Transcription of Guide to Data -Centric System Threat Modeling
1 Draft NIST Special Publication 800-154 1 2 Guide to data -Centric System 3 Threat Modeling 4 5 6 7 Murugiah Souppaya 8 Karen Scarfone 9 10 11 12 13 14 15 16 C O M P U T E R S E C U R I T Y 17 18 19 Draft NIST Special Publication 800-154 20 21 22 Guide to data -Centric System 23 Threat Modeling 24 25 26 Murugiah Souppaya 27 Computer Security Division 28 Information Technology Laboratory 29 30 Karen Scarfone 31 Scarfone Cybersecurity 32 Clifton, VA 33 34 35 36 37 38 39 40 March 2016 41 42 43 44 45 46 Department of Commerce 47 Penny Pritzker, Secretary 48 49 National Institute of Standards and Technology 50 Willie May, Under Secretary of Commerce for Standards and Technology and Director 51 i Authority 52 This publication has been developed by NIST in accordance with its statutory responsibilities under the 53 Federal Information Security Modernization Act (FISMA) of 2014, 44 3541 et seq.
2 , Public Law 54 ( ) 113-283. NIST is responsible for developing information security standards and guidelines, 55 including minimum requirements for federal information systems, but such standards and guidelines shall 56 not apply to national security systems without the express approval of appropriate federal officials 57 exercising policy authority over such systems. This guideline is consistent with the requirements of the 58 Office of Management and Budget (OMB) Circular A-130. 59 Nothing in this publication should be taken to contradict the standards and guidelines made mandatory 60 and binding on federal agencies by the Secretary of Commerce under statutory authority. Nor should 61 these guidelines be interpreted as altering or superseding the existing authorities of the Secretary of 62 Commerce, Director of the OMB, or any other federal official. This publication may be used by 63 nongovernmental organizations on a voluntary basis and is not subject to copyright in the United States.
3 64 Attribution would, however, be appreciated by NIST. 65 National Institute of Standards and Technology Special Publication 800-154 66 Natl. Inst. Stand. Technol. Spec. Publ. 800-154, 25 pages (March 2016) 67 CODEN: NSPUE2 68 Certain commercial entities, equipment, or materials may be identified in this document in order to describe an 69 experimental procedure or concept adequately. Such identification is not intended to imply recommendation or 70 endorsement by NIST, nor is it intended to imply that the entities, materials, or equipment are necessarily the best 71 available for the purpose. 72 There may be references in this publication to other publications currently under development by NIST in 73 accordance with its assigned statutory responsibilities. The information in this publication, including concepts and 74 methodologies, may be used by federal agencies even before the completion of such companion publications.
4 Thus, 75 until each publication is completed, current requirements, guidelines, and procedures, where they exist, remain 76 operative. For planning and transition purposes, federal agencies may wish to closely follow the development of 77 these new publications by NIST. 78 Organizations are encouraged to review all draft publications during public comment periods and provide feedback 79 to NIST. Many NIST cybersecurity publications, other than the ones noted above, are available at 80 81 82 Public comment period: March 14, 2016 through April 15, 2016 83 All comments are subject to release under the Freedom of Information Act (FOIA). 84 National Institute of Standards and Technology 85 Attn: Computer Security Division, Information Technology Laboratory 86 100 Bureau Drive (Mail Stop 8930) Gaithersburg, MD 20899-8930 87 Email: 88 89 ii Reports on Computer Systems Technology 90 The Information Technology Laboratory (ITL) at the National Institute of Standards and Technology 91 (NIST) promotes the economy and public welfare by providing technical leadership for the Nation s 92 measurement and standards infrastructure.
5 ITL develops tests, test methods, reference data , proof of 93 concept implementations, and technical analyses to advance the development and productive use of 94 information technology. ITL s responsibilities include the development of management, administrative, 95 technical, and physical standards and guidelines for the cost-effective security and privacy of other than 96 national security-related information in federal information systems. The Special Publication 800-series 97 reports on ITL s research, guidelines, and outreach efforts in information System security, and its 98 collaborative activities with industry, government, and academic organizations. 99 100 Abstract 101 Threat Modeling is a form of risk assessment that models aspects of the attack and defense sides of a 102 particular logical entity, such as a piece of data , an application, a host, a System , or an environment. This 103 publication examines data -Centric System Threat Modeling , which is Threat Modeling that is focused on 104 protecting particular types of data within systems.
6 The publication provides information on the basics of 105 data -Centric System Threat Modeling so that organizations can successfully use it as part of their risk 106 management processes. The general methodology provided by the publication is not intended to replace 107 existing methodologies, but rather to define fundamental principles that should be part of any sound data -108 centric System Threat Modeling methodology. 109 110 Keywords 111 data security; information security; risk assessment; risk management; Threat Modeling ; threats; 112 vulnerabilities 113 114 Trademark Information 115 All trademarks or registered trademarks belong to their respective organizations. 116 117 Acknowledgments 118 The authors, Murugiah Souppaya of the National Institute of Standards and Technology (NIST) and 119 Karen Scarfone of Scarfone Cybersecurity, wish to thank their colleagues who reviewed drafts of this 120 document and contributed to its technical content.
7 121 122 iii Table of Contents 123 Executive Summary .. 1 124 1. Introduction .. 2 125 Purpose and Scope .. 2 126 Audience .. 2 127 Document Structure .. 2 128 2. Attack and Defense Basics .. 3 129 The Attack Side .. 3 130 Vulnerability .. 3 131 Exploit and Attack .. 4 132 Attack Vector .. 5 133 Threat .. 6 134 The Defense Side .. 7 135 Risk .. 7 136 Security Controls .. 7 137 Security Objectives .. 7 138 3. Introduction to System and data -Centric System Threat Modeling .. 9 139 4. Basics of data -Centric System Threat Modeling ..11 140 Step 1: Identify and Characterize the System and data of Interest .. 11 141 Step 2: Identify and Select the Attack Vectors to Be Included in the Model .. 13 142 Step 3: Characterize the Security Controls for Mitigating the Attack Vectors .. 14 143 Step 4: Analyze the Threat Model .. 16 144 Customizing the data -Centric System Threat Modeling Approach.
8 17 145 146 List of Appendices 147 Appendix A Acronyms and Other Abbreviations ..19 148 Appendix B References ..20 149 150 151 NIST SP 800-154 (DRAFT) Guide TO data -Centric System Threat Modeling 1 Executive Summary 152 Threat Modeling is a form of risk assessment that models aspects of the attack and defense sides of a 153 particular logical entity, such as a piece of data , an application, a host, a System , or an environment. The 154 fundamental principle underlying Threat Modeling is that there are always limited resources for security 155 and it is necessary to determine how to use those limited resources effectively. There are many types of 156 Threat Modeling ; for example, System Threat Modeling is Threat Modeling performed for operational 157 systems to improve their overall security. This publication focuses on one type of System Threat Modeling : 158 data -Centric System Threat Modeling .
9 data -Centric System Threat Modeling is Threat Modeling that is 159 focused on protecting particular types of data within systems. 160 Threat Modeling is needed because of the dynamic nature of security. The attack and defense sides of 161 security are constantly changing. As part of handling this change, organizations should continually 162 reassess and evolve their defenses. This includes adopting continuous monitoring practices, security 163 automation technologies, and Threat intelligence feeds to detect new vulnerabilities and attacks in near-164 real-time, allowing rapid risk mitigation. Another key component of handling the constant change in 165 security is having security metrics; these can be used for more informed decision making, again often 166 relating to risk management in general and risk mitigation in particular. 167 Increasingly, simply following general best practices for security is insufficient for safeguarding high-168 value data .
10 Best practices are largely based on conventional wisdom intended to mitigate common threats 169 and vulnerabilities. By their very nature, such best practices are generalized, especially for ubiquitous 170 products (web browsers, server and desktop operating systems, etc.) They do not take into account the 171 unique characteristics of each System . Also, most best practices are geared toward preventing host 172 compromise and do not take into account the security needs for particular data (again, a more generalized 173 goal versus a specific one). So, for a particular situation, best practices may not include security controls 174 that are necessary to effectively reduce risk. 175 data -Centric System Threat Modeling allows organizations to consider the security needs of each case of 176 interest, instead of relying solely on generalized best practice recommendations. Organizations with 177 strong capabilities in continuous monitoring, security automation, and security metrics should consider 178 adding data -Centric System Threat Modeling based on the principles presented in this publication to 179 supplement these capabilities and achieve demonstrably better security for data of particular importance.