Information Security Risk Management Study Notes
INFORMATION SECURITY RISK MANAGEMENT
Introduction
Overview
Content sourced from Security in Computing, Fifth Edition by Charles P. Pfleeger, et al.
ISBN: 9780134085043. Copyright, Pearson Education, Inc. 2015.
Chapter 1
Asset Value
The value of an asset is subjective and varies based on the owner’s or user’s perspective.
It may not always correlate with monetary cost.
Example: Certain computer data can be priceless and irreplaceable, such as an old family picture.
Timing affects asset value.
Example: The value of a product line plan is high before the product is released but drops significantly post-launch.
CIA TRIAD
Goals of Information Security
The CIA triad consists of three primary objectives in information security measures:
Confidentiality: Protection against unauthorized access to sensitive information.
Integrity: Assurance that information remains accurate and reliable.
Availability: Ensuring authorized users have reliable access to information when needed.
Defense in Depth
Concept: A multi-layered approach to security where multiple security devices are employed in a series to create overlapping protection. This strategy includes:
Prevention: Blocking potential attacks.
Detection: Identifying attacks as they occur or post-facto.
Response: Mechanisms for recovery from attacks.
The strategy compensates for weaknesses in any single security layer by reinforcing through multiple layers.
Risk Mitigation Strategies
Countermeasures
A countermeasure is defined as an action taken to handle a security attack. They can be categorized as:
Preventative measures: Aim to stop a type of attack.
Detective measures: Identify attacks when prevention fails.
Recovery measures: Allow for a return to normal status after an attack.
Methods of Harm Response
Prevent: Block an incoming attack or close security gaps.
Deter: Make it more difficult for attacks to succeed.
Deflect: Redirect attacks toward less secure systems.
Mitigate: Reduce potential damage from an attack.
Detect: Recognize attacks during or after occurrence.
Recover: Restore systems and data post-attack.
User Authentication
Definition
Authentication: The act of confirming a user's identity.
Distinguished from Identification, which is simply stating an identity.
Requires reliable confirmation of identities, unlike public identifiers such as usernames.
Identification vs. Authentication
Identities (e.g., usernames) are public and less protected (e.g., bank account numbers displayed on checks).
Authentication should be robust and protected.
Multifactor Authentication
Multifactor authentication: Involves multiple methods from a defined list for user verification.
Strength increases with the number of authentication factors used.
Password-Based Authentication
Overview
Widely recognized as a primary defense against unauthorized access.
Authentication involves comparing a user-provided password with a stored password for that user ID.
A user ID determines authorization and user privileges.
Password Vulnerabilities and Risks
Password Theft Without User Awareness: Theft through observation, social engineering, or malware.
Easy and Undetected Password Sharing: Risks arise from users sharing credentials unintentionally.
Online Password Guessing: Attacks using valid user IDs to try multiple passwords.
Off-Line Dictionary Attacks: Attackers use stolen password files and try combinations offline without limits.
Keylogging: Software that records keystrokes to capture passwords.
Social Engineering: Manipulation of users into revealing sensitive information.
Recommended Countermeasures
Regular Password Expiration: Suggested lifetime of 30-90 days to limit the effectiveness of stolen passwords.
Strong sharing policies: Reduce unnecessary credential sharing, alternative authentication methods like OTPs (One-Time Passwords).
Password Complexity Rules: Enforce minimum lengths and combinations of characters.
Account Lockout Policies: Systems lock accounts after failed login attempts.
Detection Systems: Monitor unusual login patterns to provide alerts.
Off-Line Dictionary Attacks
Attackers steal password files, allowing them to try various combinations using specialized dictionaries that include common passwords.
Passwords must be hashed to be secure.
Countermeasures
Prevent access to the password file and ensure users cannot choose common passwords.
Keylogging
Keylogging entails using software to monitor user keystrokes and stealthily capturing password input.
Countermeasure: Utilize malware detection software and encourage alternative input methods.
Social Engineering Definition
A method where attackers persuade individuals to disclose confidential information, often impersonating legitimate personnel.
Countermeasures: Employee training on recognizing social engineering tactics and establishing verification procedures.
Conclusion
Passwords remain the most utilized user authentication method due to their call for no additional hardware or complex algorithms, however, they carry significant security flaws.
The use of hashed passwords combined with a salt value enhances security against various vulnerabilities.