed previously are easier to calculate. This value
2201and the following values are more likely to be estimates of cost.
2202â—
2203Value to owners: How much is your Social Security number or telephone number
2204worth to you? Placing a value on information can be a daunting task. For example, a
2205market researcher might collect data from a company’s sales figures and determine
2206that strong market potential exists for a new product within a certain age group and
2207demographic group. The cost associated with the creation of this new information
2208may be small, but it could be worth millions if it successfully defines a new market.
2209The value of information to an organization, or how much of the organization’s
2210bottom line can be directly attributed to the information, may be impossible to esti-
2211mate. However, it is vital to understand the overall cost of protecting this informa-
2212tion in order to understand its value. Again, estimating value may be the only
2213method.
2214â—
2215Value of intellectual property: Related to the value of information is the specific con-
2216sideration of the value of intellectual property. The value of a new product or service
2217to a customer may be unknowable. How much would a cancer patient pay for a cure?
2218How much would a shopper pay for a new type of cheese? What is the value of an
2219advertising jingle? All of these items could represent the intellectual property of an
2220organization, yet their valuation is complex. A related but separate consideration is
2221intellectual property known as trade secrets. These assets are so valuable that they are
2222the primary assets of some organizations.
2223â—
2224Value to adversaries: How much would it be worth to an organization to know what
2225the competition is doing? Many organizations have departments that deal in competi-
2226tive intelligence and that assess and estimate the activities of their competition. Even
2227organizations that are traditionally nonprofit can benefit from understanding develop-
2228ments in political, business, and competing organizations.
2229Other company-specific criteria might add value to the asset valuation process. They should
2230be identified, documented, and added to the process. To finalize this step of information
2231248 Chapter 5
2232Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2233Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
22345
2235asset identification, each organization should assign a weight to each asset based on the
2236answers to the chosen questions.
2237For another perspective on information asset valuation, read ISO 27001 Implementer’s Forum:
2238Guideline for Information Asset Valuation, which is available from www.iso27001security.com/
2239ISO27k_Guideline_on_information_asset_valuation.pdf.
2240Information Asset Prioritization Once the inventory and value assessment are
2241complete, you can prioritize each asset using a straightforward process known as weighted
2242factor analysis, as shown in Table 5-2. In this process, each information asset is assigned
2243scores for a set of assigned critical factors. In the example shown in Table 5-2, a score is
2244assessed for each asset according to three assigned critical factors. In the example, the scores
2245range from 0.1 to 1.0, which is the range of values recommended in NIST SP 800-30, Risk
2246Management for Information Technology Systems. The document is published by the
2247National Institute of Standards and Technology. In addition, each critical factor is assigned
2248a weight ranging from 1 to 100 to show the criterion’s assigned importance for the
2249organization.
2250A quick review of Table 5-2 shows that the customer order via SSL (inbound) data flow is
2251the most important asset on this worksheet, with a weighted score of 100. EDI Document
2252Set 2—Supplier fulfillment advice (inbound) is the least critical asset, with a score of 41.
2253‡ Identifying and Prioritizing Threats
2254Key Term
2255threat assessment An evaluation of the threats to information assets, including a
2256determination of their potential to endanger the organization.
2257Information asset Criterion 1: Impact
2258to revenue
2259Criterion 2: Impact
2260to profitability
2261Criterion 3: Impact
2262to public image
2263Weighted
2264score
2265Criteria weights must total 100 30 40 30
2266EDI Document Set 1—Logistics
2267BOL to outsourcer (outbound)
22680.8 0.9 0.5 75
2269EDI Document Set 2—Supplier
2270orders (outbound)
22710.8 0.9 0.6 78
2272EDI Document Set 2—Supplier
2273fulfillment advice (inbound)
22740.4 0.5 0.3 41
2275Customer order via SSL (inbound) 1.0 1.0 1.0 100
2276Customer service request via
2277e-mail (inbound)
22780.4 0.4 0.9 55
2279Table 5-2 Example of a Weighted Factor Analysis Worksheet
2280Note: In the table, EDI stands for electronic data interchange, BOL stands for bill of lading, and SSL is Secure Sockets Layer.
2281© Cengage Learning 2015
2282Risk Identification 249
2283Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2284Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
2285After an organization identifies and performs the preliminary classification of its informa-
2286tion assets, the analysis phase next examines threats to the organization. As you discov-
2287ered in Chapter 2, a wide variety of threats face an organization, its information, and its
2288information systems. The realistic threats must be investigated further, while the unimpor-
2289tant threats are set aside. If you assume that every threat can and will attack every infor-
2290mation asset, the project’s scope quickly becomes so complex that it overwhelms your
2291ability to plan.
2292The threats to information security that you learned about in Chapter 2 are shown in
2293Table 5-3.
2294Each threat in Table 5-3 must be examined to assess its potential to endanger the organiza-
2295tion. This examination is known as a threat assessment. You can begin a threat assessment
2296by answering a few basic questions, as follows:
2297â—
2298Which threats present a danger to an organization’s assets in the given environment?
2299Not all threats have the potential to affect every organization. While an entire cate-
2300gory of threats probably cannot be eliminated, such elimination speeds up later steps
2301of the process. (Read the Offline feature entitled Survey of Industry to see which
2302threats leading CIOs identified for their organizations.) Once an organization has
2303determined which threats apply, the security team brainstorms for particular exam-
2304ples of threats within each category. These specific threats are examined to determine
2305whether they apply to the organization. For example, a company with offices on the
2306twelfth floor of a high-rise in Denver, Colorado, is not subject to flooding. Similarly,
2307a firm with an office in Oklahoma City should not be concerned with landslides.
2308Using this methodology, specific threats may be eliminated because of very low
2309probability.