Information SECURITY Risk Assessment Turning
Description: Information SECURITY Risk Assessment Turning Project in Process: Segmentation, Prioritization and Iteration Cornell University: Steve Schuster (sjs74cornell.edu) Interim Executive Director for Cornell Information Technologies Illumant,
Related Topics
Download Presentation
"Information SECURITY Risk Assessment Turning" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.
Presentation Transcript
slide1. Information SECURITY Risk Assessment Turning Project in Process: Segmentation, Prioritization and Iteration Cornell University: Steve Schuster (sjs74@cornell.edu)
Interim Executive Director for Cornell Information Technologies Illumant, LLC: Matija Siljak (siljak@illumant.com)
Director, Advisory Services<br>
slide2. Why Risk Assessment? To answer these questions:
What constitutes sensitive information?
Where is it?
How much of it is there?
How effectively is it protected?
What are the vulnerabilities that could lead to compromise?
What is the likelihood of compromise?
What is the potential impact?
What is the most effective use of protection resources?<br>
slide3. Problems with risk assessment Traditional risk assessment:
One-offs
project not process = limited ongoing benefit
Breach response
reactive not proactive = skewed expectations
Big endeavor
expensive and effort-intensive = risky project
Questionable value
predictable results and imbalanced cost-benefit = dissatisfaction<br>
slide4. Solutions Modified risk assessment:
One-offs
segment into small, independent components and iterate
Breach response
minimize time to partial results
Big endeavor
segment into small, independent components and iterate
start at a high level, drill down later based on interim results
Questionable value
minimize cost and effort and time to results, balance cost and benefit<br>
slide5. The formula remains the same:
Risk = Threat x Vulnerability x Impact
Change is to administration and expectations
Divide up the data gathering into segments
Use interim results to prioritize further tasks and where to drill down
Tolerate incompleteness, omission – circle back
Analogy: mainframe vs. linux cluster What is different?<br>
slide6. Risk assessment methodology overview<br>
slide7. Risk Assessment Process Summary Data Classification Data Types Exposure Analysis Assets (Apps, DBs, etc.) Departments and Units MAP TO MAP TO MAP TO =<br>
slide8. data classification Start with the data classification policy. Consider other potentially sensitive data, for example: Student Info
SSN/
Financial Info
Credit Card Info
Driver’s License
Protected Health Info
Academic Records Employee / Faculty (HR) Info
SSN
Payroll Info
Driver’s License
Bank Account Info
Protected Health Info Alumni and Donor Info
SSN
Credit Card Info
Driver’s License
Bank Account Info Financial Data
University Finances Point-of-Sale
Customer Credit Card Data Physical Plant
Buildings, Facilities, Utilities
Grounds Cyber Infrastructure
Access Info, Logs, LDAP Other PII
Human Subject Research
Key Performance Indicators Protected Health Info (PHI)
Info in Non-medical Systems Intellectual Property
Courseware, Research, Papers, Books, Code Library
Citation DB
Digital Full Text
Circulation<br>
slide9. data and asset inventory Map the assets to data types and locations and attempt to roughly quantify the data<br>
slide10. exposure analysis After completing the inventory exercise, identify the key assets and departments on which to focus.<br>
slide11. Vulnerabilities Risk Assessment Process Summary Controls Assessment Controls Threats Assets (Apps, DBs, etc.) Departments and Units MAP TO MAP TO = Regulations MAP TO MAP TO MAP TO<br>
slide12. threat analysis Select an appropriate threat model:
Malicious activity
Malfunction
Human error
Environmental<br>
slide13. Controls analysis Using best practice frameworks, standards, and regulations, we evaluate departmental and university controls
EDUCAUSE Risk Management Framework
Look for:
Existence
Effectiveness
Compliance New York Information Security Breach and Notification Act 2005<br>
slide14. controls analysis Start at a high level and drill down.
For example, we examine:<br>
slide15. Control Maturity Model<br>
slide16. Risk Assessment Exposure Analysis Risk Assessment Process Summary Security Roadmap Controls Assessment +<br>
slide17. Cost-Benefit Analysis Review exposures, vulnerabilities and potential impact
Create list of remediation options
Estimate costs and compare with benefits
Outline security roadmap
Identify long-range plans
Highlight action items
Quick wins
High priority exposures
Determine on-going risk assessment schedule
to revisit units and departments
Visit new units and departments
drill down on areas that need further investigation and more detail<br>
Interim Executive Director for Cornell Information Technologies Illumant, LLC: Matija Siljak (siljak@illumant.com)
Director, Advisory Services<br>
slide2. Why Risk Assessment? To answer these questions:
What constitutes sensitive information?
Where is it?
How much of it is there?
How effectively is it protected?
What are the vulnerabilities that could lead to compromise?
What is the likelihood of compromise?
What is the potential impact?
What is the most effective use of protection resources?<br>
slide3. Problems with risk assessment Traditional risk assessment:
One-offs
project not process = limited ongoing benefit
Breach response
reactive not proactive = skewed expectations
Big endeavor
expensive and effort-intensive = risky project
Questionable value
predictable results and imbalanced cost-benefit = dissatisfaction<br>
slide4. Solutions Modified risk assessment:
One-offs
segment into small, independent components and iterate
Breach response
minimize time to partial results
Big endeavor
segment into small, independent components and iterate
start at a high level, drill down later based on interim results
Questionable value
minimize cost and effort and time to results, balance cost and benefit<br>
slide5. The formula remains the same:
Risk = Threat x Vulnerability x Impact
Change is to administration and expectations
Divide up the data gathering into segments
Use interim results to prioritize further tasks and where to drill down
Tolerate incompleteness, omission – circle back
Analogy: mainframe vs. linux cluster What is different?<br>
slide6. Risk assessment methodology overview<br>
slide7. Risk Assessment Process Summary Data Classification Data Types Exposure Analysis Assets (Apps, DBs, etc.) Departments and Units MAP TO MAP TO MAP TO =<br>
slide8. data classification Start with the data classification policy. Consider other potentially sensitive data, for example: Student Info
SSN/
Financial Info
Credit Card Info
Driver’s License
Protected Health Info
Academic Records Employee / Faculty (HR) Info
SSN
Payroll Info
Driver’s License
Bank Account Info
Protected Health Info Alumni and Donor Info
SSN
Credit Card Info
Driver’s License
Bank Account Info Financial Data
University Finances Point-of-Sale
Customer Credit Card Data Physical Plant
Buildings, Facilities, Utilities
Grounds Cyber Infrastructure
Access Info, Logs, LDAP Other PII
Human Subject Research
Key Performance Indicators Protected Health Info (PHI)
Info in Non-medical Systems Intellectual Property
Courseware, Research, Papers, Books, Code Library
Citation DB
Digital Full Text
Circulation<br>
slide9. data and asset inventory Map the assets to data types and locations and attempt to roughly quantify the data<br>
slide10. exposure analysis After completing the inventory exercise, identify the key assets and departments on which to focus.<br>
slide11. Vulnerabilities Risk Assessment Process Summary Controls Assessment Controls Threats Assets (Apps, DBs, etc.) Departments and Units MAP TO MAP TO = Regulations MAP TO MAP TO MAP TO<br>
slide12. threat analysis Select an appropriate threat model:
Malicious activity
Malfunction
Human error
Environmental<br>
slide13. Controls analysis Using best practice frameworks, standards, and regulations, we evaluate departmental and university controls
EDUCAUSE Risk Management Framework
Look for:
Existence
Effectiveness
Compliance New York Information Security Breach and Notification Act 2005<br>
slide14. controls analysis Start at a high level and drill down.
For example, we examine:<br>
slide15. Control Maturity Model<br>
slide16. Risk Assessment Exposure Analysis Risk Assessment Process Summary Security Roadmap Controls Assessment +<br>
slide17. Cost-Benefit Analysis Review exposures, vulnerabilities and potential impact
Create list of remediation options
Estimate costs and compare with benefits
Outline security roadmap
Identify long-range plans
Highlight action items
Quick wins
High priority exposures
Determine on-going risk assessment schedule
to revisit units and departments
Visit new units and departments
drill down on areas that need further investigation and more detail<br>