CyberSecurity#
Organizations Behaving Badly#
A zero-day exploit is a cyber attack that takes place before the security community and/or software developers become aware of and fix a security vulnerability. It takes advantage of security flaws that enable unauthorized users to gain access to a computer system or to download sensitive user data. Until a zero-day exploit is discovered and a patch is written to fix the underlying flaw, users of the software are vulnerable to attack.
While one would hope that the discoverer of a zero-day vulnerability would immediately inform the original software manufacturer so that a fix can be created for the problem, unfortunately this is often not the case. In some cases, this knowledge is sold on the black market to hackers, cyberterrorists, governments, or large organizations that may then use it to launch their own cyberattacks.
The U.S. Federal Bureau of Investigation, Department of Defense, National Security Agency, and other government agencies spend heavily on information about vulnerabilities in computer systems. In many cases, these agencies choose not to inform the public about such cyber threats, leaving all users of the affected software vulnerable to the attack. The reasoning behind such an approach is that keeping a zero-day vulnerability secret from others allows these intelligence and law enforcement agencies to create a powerful tool that can be wielded for espionage or cyberattack purposes.
In theory, U.S. agencies are not allowed to withhold “major” cybersecurity vulnerabilities from the companies affected by them, with few exceptions, under a policy known as the Vulnerabilities Equities Process (VEP). However, critics argue that this policy is not transparent (for instance, it is not clear what triggers the VEP or how many cybersecurity vulnerabilities have been disclosed to affected organizations).
Under the VEP, the FBI found an exception that allowed it to refuse to reveal the vulnerability that enabled it to hack into the iPhone of the San Bernandino shooter who killed 14 people in late 2015. In addition, because the VEP is an executive branch administrative policy—not a law or executive order—it can be overturned at any time by the president.
The Threat Landscape#
The security of data and information systems used in business is of utmost importance. Confidential business data and private customer and employee information must be safeguarded, and systems must be protected against malicious acts of theft or disruption. Although the need for security is obvious, it must often be balanced against other business needs.
Why Compuer Incidents Are So Prevalent?#
Increasing computing complexity, expanding and changing systems, an increase in the prevalence of Bring Your Own Device (BYOD) policies, a growing reliance on software with known vulnerabilities, and the increasing sophistication of those who would do harm have caused a dramatic increase in the number, variety, and severity of security incidents.
Computing environments have become enormously complex. Cloud computing, networks, computers, mobile devices, virtualization, operating systems, applications, websites, switches, routers, and gateway s are interconnected and driven by hundreds fo millions of lines of code. This environment continues to increase in complexity every day. The number of possible entry point s to a network expands continually as more devices are added, increasing the possibility of security breach es.
Business has moved from an era of stand-alone computers, in which critical data were stored in an isolated mainframe computer in a locked room, to an era in which personal computers and mobile devices connect to networks with millions of other computers, all capable of sharing information. Information technology has become ubiquitous and is a necessary tool for organizations to achieve their goals. However, it is increasingly difficult for IT organizations to keep up with the pace of technological change, successfully perform an ongoing assessment of new security risks, and implement approaches for dealing with them.
Bring Your Own Device (BYOD) is a business policy that permits, and in some cases encourages, employees to use their own mobile devices to access company computing resources and applications, including email, ocrporate databases, the corporate intranet, and the Internet. Proponetns of BYOD say it improves employee’s productivity by allowing workers to use devices with which they are already familiar—while also helping to create an image of a company as a flexible and progressive employer.
Most companies have found that they cannot entirely prevent employees from using their own devices to perform work functions. However, this practice raises many potential security issues as it is highly likely that such devices are also used for nonwork activity that exposes them to malware much more frequently than a device used strictly for business purposes.
It is worth noting that employees also have concerns with BYOD policies, primarily related to privacy. Most people place a high priority on keeping any prying eyes, including those of their employer, from looking at the personal photos, text messages, and email stored on their personal mobile devices.
In computing, an exploit is an attack on an information system that takes advantage of a particular system vulnerability. Often this attack is due to poor system design or implementation. Once the vulnerability is discovered, software develoeprs create and issue a “fix”, or patch to eliminate the problem. Users of the system or application are responsible for obtaining and installing the patch, which they can usually download from the web.
Any delay in installing a patch exposes the user to a potential security breach. The need to install a fix to prevent a hacker from taking advantage of a known system vulnerability can create a time-management dilemma for system support personnel trying to balance a busy work schedule.
Clearly, it can be difficult to keep up with all the required patches to fix these vulnerabilities, and U.S. companies increasingly rely on commercial software to use already installed software as is rather than implement security fixes that will either make the software harder to use or eliminate “nice-to-have” features that will help sell the software to end-user s.
Previously, the stereotype of a computer troublemaker was that of an introverted “geek” working on his or her own and motivated by the desire to gain some degree of notoriety. This individual was armed with specialized, but limited, knowledge of computers and networks and used rudimentary tools, perhaps downloaded from the Internet, to execute his or her exploits.
While such individuals still exist, it is not this stereotyped individual who is the biggest threat to IT security. Today’s computer manace is much better organized and may be part of an organized group (for example, Anonymous, Chaos Computer club, Lizard Squad, TeslaTeam, and hacker teams sponsored by national governments) that has an agenda and targets specific organizations and websites. Some of these groups have ample resources, including money and sophisticated tools to support their efforts. Today’s computer attacker has great depth of knowledge and expertise in getting around computer and network security safeguard s.
Types of Perpetrator#
Someone who violates computer or Interent security maliciously for illegal personal gain (in contrast to a white hat hacker who is someone who has been hired by an organization to test the security of its information systems).
An individual who causes problems, steals data, and corrupts systems.
An employee or contractor who attempts to gain financially and/or distrupt a company’s information systems and business operations.
An individual who captures trade secret s and attempts to gain an unfair competitive advantage.
Someone who attacks a computer system or network for financial gain.
An individual who hacks computers or websites in an attempt to promote a political ideology.
Someone who attemps to destroy the infrastructure components of governments, financial institutions, and other corporations, utilities, and emergency response units.
Types of Exploit#
There are numerous types of computer attacks, with new varieties being invented all the time.
While we usually think of such exploits being aimed at computers, smartphones continue to become more computer capable. Increasingly, smartphone users store an array of personal identity information on their devices, including credit card numbers and bank account numbers. The more people use their smartphones for these purposes, the more attractice these devices become as targets for cyberthieves.
One form of smartphone malware runs up charges on users’ accounts by automatically sending messages to numbers that charge fees upon receipt of a message.
Ransomware is a malware that stops you from using your computer or accessing your data until you meet certain demands, such as paying a ransom or sending photos to the attacker. A computer becomes infected with ransomware when a user opens an email attachment containing the malware or is lured to a compromised website by a deceptive email or pop-up window. Ransomware can also be spread through removable USB drives or by texting applications such as Yahoo Messenger, with the payload disguised as an image.
Computer virus has become an umbrella term for many types of malicious code. Technically, a virus is a piece of programming code, usually disguised as something else, that causes a computer to behave in an unexpected and usually undesirable manner. For example, a virus may be programmed to display a certain message on an infected computer’s display screen, delete or modify a certain document, or reformat the hard drive.
Almost all viruses are attached to a file, meaning the virus executes only when the infected file is opened. A virus is spread to other machines when a computer user shares an infected file or sends an email with a virus-infected attachment. In other words, viruses are spread by the action of the “infected” computer user.
Macro viruses have become a common and easily created form of virus. Attackers use an application macro language (such as Visual Basic or VBScript) to create program that infect documents and templates. After an infected document is opened, the virus is executed and infects the user’s application templates. Macro s can insert unwanted words, numbers, or phrases into documents or alter command functions.
After a macro virus infects a user’s application, it can embed itself in all future documents created with the application.
Unlike a computer virus, which requires users to spread infected files to other users, a worm is a harmful program that resides in the active memory of the computer and duplicates itself. Worms differ from viruses in that they can propagate without human intervention, often sending copies of themselves to other computers by email. A worm is capable of replicating itself on your ocomputer so that it can potentially send out thousands of copies of itself to everyone in your email address book, for example.
The negative impact of a worm attack on an organization’s computers can be considerable—lost data and programs, lost productivity due to workers being unable to use their computers, additional lost productivity as workers attempt to recover data and programs, and lots of effort for IT workers to clean up the mess and restore everything to as close to normal as possible.
A Trojan horse is a seemingly harmless program in which malicious code is hidden. A victim on the receiving end of a Trojan horse is usually tricked into opening it because it appears to be useful software from a legitimate source, such as an update for software the user currently has installed on his or her computer. The program’s harmful payload might be designed to enable the hacker to destroy hard drives, corrupt files, control the computer remotely, launch attacks against other computers, steal passowrds, or spy on users by recording keystrokes and transmitting them to a server operated by a third-party. A Trojan horse often creates a “backdoor” on a computer that enables an attacker to gain future access to the system and compromise confidential or private information.
A Trojan horse can be delivered via an email attachment, downloaded to a user’s computer when he or she visits a website, or contracted via a removable media device, such as a DVD or USB memory stick. Once an unsuspecting user executes the program that hosts the Trojan horse, the malicious payload is automatically launched as well—with not telltale signs. Common host programs include scree nservers, greeting card systems, and games.
Another type of Trojan horse is a logic bomb, which executes when it is triggered by a specific event. For example, logic bombs can be triggered by a change in a particular file, by typing a specific series of keystrokes, or at a specific time or date.
A blended threat is a sophisticated threat that combines the features of a virus, worms, Trojan horse, and other malicious code into a single payload. A blended threat attack might use server and Internet vulnerabilities to initiate and then transmit and spread an attack on an organization’s computing devices, using multiple modes to transport itself, including email, Internet Relay Chat (IRC), and file-sharing networks. Rather than launching a narrowly focused attack on specific EXE files, a blended threat might attack multiple EXE files, HTML files, and registry key s simultaneously.
Email spam is the use of email systems to send unsolicited email to large numbers of people. Most spam is a form of low-cost commercial advertising, sometimes for questionable products such as pornography, phony get-rich-quick schemes, and worthless stock. Spam is also an extremely inexpensive marketing tool used by many legitimate organizations. However, spam is also used to deliver harmful worms and other malware.
Spam forces unwanted and often objectionable material into email boxes, detracts from the ability of recipients to communicate effectively due to full mailboxes and relevant emails being hidden among many unsolicited messages, and costs Internet users and service providers millions of dollars annually. It takes user’s time to scan and delete spam email, a cost that can add up if they pay for Internet connection charges on an hourly basis. It also costs money for Internet Service Provider s (ISPs) and online services to transmit spam, which is reflected in the rates of charged to all subscibers.
There is an even more sinister side to spam—often it is used to entice unsuspective recipients to take actions that will result in malware being downloaded to their computer.
The Controlling the Assault of Non-Solicited Pornography and Marketing (CAN-SPAM) Act states that it is legal to spam, provided the messages meet a few basic requirements—spammers cannot disguise their identity by using a false return address, the email must include a label specifying that it is an ad or a solicitation, and the email must include a way for recipients to indicate that they do not want future mass mailings.
Many companies—including Google, Microsoft, and Yahoo!—offer free email services. Spammers often seek to use email accounts from such major, free, and reputable web-based email service providers, as their spam can be sent at no charge and is less likely to be blocked. Spammers can defeat the registration process of the free email services by launching a coordinated bot attack that can sign up for thousands of email accounts. These accounts are then used by the spammers to send thousands of untraceable email messages for free.
A partial solution to this problem is the use of Completely Automated Public Turing Test to Tell Computers and Humans Apart (CAPTCHA) to ensure that only humans obtain free accounts. CAPTCHA software generates and grades tests that humans can pass and all but the most sophisticated computer programs cannot. For example, humans can read the distorted text but simple computer programs cannot.
A distributed denial-of-service (DDoS) attack is one in which a malicious hacker takes over computers via the Internet and causes them to flood a target site with demands for data and otehr small tasks. A DDoS attack does not involve infiltration of the targeted system. Instead, it keeps the target so busy responding to a stream of automated requests that legitimate users cannot get in—the Internet equivalent of dialing a telephone number repeatedly so that all other callers hear a busy signal. The targeted machine essentially holds the line open while waiting for a reply that never comes; eventually, the requests exhaust all resources of the target.
The software required to initiate a DDoS is simple to use, and many DDoS tools are readily available at a variety of hacker sites. In a DDoS attack, a tiny program is downloaded surreptitiously from the attacker’s computer to dozens, hundres, or even thousands of computers all over the world.
The term botnet is used to describe a large group of such computers, which are controlled from one or more remote locations by hackers, without the knowledge or consent of their owners. The collective processing capacity of some botnets exceeds that of the world’s most powerful supercomputers. Based on a command by the attacker or at a preset time, the botnet computers (called zombies) go into action, each sending a simple request for access to the target site again and again—dozens of times per second. The target computers become so overwhelmed by requests for service that legitimate users are unable to get through to the target computer.
A rootkit is a set of programs that enables its user to gain administrator-level access to a computer without the end-user’s consent or knowledge. Once installed, the attacker can gain full control of the system and even obscure the presence of the rootkit from legitimate system administrators. Attackers can use the rootkit to execute files, access logs, monitor user activity, and change the computer’s configuration. Rootkits are one part of a type of blended threat that consists of a dropper, a loader, and a rootkit. The dropper code gets the rootkit installation started and can be activated by clicking on a link to a malicious website in an email or opening an infected PDF file. The dropper lauches the loader program and then deletes itself. The loader loads the rootkit into memory; at that point, the computer has been compromised. Rootkits are designed so cleverly that it is difficul even to discover if they are installed on a computer. The fundamental problem with trying to detect a rootkit is that the operating system cannot be trusted to provide valid test results.
The following are some symptoms of rootkit infections:
The computer locks up or fails to respond to input from the keyboard or mouse.
The screen saver changes without any action on the part of the user.
The taskbar disappears.
Network activities function extremely slowly.
When it is determined that a computer has been infected with a rootkit, there is little to do but reformat the disk; reinstall the operating system and all applications; and reconfigure the user’s settings, such as mapped drives. This can take hours, and the user may be left with a basic working machine, but all locally held data and settings may be lost.
An advanced persistent threat (APT) is a network attack in which an intruder gains access to a network and stays there—undetected—with the intention of stealing data over a long period of time (weeks or even months). Attackers in an APT must continuously rewrite code and employ sophisticated evasion techniques to avoid discovery. APT attacks target organizations with high-value information, such as banks and financial institutions, government agencies, and insurance companies with the goal of stealing data rather than disrupting services.
An APT attack advances through the following five phases:
- Reconnaissance.
The intruder begins by conducting reconnaissance on the network to gain useful information about the target (security software installed, computing resources connected to the network, number of users).
- Incursion.
The attacker next launches incursion s to gain access to the network at a low level to avoid setting off any alarms or suspicion. Some forms of spear phishing may be employed in this phase. After gaining entrance, the attacker establishes a backdoor, or a means of accessing a computer program that bypasses security mechanisms.
- Discovery.
The intruder now begins a discovery process to gather valid user credentials (especially administrative ones) and move laterally across the network, installing more backdoors. These backdoors enable the attacker to install bogus utilities for distributing malware that remains hidden in plain sight.
- Capture.
The attacker is now ready to access unprotected or compromised systems and capture information over a long period of time.
- Export.
Captured data are then exported back to the attacker’s home base for analysis and/or used to commit fraud and other crimes.
Although APT attacks are difficult to identify, the theft of data can never be completely invisible. Detecting anomalies in outbound data is perhaps the best way for an administrator to discover that the network has been the target of an APT attack.
Phishing is the act of fraudulently using email to try to get the recipient to reveal personal data. In a phishing scam, con artist s send legitimate-looking emails urging the recipient to take action to avoid a negative consequence or to receive a reward. The requested action may involve clicking on a link to a website or opening an email attachment. These emails lead consumers to counterfeit websites designed to trick them into divulging personal data or to download malware onto their computers.
Spear phishing is a variation of phishing in which the phisher sends fraudulent emails to a certain organization’s employees. It is known as spear phishing because the attack is much more precise and narrow, like the tip of a spear. The phony emails are designed to look like they came from high-level executives within the organization. Employees are directed to a fake website and then asked to enter personal information, such as name, Social Security number, and network passwords. Botnets have become the primary means for distributing phishing scams.
Smishing is another variation fo phishing that involves the use of texting. In a smishing scam, people receive a legitimate-looking text message telling them to call a specific phone number or log on to a website. This is often done under the guise that there is a problem with the recipient’s bank account or credit card that requires immediate attention. However, the phone number or website is phony and is used to trick unsuspecting victims into providing personal information such as a bank account number, personal identification number, or credit card number, which can then be used to steal money from victims’ bank accounts, charge purchases on their credit cards, or open new accounts. In some cases, if victims log on to a website, malicious software is downloaded onto their smartphones, providing criminals with access to information stored on the phones. The number of smishing scams typically increases around the holidays as more people use their smartphones to make online purchases.
Vishing is similar to smishing except that the victims receive a voice-mail message telling them to call a phone number or access a website.
Financial institutions, credit card companies, and other organizations whose customers may be targeted by criminals in this manner should be on the alert for phishing, smishing, and vishing scams. They must be prepared to act quickly and decisively, without alarming their customers if such a scam is detected. Recommended action steps for institutions and organizatiosn include the following:
Companies should educate their customers about the dangers of phishing, smishing, and vishing through letters, recorded messages for those calling into the company’s call center, and articles on the company’s website.
Call center service employees should be trained to detect customer complaints that indicate a scam is being perpetrated. They should attempt to capture key pieces of information, such as the callback number the customer was directed to use, details of the phone message or text message, and the type of information requested.
Customers should be notified immediately if a scam occurs. This can be done via a recorded message for customers phoning the call center, working with local media to place a news article in papers serving the area of the attack, placing a banner on the institution’s web page, and even displaying posters in bank drive-through and lobby areas.
If it is determined that the calls are originating from within the United States, companies should report the scam to the FBI.
Institutions can also try to notify the telecommunications carrier for the particular members to request that they shut down the phone number’s victims are requested to call.
Cyberspionage involved the deployment of malware that secretly steals data in the computer systems of organizations, such as government agencies, military contractors, political organizations, and manufacturing firms. The type of data most frequently targeted includes data that can provide an unfair competitive advantage to the perpetrator. These data are typically not public knowledge and may even be protected via patent, copyright, or trade secret. High-value data include the following:
Sales, marketing, and new product development plans, schedules, and budgets
Details about product designs and innovative processes
Employee personal information
Customer and client data
Sensitive information about partneres and partner agreements
Cyberterrorism is the intimidation of government or civilian population by using information technology to disable critical national infrastructure (for example, energy, transportation, financial, law enforcement, and emergency response) to achieve political, religious, or ideological goals. It is an increasing concern for countries and organizations around the globe. Indeed, in a statement released by the White House in early 2015, President Obama said, “Cyber threats pose one of the gravest national security danges that the United States faces.”
The Department of Homeland Security (DHS) is a large federal agency with more than 240,000 employees and a budget of almost $65 billion whose goal is to provide for a “safer, moe secure America, which is resilient against terrorism and other potential threats.” The agency’s Office of Cybersecurity and Communications resides within the National Protection and Programs Directorate and is responsible for enhancing the security, resilience, and reliability of U.S. cyber and communications infrastructure.
It works to prevent or minimize disruptions to critical information infrastructure in order to protect the public, the economy, and government services. The DHS website provides a link that enables users to report cyber incidents. Incident reports go to the U.S. Computer Emergency Readiness Team (US-CERT) Incident Reporting System, which assists analysts at the US-CERT (a partnership between the DHS and the public and private sectors) in providing timely handling of security incidents as well as in conducting improved analysis of such incidents.
Cyberterrorists try on a daily basis to gain unauthorized access to a number of important and sensitive sites, such as the computers at the British, French, Israeli, and U.S. foreign intelligence agencies; North American Aerospace Defense Command (NORAD); and numerous government ministries and private companies around the world.
Federal Laws for Prosecuting Computer Attacks#
Over the years, several laws have been enacted to help prosecute those responsible for computer-related crimes. For example, Section 814 of the USA Patriot Act defines cyberterrorism as any hacking attempts designed to gain unauthorized access to a protected computer, which, if successful, would cause a person an aggregate loss greater than $5,000; adversely affect someone’s medical examination, diagnosis, or treatment; cause a person to be injured; cause a threat to public health or safety; or cause damage to a governmental computer that is used as a tool to administer justice, national defense, or national security. Those convicted of cyberterrorism are subject to a prison term of 5 to 20 years. (The $5,000 threshold is quite easy to exceed, and, as a result, many young people who have been involved in what they consider to be minor computer pranks have found themselves meeting the criteria to be tried as cyberterrorists.)
- Computer Fraud and Abuse Act (U.S. Code Title 18, Section 1030)
Addresses fraud and related activities in association with computers, including the following:
Accessing a computer without authorization or exceeding authorized access;
Transmitting a program, code, or command that causes harm to a computer;
Trafficking of computer passwords;
Threatening to cause damage to a protected computer.
- Fraud and Related Activity in Connection with Access Devices Statute (U.S. Code Title 18, Section 1029)
Covers false claims regarding unauthorized use of credit cards.
- Stored Wire and Electronic Communications and Transactional Records Access Statutes (U.S. Code Title 18, Chapter 121)
Focuses on unlawful access to stored communications to obtain, alter, or prevent authorized access to a wire or electronic communication while it is in electronic storage.
- USA Patriot Act (Public Law 107-56)
Defines cyberterrorism and associated penalties.
The CIA Security Triad#
The IT security practices of organizations worldwide are focused on ensuring confidentiality, maintaining integrity, and guaranteeing the availability of systems and data. Confidentiality ensures that only those individuals with the proper authority can access sensitive data such as employee personal data, customer and product sales data, and new product and advertising plans. Integrity ensures that data can only be changed by authorized individuals so that the accuracy, consistency, and trustworthiness of data are guaranteed. Availability ensures that the data can be accessed when and where needed, including during times of both normal and disaster recovery operations. A widely held but difficult-to-achive standard for a system or product is known as “five 9s” or 99.999% availability. For an operation that runs 365 days per year, 24 hours per day this translates to less than one hour of unavailability per year. Confidentiality, integrity, and availability are referred to as the CIA security triad.
Implementing CIA at the Organization Level#
Implementing CIA begins at the organization level with the definition of an overall security strategy, performance of a risk assessment, laying out plans for disaster recovery, setting security policies, conducting security audits, ensuring regulatory standards compliance, and creating a security dashboard. Completion of these tasks at the organizational level will set a sound foundation and clear direction for future CIA-related actions.
Implementing CIA security at the organization level requires a risk-based security strategy with an active governance process to minimize the potential impact of any security incident and to ensure business continuity in the event of a cyberattack. Creating such a strategy typically beings with performing a risk assessment to identify and prioritize the threats that the organization faces. The security strategy must define a disaster recovery plan that ensures the availability of key data and information technology assets. Security policies are needed to guide employees to follow recommended processes and practices to avoid security-related problems. Periodic security audit s are needed to ensure that individuals are following established policies and to assess if the policies are still adequate even under changing conditions. In addition to complying with its internal policies, an organization may also need to comply with standards defined by external parties, including regulatory agencies. Many organizations employ a security dashboard to help track the key performance indicators of their security strategy. The various components of the security strategy will now be defined.
Risk assessment is the process of assessing security-related risks to an organization’s computers and networks from both internal and external threats. Such threats can prevent an organization from meeting its key business objectives. The goal of risk assessment if to identify which investments of time and resources will best protect the organization from its most likely and serious threats.
In the context of an IT risk assessment, an asset is any hardware, software, information system, network, or database that is used by the organization to achieve its business objectives. A loss event is any occurrence that has a negative impact on an asset, such as a computer contracting a virus or a website undergoing a DDoS attack.
The steps in a general security risk management process are as follows:
- Step 1
Identify the set of IT assets about which the organization is most concerned. Priority is typically given to those assets that support the organization’s mission and the meeting of its primary business goals.
- Step 2
Identify the loss events or the risks or threats that could occur, such as a DDoS attack or insider fraud.
- Step 3
Assess the frequency of events or the likelihood of each potential threat; some threats, such as insider fraud, are more likely to occur than others.
- Step 4
Determine the impact of each threat occurring. Would the threat have a minor impact on the organization, or could it keep the organization from carrying out its mission for a lengthy period of time?
- Step 5
Determine how each threat can be mitigated so that is becomes much less likely to occur or, if it does occur, has less of an impact on the organization. Due to time and resource limitations, most organizations choose to focus on just those threats that have a high (relative to all other threats) probability of occurrence and a high (relative to all other threats) impact. In other words, first address those threats that are likely to occur and that would have a high negative impact on the organization.
- Step 6
Assess the feasibility of implementing the mitigation options.
- Step 7
Perform a cost-benefit analysis to ensure that your efforts will be cost-effective. No amount of resources must balance the risk of a security breach with the cost of preventing one. The concept of reasonable assurance in connection with IT security recognizes that managers must use their judgment to ensure that the cost of control does not exceed the system’s benefits or the risks involved.
- Step 8
Make the decision on whether or not to implement a particular countermeasure. If you decide against implementing a particular countermeasure, you need to reassess if the threat is truly serious and, if so, identify a less costly countermeasure.
Adverse event |
Business objective threatened |
Threat (estimated frequency of event) per year |
Vulnerability (likelihood of sucess of this threat) (%) |
Estimated cost of a successful attack ($) |
Risk = Threat x Vulnerability x Estimated cost ($) |
Relative priority to be fixed |
|---|---|---|---|---|---|---|
Data breach of customer account data |
Provide a safe, secure website that consumers can trust |
18 |
3 |
5,000,000 |
2,700,000 |
1 |
Dstributed DDoS attack |
24/7 operation of a retail website |
3 |
25 |
500,000 |
375,000 |
2 |
Email attachment with harmful worm |
Rapid and reliable communications among employees and suppliers |
1,000 |
0.05 |
200,000 |
100,000 |
3 |
Harmful virus |
Employees’ use of personal productivity software |
2,000 |
0.04 |
50,000 |
40,000 |
4 |
Invoice and payment fraud |
Reliable cash flow |
1 |
10 |
200,000 |
20,000 |
5 |
Data availability requires implementing products, services, policies, and procedures that ensure that data are accessible even during disaster recovery operations. To accomplish this goal, organizations typically implement a disaster recovery plan, which is a documented process for recovering an organization’s business information system assets—including hardware, software, data, networks, and facilities—in the event of a disaster.
A disaster recovery plan focuses on technology recovery and identifies the people or the teams responsible to take action in the event of a disaster, what exactly these people will do when a disaster strikes, and the information system resources required to support critical business processes. Disasters can be natural (for example, earthquake, fire, and flood) or manmade (for example, accident, civil unrest, and terrorism). When developing a disaster recovery plan, organizations should think in terms of not being able to gain access to their normal place of business for an extended period of time, possibly up to several months.
As part of defining a business continuity plan, an organization should conduct a business impact analysis to identify critical business processes and the resources that support them. The recovery time for an information system resource should match the recovery time objective for the most critical business processes that depend on that resource. Some business processes are more pivotal to continued operations and goal attainment than others. These processes are called mission-critical processes. Quickly recovering data and operations for these mission-critical processes can make the difference between failure and survival for an organization. If your billing system doesn’t work and you can’t send out invoices, your company is at the risk of going out of business due to cash flow issues.
Cloud computing has added another dimension to disaster recovery planning. If your organization is hit by a disaster, information systems that are running in the cloud are likely to be operational and accessible by workers from anywhere they can access the Interent. Data stored in the cloud may be insulated from the effects of a disaster if it is stored at the site of the service provider, which could be hundreds of miles from the organization. On the other hand, if the cloud service provider is hit by a disaster, it may cause a serious business disruption for your organization even if it is otherwise unaffected by a distant disaster. Thus, part of the evaluation of a cloud service provider must include analysis of the provider’s disaster recovery plans.
Files and databases can be protected by making a copy of all files and databases changed during the last few days or the last week, a technique called incremental backup. This approach to backup uses an image log, which is a separate file that contains only changes to applications or data. Whenever an application is run, an image log is created that contains all changes made to all files. If a problem occurs with a database, an old database with the last full backup of the data, along with the image log, can be used to re-create the current database.
It is imperative that a disaster plan be practiced and improvements be made to the plan based on the results of the test. Unfortunately, a recent survey of IT managers revealed that as many as one in eight have either never tested their organization’s disaster recovery solution or have no idea exactly when it was last tested. One reasonable approach to testing is to simulate a disaster for a single critical portion (for example, order processing or customer billing) of your business during a time of low business activity. The next disaster plan test should then target a different area of the business.
A security policy defines an organization’s security requirements, as well as the controls and sanctions needed to meet those requirements. A good security policy delineates responsibilities and the behavior expected of members of the organization. A security policy outlines what needs to be done but not how to do it. The details of how to accomplish the goals of the policy are typically provided in separate documents and procedure guidelines.
Experienced IT managers understand that users will often attempt to circumvent security policies or simply ignore them altogether. Because of that, automated system rules should mirror an organization’s written policies whenever possible. Automated system rules can often be put into practice using the configuration options in software program. For example, if a written policy states that passwords must be changed every 30 days, then all systems should be configured to enforce this policy automatically.
System administrators must also be vigilant about changing the default username sand passwords for specific devices when they are added to an organization’s network. Cybercriminals and others looking to access the networks of various organizations can easily find information online regarding the default username and password combinations for many vendor’s products.
A growing area of concern for security experts is the use of wireless devices to access corporate email, store confidential data, and run critical applications, such as inventory management and sales force automation. Mobile devices such as smartphones can be susceptible to viruses and worms. However, the primary security threat for mobile devices to be loss or theft of the device. Wary companies have begun to include special security requirements for mobile devices as part of their security policies. In some cases, users of laptops and mobile devices must use a virtual private network (VPN) to gain access to their corporate network.
Another important prevention tool is a security audit that evaluates whether an organization has a well-considered security policy in place and if it is being followed. For example, if a policy says that all users must change their passwords every 30 days, the audit must check how well that policy is being implemented. The audit should also review who has access to particular systems and data and what level of authority each user has. It is not unusual for an audit to reveal that too many people have access to critical data and that many people have capabilities beyond those needed to perform their jobs. One result of a good audit is a list of items that needs to be addressed in order to ensure that the security policy is being met.
A thorough security audit should also test system safeguards to ensure that they are operating as intended. Such tests might include trying the default system passwords that are active when software is first received from the vendor. The goal of such a test is to ensure that all such known passwords have been changed.
Some organizations will also perform a penetration test of their defenses. This entails assigning individuals to try to break through the measures and identify vulnerabilities that still need to be addressed. The individuals used for this test are knowledgeable and are likely to take unique appraches in testing the security measures.
In addition to the requirement to comply with your own security program, your organization may also be required to comply with one or more standards defined by external parties. In that case, your organization’s security program must include a definition of what those standards are and how the organization will comply.
Act or standard |
Who is affected? |
Subject matter |
|---|---|---|
Bank Secrecy Act of 190 (Public Law 91-507)— Amended several times, including by provisions in Title III of the USA PATRIOT Act (see 31 USC S. 5311-5330 and Title 31 Code of Federal Regulations Chapter X) |
Financial institutions |
Requires financial institutions in the United States to assist U.S. government agencies in detecting and preventing money laundering |
European Union—United States Privacy Shield |
Organizations that do business with companies and/or individuals in the European Union |
Provides companies on both sides of the Atlantic with a mechanism to comply with EU data protection requirements when transferring personal data from the European Union to the United States in support of transatlantic commerce |
Federal Information Security Management Act (44 U.S.C. S. 3541, et seq.) |
Every federal agency |
Requires each federal agency to provide information security for the data and information systems that support the agency’s operations and assets, including those provided or managed by another agency, contractor, or other source. |
Foreign Corrupt Practices Act (15 U.S.C. S. 78dd-1, et seq.) |
Any person who is a citizen, national, or resident of the United States and engages in foreign corrupt practices; also applies to any act by U.S. businesses, foreign corporation’s trading securities in the United States, American nationals, U.S. citizens, and U.S. residents acting in furtherance of a foreign corrupt practice whether or not they are physicall present in the United States. |
Makes certain payments to foreign officials and other foreign persons illegal and requires companies to maintain accurate records. |
Gramm-Leach-Bliley Act (Public Law 106-102) |
Companies that offer financial products or services to individuals, such as loans, insurance, or financial and investment advice. |
Governs the collection, disclosure, and protection of consumers’ nonpublic personal information or personally identifiable information. |
Health Insurance Portability and Accountability Act (Public Law 104-191) |
Healthcare clearinghouses, employer-sponsored health plans, health insurers, and medical service providers |
Regulates the use and disclosure of an individual’s health information |
Payment Card Industry Data Security Standard (PCI DSS) |
All organizations that store, process, and transmit cardholder data, most notably for debit cards and credit cards. |
Provides a framework of specifications, tools, measurements, and support resources to help organizations ensure the safe handling of cardholder information. |
Sarbanes-Oxley Act (Public Law 107-204 116 Stat. 745) |
All public corporations |
Protects shareholders and the general public from accounting errors and fraudulent practices in the enterprise. |
Many organizations use security dashboard software to provide a comprehensive display of all key performance indicators related to an organization’s security defenses, including threats, exposures, policy compliance, and incident alerts. The purpose of a security dashboard is to reduce the effort required to monitor and identify threats in time to take action. Data that appear in a security dahsboard can come from a variety of sources, including security audits, firewall s, applications, servers, and other hardware and software devices.
# |
Key performance measure |
Goal |
Actual |
Status |
|---|---|---|---|---|
1 |
Number of segregation-of-duty violations |
0 |
2 |
Red |
2 |
Number of users with weak, noncompliant passwords |
<5 |
4 |
Green |
3 |
Percentage of critical IT assets that passed penetration tests |
>96% |
93% |
Yellow |
4 |
Backlog of software security patches and updates |
<3 |
3 |
Green |
5 |
Number of days since last internal security audit |
<90 |
94 |
Yellow |
6 |
Percentage of employees and contractors who passed security exam |
>95% |
87% |
Red |
7 |
Score on last disaster-recovery test |
>90% |
93% |
Green |
Legend
Red: Immediate action required.
Yellow: Caition, should be monitored.
Green: OK, goal has been met.
Implementing CIA at the Network Level#
The Internet provides a wide-open and well-travelled pathway for anyone in the world to reach your organization’s network. As a result, organizations are continuing to move more of their business processes to the Internet to better serve customers, suppliers, employees, investors, and business partners. However, unauthorized network access by a hacker or resentful employee can result in compromised sensitive data and severely degrade services, with a resulting negative impact on productivity and operational capability. This, in turn, can create a severe strain on relationships with customers, suppliers, employees, investors, and business partners, who may question the capability of the organization to protect its confidential information and offer reliable services. Organizations must carefully manage the security of their networks and implement strong measures to ensure that sensitive data re not accessible to anyone who is not authorized to see it.
To maintain a secure network, an organization must authenticate users attempting to access the network by requiring them to enter a username and password; inserting a smart card and entering the associated PIN; or providing a fingerprint, voice pattern sample, or retina scan. The Federal Financial Institutions Examination Council has developed a set of guidelines called “Authentication in an Internet Banking Environment,” which recommends a two-factor authorization. This approach adds another identity check along with the password system. A number of multifactor authentication schemes can be used, such as biometrics, one-time passwords, or hardware tokens that plug into a USB port on the computer and generate a password that matches the one used by a bank’s security system.
Installation of a corporate firewall is the most common security precaution taken by businesses. A firewall is a system of software, hardware, or a combination of both that stands guard between an organization’s internal network and the Internet and limits network access based on the organization’s access policy.
Any Internet traffic that is not explicitly permitted into the internal network is denied entry through a firewall. Similarly, most firewalls can be configured so that itnernal network users can be blocked from gaining access to websites deemed inappropriate for employees, such as those whose content is based on sex and violence. Most firewalls can also be configured to block instant messaging, access to newsgroups, and other Internet activities.
A next-generation firewall (NFGW) is a hardware- or software-based network security system that is able to detect and block sophisticated attacks by filtering network traffic dependent on the packet contents. Compared to first- and second-generation firewalls, an NFGW goes deeper to inspect the content of packets and match sequences of bytes for harmful activities, such as known vulnerabilities, exploit attacks, viruses, and malware.
A router is a networking device that connects multiple networks together and forwards data packets from one network to another. Often, an ISP installs a router in a subscriber’s home to connect the ISP’s network to the network within the home.
Routers enable you to create a secure network by assigning it a passphrase so that only individuals who have the passphrase can connect to your network. However, a skilled and committed attacker can break the passphrase to gain access to your network. So, as an additional layer of security, the router provides you the capability to specify the unique media access control (MAC) address of each legitimate device connected to the network and restrict access to any other device that attempts to connect to the network. This effectively enables the router to distinguish legitimate traffic from unsolicited traffic and reject uninvited inbound connections. Most routers also have an option to restrict access to specific websites, thus blocking access to websites that are known to infect user devices with malware.
Encryption is the process of scrambling messages or data in such a way that only authorized parties can read it. It is used to protect billions of online transactions each day. To complete such transactions, sensitive data must be sent and received. Great harm could be done and chaos could ensue if these data were to fall into the wrong hands. Encryption is one means of keeping these data secure.
An encryption key is a value that is applied (using an algorithm) to a set of unencrypted text (plaintext) to produce encrypted text that appears as a series of seemingly random characters (ciphertext) that is unreadable by those without the encryption key needed to decipher it. There are two types of encryption algorithms: symmetric and asymmetric.
Symmetric algorithms use the same key for both encryption and decryption. Asymmetric algorithms use one key for encryption and a different key for decryption. Advanced Encryption Standard (AES) is the most widely used symmetric algorithm and is entrusted to protect classified U.S. government information. Wireless Protected Access 2 (WPA2), which is the most commonly used security protocol for wireless networks today, employs the AES encryption algorithm.
The ability to keep encrypted data secret is not determined by the encryption algorithm, which is widely known, but rather on the encryption key. The encryption key is chosen from one of a large number of possible encryption keys. In general, the longer the key, the stronger the encryption. Thus, an encryption protocol is based on a 56-bit key is not as strong as one based on a 128-bit key. Of course, it is essential that the key be kept secret from possible interceptors. A hacker who obtains the key can recover the original message from the encrypted data. Encryption methods rely on the limitations of computing power for their security. If breaking a code requries too much computing power, even the most determined hacker cannot be successful.
Many online shoppers fear the theft of their credit card numbers and banking information. To help prevent this type of theft, the Transport Layer Security (TLS) communications protocol is used to secure sensitive data. Transport Layer Security (TLS) is a communications protocol or system of rules that ensures privacy between communicating applications and their users on the Internet. TLS enables a client (such as a web browser) to initiate a temporary, private conversation with a server (such as an online shopping site or bank). Before the client and server start communicating, they perform an automated process called a “handshake” during which they exchange information about who they are and which secret codes and algorithms they will use to encode their messages to each other. Then, for the duration of the conversation, all the data that pass between the client and server is encrypted so that even if somebody does listen in, they won’t be able to determine what is being communicated.
A proxy server serves as an intermediary between a web browser and another server on the Internet that makes requests to websites, servers, and services on the Internet for you. When you enter the URL for a website, the request is forwarded to the proxy server, which relays the request to the server where the website is hosted. The homepage of the website is returned to the proxy server, which then passes it on to you. Thus the website sees the proxy server as the actual visitor and not you.
By forcing employees to access the Internet through a proxy server, companies can prevent employees from accessing certain websites. A proxy server can also capture detailed records of all the websites each employee has visited, when, and for how long. When you access a website directly, the server hosting the website can see your IP address and store cookies on your computer, but a proxy server can hide your IP address and block cookies from being sent to your device. A proxy server relays those packets for you and strips the originating address so instead of your IP address, the website only sees the address of the proxy server.
Remote users working at home, from a client’s office, or in a branch office often have a need to access sensitive data on a company’s private servers; however, doing so from an unsecured public network, such as a coffee shop wireless hotspot, could expose that data to unauthorized users with ill intentions. A VPN enables remote users to securely access an organization’s collection of computing and storage devices and share data remotely. To connect to a VPN, you launch a VPN client on your computer and perform some form of authentication using your credentials, Your computer then exchanges keys to be used for the encryption process with the VPN server. Once both computers have verified each other as authentic, all of your Internet communications are encrypted and secured from eavesdropping.
An intrusion detection system (IDS) is software and/or hardware that monitors system and network resources and activities and notifies network security personnel when it detects network traffic that attempts to circumvent the security measures of a networked computer environment. Such activities usually signal an attempt to breach the integrity of the system or to limit the availability of network resources.
Knowledge-based approaches and behavior-based approaches are two fundamentally different approaches to intrusion detection. Knowledge-based IDSs contain information about specific attacks and system vulnerabilities and watch for attempts to exploit these vulnerabilities, such as repeated failed login attempts or recurring attempts to download a program to a server. When such an attempt is detected, an alarm is triggered. A behavior-based IDS models normal behavior of a system and its users from reference infokrmation collected by various means. The IDS compares current activity to this model and generates an alarm if it finds a deviation. Examples include unusual traffic at odd hours or a user in the human resources department who accesses an accounting program that he or she has never before used.
Implementing CIA at the Application Level#
Authentication methods, user roles and accounts, and data encryption are key elements of the application security layer. These elements must be in place to ensure that only authorized users have access to the organization’s applications and data and that their access is limited to actions that are consistent with their defined roles and responsibilities.
For many applications, users are required to enter a username and password to gain access. This is a form of single-factor authentication as the user needs to provide just one credential, a password to gain access. Two-factor authentication requires the user to provide two types of credential before being able to access an account; the two credentials can be any of the following:
Something you know, such as a PIN or password;
Something you have, such as some form of security card or token;
Something you are, such as a biometric (for example, a fingerprint or retina scan).
Two-factor authentication is required to withdraw money from a cash machine. You must present your bank card (something that you have) and a PIN (something that you know) to obtain cash from the machine.
Another important safeguard at the application level is the creation of roles and user accounts so that once users are authenticated, they have the authority to perform their responsibilities and nothing more. For example, members of the finance department should have different authorizations from members of the human resources department. An accountant should not be able to review the pay and attendance records of an employee, and a member of the human resources department should not know how much as spent to modernize a piece of equipment. Even within one department, for example, some users may be able to approve invoices for payment, but others may only be able to enter them. An effective system administrator will identify similarities among users and create profiles associated with these groups.
Major enterprise systems such as enterprise resource planning (ERP), customer relationship management (CRM), and product lifecycle management (PLM) access sensitive data residing on data storage devices located in data centers, in the cloud, or at third-party locations. Data encryption should be used within such applications to ensure that these sensitive data are protected from unauthorized access.
Implementing CIA at the End-User Level#
Security education, authentication methods, antivirus software, and data encryption must all be in place to protect what is often the weakest link in the organization’s security perimeter—the individual end-user.
Creating and enhancing user awareness of security policies is an ongoing security priority for companies. Employees and contract workers must be educated about the importance of security so that they will be motivated to understand and follow security policies. This can often be accomplished by discussing recent security incidents that affected the organization. Users must understand that they are a key part of the security system and that they have certain responsibilities. For example, users must help protect and organization’s information systems and data by doing the following:
Guarding their passwords to protect against unauthorized access to their accounts;
Prohibiting others from using their passwords;
Applying strict access controls (file and directory permissions) to protect data from disclosure and destruction;
Reporting all unusual activity to the organization’s IT security group;
Taking care to ensure that portable computing and data storage devices are protected (hundreds of thousands of laptops are lost or stolen per year).
Security assessment question |
|---|
Do you have the most current version of your computer’s operating system installed? |
Do you have the most current version of firewall, antivirus, and malware software installed? |
Do you install updates to all your software when you receive notice that a new update is available? |
Do you use different, strong passwords for each of your accounts and applications—a minimum of 10 characters, with a mix of capital and lowercase letters, numbers, and special characters? |
Are you familiar with and do you follow your organization’s policies in regard to accessing corporate websites and applications from your home or remote locations (for example, access via a VPN)? |
Have you set the encryption method to WPA2 and changed the default name and password on your home wireless router? |
When using a free, public wireless network, do you avoid checking your email or accessing websites requiring a username and password? |
Do you regrain from clicking on a URL in an email from someone you do not know? |
Do you back up critical files to a separate device at least once a week? |
Are you familiar with and do you follow your organization’s policies regarding the storage of personal or confidential data on your device? |
Does your device have a security passcode that must be entered before it accepts further input? |
Have you installed Locate My Device or similar software in case your device is lost or stolen? |
Do you make sure not to leave your device unattended in a public place where it can be easily stolen? |
Have you reviewed and do you understand the privacy settings that control who can see or read what you do on Facebook and other social media sites? |
End-users should be required to implement a security passcode that must be entered before their computing/communications device accepts further input. If your device supports Touch ID, you can use your fingerprint instead of your passcode. Again, a number of multifactor authentication schemes can be used.
Antivirus software should be installed on each user’s personal computer to scan a computer’s memory and disk drives regularly for viruses. Antivirus software scans for a specific sequence of bytes, known as a virus signature, that indicates the presence of a specific virus. If it finds a virus, the antivirus software informs the user, and it may clean, delete, or quarantine any files, directories, or disks affected by the malicious code. Good antivirus software checks vital system files when the system is booted up, monitors the system continuously for virus-like activity, scans disks, scans memory when a program is run, checks programs when they are downloaded, and scans email attachments before they are opened. Two of the most widely used antivirus software products are Norton AntiVirus from Symantec and Personal Firewall from McAfee.
According to US-CERT, most virus and worm attacks use already known malware programs. Thus, it is crucial that antivirus software be continually updated with the latest virus signatures. In most corporations, the network administrator is responsible for monitoring network security websites frequently and downloading updated antivirus software as needed. Many antivirus vendors recommended—and provide for—automatic and frequent updates. Unfortunately, antivirus software is not able to identify and block all viruses.
While you should already have a login password for your mobile computing device or workstation, those measures won’t protect your data if someone steals your device—the thief can simply remove your storage device or hard drive and plug it into another computing device and access the data. If you have sensitive information on your computer, you need to employ full-disk encryption, which protects all your data even if your hardware falls into the wrong hands.
Response to CyberAttack#
An organization should be prepared for the worst—a successful attack that defeats all or some of a system’s defenses and damages data and information systems. A response plan should be developed well in advance of any incident and be approved by both the organization’s legal department and senior management. A well-developed response plan helps keep an incident under technical and emotional control.
In a security incident, the primary goal must be to regain control and limit damage, not to attempt to monitor or catch an intruder. Sometimes system administrators take the discovery of an intruder as a personal challenge and lose valuable time that should be used to restore data and information systems to normal.
A key element of any response plan is to define who to notify and who not to notify in the event of a computer security incident. Questions to cover include the following: Within the company, who needs to be notified, and what information does each person need to have? Under what conditions should the company contact major customers and suppliers? How does the company inform them of a disruption in business without unnecessarily alarming them? When should local authorities or the FBI be contacted?
Most security experts recommend against giving out specific information about a compromise in public forums, such as news reports, conferences, professional meetings, and online discussion groups. All parties working on the problem must be kept informed and up-to-date without using systems connected to the compromised system. The intruder may be monitoring these systems and emails to learn what is known about the security breach.
A critical ethical decision that must be made is what to tell customers and others whose personal data may have been compromised by a computer incident. Many organizations are tempted to conceal such information for fear of bad publicity and loss of customers. Because such inaction is perceived by many to be unethical and harmful, a number of state and federal laws have been passed to force organizatiosn to reveal when customer data have been breached.
An organization should document all details of a security incident as it works to resolve the incident. Documentation captures valuable evidence for a future prosecution and provides data to help during the incident eradication and follow-up phases. It is especially important to capture all system events, the specific actions taken (what, when, and who), and all external conversations (what, when, and who) in a logbook. Because this may become court evidence, an organization should establish a set of document-handling procedures using the legal department as a resource.
Often, it is necessary to act quickly to contain an attack and to keep a bad situation from becoming even worse. The incident response plan should clearly define the process for deciding if an attack is dangerouos enough to warrant shutting down or disconnecting critical systems from the network. How such decisions are made, how fast they are made, and who makes them are all elements of an effective response plan.
Before the IT security group begins the eradication effort, it must collect and log all possible criminal evidence from the system and then verify that all necessary backups are current, complete, and free of any malware. Creating a forensic disk image of each compromised system on write-only media both for later study and as evidence can be very useful. After virus eradication, a new backup must be created. Throughout this process, a log should be kept of all actions taken. This will prove helpful during the incident follow-up phase and ensure that the problem does not recur. It is imperative to back up critical applicatiosn and data regularly. Many organizations, however, have implemented inadequate backup processes and found that they could not fully restore original data after a security incident. All backups should be created with enough frequency to enable a full and quick restoration of data if an attack destroys the original, and this process must be tested to confirm that it works.
Of course, an essential part of follow-up is to determine how the organization’s security was compromised so that it does not happen again. Often the fix is as simple as getting a software patch from a product vendor. However, it is important to look deeper than the immediate fix to discover why the incident occurred. If a simple software fix could have prevented the incident, then why wasn’t the fix installed before the incident occurred?
A review should be conducted after an incident to determine exactly what happend and to evaluate how the organization responded. One approach is to write a formal incident report that includes a detailed chronology of events and the impact of the incident. This report should identify any mistakes so that they are not repeated in the future. The experience from this incident should be used to update and revise the security incident response plan.
The key elements of a formal incident report should include the following:
IP address and name of host computer(s) involved;
The date and time when the incident was discovered;
How the incident was discovered;
The method used to gain access to the host computer;
A detailed discussion of vulnerabilities that were exploited;
A determination of whether or not the host was compromised as a result of the attack;
The nature of the data stored on the computer (customer, employee, financial, etc);
A determination of whether the accessed data are considered personal, private, or confidential;
The number of hours the system was down;
The overall impact on the business;
An estimate of total monetary damage from the incident;
A detailed chronology of all events associated with the incident.
Creating a detailed chronology of all events will also document the incident for possible later prosecution. To this end, it is critical to develop an estimate of the monetary damange. Potential costs include loss of revenue, loss in productivity, and the salaries of people working to address the incident, along with the cost to replace data, software, and hardware.
Another important issue is the amount of effort that should be put into capturing the perpetrator. If a website was simply defaced, it is easy to fix or restore the site’s HTML. However, what if the intruders inflicted more serious damage, such as erasing proprietary program source code or the contents of key corporate databases? What if they stole company trade secrets? Expert crackers can conceal their identity, and tracking them down can take a long time as well as a tremendous amount of corporate resources.
The potential for negative publicity must also be considered. Public discussion of security attacks through public trials and the associated publicity has not only enormous potential costs in public relations but real monetary costs as well. For example, a bank or brokerage firm might lose customers who learn of an attack and think their money or records aren’t secure. Even if a company decides that the negative publicity risk is worth it and goes after the perpetrator, documents containing proprietary infomration that must be provided to the court could cause even greater security threats in the future. On the other hand, an organization must consider whether it has an ethical or legal duty to inform customers or clients of a cyberattack that may have put their personal data or financial resources at risk.
Keeping up with computer criminals—and with new laws and regulations—can be daunting for organizations. Criminal hackers are constantly poking and prodding, trying to breach the security defenses of organizations. Also, laws such as HIPAA, Sarbanes-Oxley, and the USA Patriot Act require businesses to prove that they are securing their data. For most small and mid-sized organizations, the level of in-house network security expertise needed to protect their business operations is too costly to acquire and maintain. As a result, many organizations outsource their network security operations to a managed security service provider (MSSP), which is a company that monitors, manages, and maintains computer and network security for other organizations. MSSPs include such companies as AT&T, Computer Sciences Corporation, Dell SecureWorks, IBM, Symantec, and Verizon. MSSPs provide a valuable service for IT departments drowning in reams of alerts and false alarms coming from VPNs; antivirus, firewall, and IDSs; and other security-monitoring systems. In addition, some MSSPs provide vulnerability scanning and web blocking and filtering capabilities.
Computer forensics is a discipline that combines elements of law and computer science to identify, collect, examine, and preserve data from computer systems, networks, and storage devices in a manner that preserves the integrity of the data gathered so that it is admissible as evidence in a court of law. A computer forensics investigation may be opened in response to a criminal investigation or civil litigation. It may also be launched for a variety of othe reasons, for example, to retrace steps taken when a data have been lost, to assess damage following a computer incident, to investigate the unauthorized disclosure of personal or corporate confidential data, or to confirm or evaluate the impact of industrial espionage.
Computer forensics investigators work as a team to investigate an incident and conduct forensic analysis by using various methodologies and tools to ensure the computer network system is secure in an organization.
Proper handling of a computer forensics investigation is the key to fighting computer crime successfully in court. In addition, extensive training and certification increases the stature of a computer forensics investigator in a court of law. Numerous certifications relate to computer forensics, including the CGE (Certified Computer Examiner), CISSP (Certified Information Systems Security Professional), CSFA (CyberSecurity Forensic Analyst), and GCFA (Global Information Assurance Certification Certified Forensics Analyst). The EnCE Certified Examiner program certifies professionals who have mastered computer investigation methods as well as the use of Guidance Software’s EnCase comptuer forensic software. Numerous universities (both online and traditional) offer degrees specializing in computer forensics. Such degree programs should include training in accounting, particularly auditing, as this is very useful in the investigation of cases involving fraud.
Question |
|---|
Has a risk assessment been performed to identify investments in time and resources that can protect the organization from its most likely and most serious threats? |
Have senior management and employees involved in implementing security measures been educated about the concept of reasonable assurance? |
Has a security policy been formulated and broadly shared throughout the organization? |
Have automated systems policies been implemented that mirror written policies? |
Does the security policy address the following?
|
Is there an effective security education program for employees and contract workers? |
Has a multi-layered CIA strategy been implemented? |
Has a firewall been installed? |
Is antivirus software installed on all personal computers? |
Have precautions been taken to limit the impact of malicious insiders? |
Are the accounts, passwords, and login IDs of former employees promptly deleted? |
Are employee responsibilities adequately defined and separated? |
Are individual roles defined so that users have authority to perform their responsibilities and nothing more? |
Is it a requirement to review at least quarterly the most critical Internet security threats and implement safeguards against them? |
Has it been verified that backup processes for critical software and databases work correctly? |
Has an intrusion detection system been implemented to catch intruders in the act—both in the network and on critical computers on the network? |
Are periodic IT security audits conducted? |
Has a comprehensive incident response plan been developed? |
Hsa the security plan been reviewed and approved by legal and senior management? |
Does the plan address all of the following areas?
|
Glossary#
- Application macro language#
A specialized programming or command language built into a software program to automate repetitive tasks and control the application’s features.
- Backdoor#
A secret, hidden method that bypasses normal security and authentication processes to access a system or data.
- Bogus#
Data, packets, or code that is fake, incorrect, broken, or sent from an invalid source.
- Bring Your Own Device#
A set of workplace rules that lets employees use their personal phones, tablets, or laptops to do work and access company networks.
- Cloud computing#
The delivery of computing services—including data storage, servers, databases, networking, and software—over the Internet on an on-demand basis.
- Con artist#
A person who deceives and manipulates others to steal their money, property, or sensitive data through a false sense of trust.
- Counterfeit#
Unauthorized, fake software, hardware, or digital goods make to look authentic and sold to deceive buyers into thinking they are genuine.
- Cyber attack#
A deliberate attempt by malicious actors to gain unauthorized access to, disrupt, steal, or destroy computer systems, networks, or digital data.
- Delineates#
To describe, draw, or explain something with exact detail, or to mark the physical boundaries and outlines of an object or area.
- Divulging#
The act of making secret, private, or sensitive information known to other people.
- End-user#
The ultimate person who uses a software application, hardware device, or computer system for its intended practical purpose.
- Entry point#
The specific vulnerability, device, or pathway that an attacker uses to gain initialized unauthorized access to a system, network, or application.
- Espionage#
The act of secretly collecting confidential, classified, or military information without authorization.
- Exploit#
A piece of code, a tool, or a technique that takes advantage of a security flaw or vulnerability in a system, software, or hardware.
- Firewall#
A network security device that monitors and filters incoming and outgoing network traffic based on preset safety rules.
- Gateway#
A hardware or software that links two different computer networks together. It translates data from one network protocol so it can travel safely to another, like connecting a home network to the Internet.
- Image log#
A recorded copy of data pages or records showing their state before (before-image) or after (after-image) a modification is made.
- Incremental backup#
A data protection method that copies only the files or data blocks created or changed since the most recent backup of any kind.
- Incursion#
More commonly referred to as a cyber intruction or system breach; an unauthorized electronic entry or attack that penetrates a network, database, or computer system’s security boundaries.
- Internet Relay Chat#
A real-time, text-based communication protocol used for group discussions and private messaging.
- Internet Service Provider#
A company that gives individuals, homes, and businesses access to the Internet.
- Macro#
A single rule, pattern, or instruction that automatically expands into a larger sequence of commands or code.
- Mainframe computer#
A high-performance, ultra-reliable enterprise system built to process massive volumnes of real-time transactions and bulk data securely for large organizations.
- Outbound data#
Information or traffix that originates inside a private network, device, or system and moves outward toward an external destination on the public Internet.
- Patch#
A piece of software code released by a vendor to fix a specific security flaw, bug, or vulnerability in an existing program or operating system.
- Penetration Test#
A simulated, authorized cyberattack on a computer system, network, or application designed to find weak spots before malicious hackers can exploit them.
- Phony#
Something that is fake and not real, or an insincere person who tries to trick others.
- Prevalence#
The state or fact of being widespread, common, or happening often.
- Prosecute#
Refers to the legal process of initiating and conducting criminal proceedings against individuals or groups who commit digital crimes.
- Ransom#
A payment demanded by cybercriminals to restore access to a locked device or encrypted data. It is the core financial demand made during a Ransomware attack.
- Reconnaissance#
The preliminary phase of getting information about a target system, network, or organization to identify vulnerabilities and plan a potential breach.
- Registry key#
A folder-like container in the Windows registry database that stores configuration settings and othe keys.
- Safeguard#
Any action, device, policy, or technical control used to reduce vulnerabilities and protect computer systems, networks, and data from harm, damage, or unauthorized access.
- Security audit#
A systematic, independent evaluation of an organization’s security infrastructure, policies, controls, and operations to identify vulnerabilities and ensure regulatory compliance.
- Security breach#
Any incident where an unauthorized party gains access to a computer system, network, application, or device..
- Security Vulnerability#
A weakness or flaw in a system, software, hardware, or process that an attacker can exploit to compromise data security or gain unauthorized access.
- Surreptitiously#
Actions taken by software, hackers, or systems secretly, stealthily, and without the user’s knowledge or consent.
- Trade secret#
Any confidential technical or commercial information—such as source code, proprietary algorithms, or internal software architecture—that gives a business a competitive advantage and is actively kept secret.
- Ubiquitous#
Technology, data, or connectivity are present, accessible, and active everywhere at all times.
- Virtualization#
A technology that uses software to create a simulated, or virtual, version of a physical computer system, server, storage device, or network.
- Virtual Private Network#
A service that creates a safe, encrypted connection between your device and the Internet.
- Vulnerabilities Equities Process#
A U.S. government interagency framework used to decide whether to disclose a newly discovered zero-day software flaw to a vendor for patching or to withhold it for national security and law enforcement operations.
- Zero-day Exploit#
A cyberattack that targets a software or hardware flaw before the developer knows about the problem or has a chance to fix it.