Information Security Risk Management Study Notes

INFORMATION SECURITY RISK MANAGEMENT

Introduction

Overview
  • Content sourced from Security in Computing, Fifth Edition by Charles P. Pfleeger, et al.

  • ISBN: 9780134085043. Copyright, Pearson Education, Inc. 2015.

Chapter 1

Asset Value
  • The value of an asset is subjective and varies based on the owner’s or user’s perspective.

  • It may not always correlate with monetary cost.

    • Example: Certain computer data can be priceless and irreplaceable, such as an old family picture.

    • Timing affects asset value.

      • Example: The value of a product line plan is high before the product is released but drops significantly post-launch.

CIA TRIAD

Goals of Information Security
  • The CIA triad consists of three primary objectives in information security measures:

    • Confidentiality: Protection against unauthorized access to sensitive information.

    • Integrity: Assurance that information remains accurate and reliable.

    • Availability: Ensuring authorized users have reliable access to information when needed.

Defense in Depth

  • Concept: A multi-layered approach to security where multiple security devices are employed in a series to create overlapping protection. This strategy includes:

    • Prevention: Blocking potential attacks.

    • Detection: Identifying attacks as they occur or post-facto.

    • Response: Mechanisms for recovery from attacks.

  • The strategy compensates for weaknesses in any single security layer by reinforcing through multiple layers.

Risk Mitigation Strategies

Countermeasures
  • A countermeasure is defined as an action taken to handle a security attack. They can be categorized as:

    • Preventative measures: Aim to stop a type of attack.

    • Detective measures: Identify attacks when prevention fails.

    • Recovery measures: Allow for a return to normal status after an attack.

Methods of Harm Response
  • Prevent: Block an incoming attack or close security gaps.

  • Deter: Make it more difficult for attacks to succeed.

  • Deflect: Redirect attacks toward less secure systems.

  • Mitigate: Reduce potential damage from an attack.

  • Detect: Recognize attacks during or after occurrence.

  • Recover: Restore systems and data post-attack.

User Authentication

Definition
  • Authentication: The act of confirming a user's identity.

    • Distinguished from Identification, which is simply stating an identity.

    • Requires reliable confirmation of identities, unlike public identifiers such as usernames.

Identification vs. Authentication
  • Identities (e.g., usernames) are public and less protected (e.g., bank account numbers displayed on checks).

  • Authentication should be robust and protected.

Multifactor Authentication
  • Multifactor authentication: Involves multiple methods from a defined list for user verification.

    • Strength increases with the number of authentication factors used.

Password-Based Authentication

Overview
  • Widely recognized as a primary defense against unauthorized access.

  • Authentication involves comparing a user-provided password with a stored password for that user ID.

  • A user ID determines authorization and user privileges.

Password Vulnerabilities and Risks
  • Password Theft Without User Awareness: Theft through observation, social engineering, or malware.

  • Easy and Undetected Password Sharing: Risks arise from users sharing credentials unintentionally.

  • Online Password Guessing: Attacks using valid user IDs to try multiple passwords.

  • Off-Line Dictionary Attacks: Attackers use stolen password files and try combinations offline without limits.

  • Keylogging: Software that records keystrokes to capture passwords.

  • Social Engineering: Manipulation of users into revealing sensitive information.

Recommended Countermeasures
  • Regular Password Expiration: Suggested lifetime of 30-90 days to limit the effectiveness of stolen passwords.

  • Strong sharing policies: Reduce unnecessary credential sharing, alternative authentication methods like OTPs (One-Time Passwords).

  • Password Complexity Rules: Enforce minimum lengths and combinations of characters.

  • Account Lockout Policies: Systems lock accounts after failed login attempts.

  • Detection Systems: Monitor unusual login patterns to provide alerts.

Off-Line Dictionary Attacks

  • Attackers steal password files, allowing them to try various combinations using specialized dictionaries that include common passwords.

  • Passwords must be hashed to be secure.

Countermeasures
  • Prevent access to the password file and ensure users cannot choose common passwords.

Keylogging

  • Keylogging entails using software to monitor user keystrokes and stealthily capturing password input.

    • Countermeasure: Utilize malware detection software and encourage alternative input methods.

Social Engineering Definition

  • A method where attackers persuade individuals to disclose confidential information, often impersonating legitimate personnel.

    • Countermeasures: Employee training on recognizing social engineering tactics and establishing verification procedures.

Conclusion

  • Passwords remain the most utilized user authentication method due to their call for no additional hardware or complex algorithms, however, they carry significant security flaws.

    • The use of hashed passwords combined with a salt value enhances security against various vulnerabilities.