Transcription of Identifying Information Security Threats - IT Today
1 82-10-41 Identifying Information Security ThreatsTimothy R. StaceyRonald E. HelsleyJudith V. BastonPayoffThe success of an enterprises Information Security risk-based management program isbased on the accurate identification of the Threats to the organization's Information article presents a structured approach for Identifying an enterprise-specific threatpopulation, which is an essential first step for Security planners who are involved indeveloping cost-effective strategies for addressing their organizations' Information a compliance-based Information Security program, the Information systems are designedand required to comply with a pre-determined, comprehensive set of Security , it has been shown that this type of Security program leads to the incorporation ofexpensive safeguards.
2 Some of which may be irrelevant to todays changing informationsystem architectures and threat populations. Simply, an enterprise will waste significantmoney on the implementation of inappropriate Security controls because it uses acompliance-based Information Security program. The government has recognized this areaof potential waste and has mandated that government Information systems institute risk-based Information Security migration from a compliance-based to a risk-based Information Security programshifts the responsibility to and places a significant additional burden on the local securitypractitioner. The adoption of a risk-based Information Security program requires theenterprise to become cognizant of the Threats to its Information systems and to respond withsafeguards and protection mechanisms appropriate to its set of Threats .
3 In addition, theenterprise must continually review its Security posture because of changing technologiesand the dynamic threat population. Thus, it is critical that the enterprise adopt a structuredmethodology to determine the pertinent Threats , to re-evaluate residual vulnerabilities, andto identify new the NASA community, government directives, such as the Office of Managementand Budget Circular A-130, and NASA Agency directives have placed the responsibilityfor the cost effective protection of Information systems directly with the owners ( ,managers) of the facilities. To provide guidance and support, the NASA centers haveprovided Security handbooks, such as Johnson Space Centers Automated InformationSystems Security Manual, These handbooks mandate sets of securityrequirements that, if implemented, provide.
4 A common and adequate baseline .. and .. provide adequate AIS Security protection, meet the intent of Federal and Agencyguidelines, and be consistent with good business practices. The Changing Role of the Information Security PractitionerIn a cost-containment era, it is the Information Security officers responsibility to ensure thatthe Information systems are protected adequately, yet cost effectively. The securitypractitioner is now responsible for accurately assessing the current risk levels and, whennecessary, recommending cost effective risk reduction strategies. The Security practitionercan also be held liable for failure to exercise due diligence in protecting the systems. ToPrevious screenperform these tasks, the Security practitioner must understand the Threats to theorganizations's Information High-Level Threat CategoriesFor the past several years, Information systems professionals at Rockwell SpaceOperations have employed a set of five high-level threat categories: Personnel and administrative.
5 Network. Hardware. Software. Environmental and physical these categories, 21 Threats were identified, which were used in weighing thesecurity posture of the Information systems as illustrated in Exhibit 1. From that point,approximately 450 recommended safeguards were keyed to those threat systems personnel were interviewed to determine their systems level ofcompliance to the recommended safeguards. Based on the five threat categories, a securityposture was subjectively determined, additional safeguards to be implemented wereidentified to reduce risk, a management-level briefing was prepared, and all findings Threat ListThreat Category ThreatPersonal/Administrative Threat Terroist Actions/Civil DisorderActivity for Personal GainMalicious Acts by an Individual EmployeeTampering with or Destruction of Hardware And/or Related ComponentsTheft of Hardware and/or Related ComponentsTheft of ResourcesNetwork Threat Essential Communication Line/EquipmentFailureMasquerading as an Authorized UserSniffingSpoofingWiretaping or EavesdroppingHardware Threat Essential Hardware FailureSoftware Threat Programmer/Operator ErrorEssential Software FailureMalicious Software InvasionUnauthorized access or Execution PrivilegesEnvironmental/Physical Security Threat Theft or Equipment TamperingLoss of stable Electrical PowerFacility or Equipment FireNatural DisasterTemperature/Humidity
6 ExtremesPrevious screen Threat Category ThreatPersonal/Administrative Threat Terrorist Actions/Civil Disorder Activity for Personal Gain Malicious Acts by an Individual Employee Tampering with or Destruction of Hardware And/or Related Components Theft of Hardware and/or Related Components Theft of ResourcesNetwork Threat Essential Communication Line/Equipment Failure Masquerading as an Authorized User Sniffing Spoofing Wiretapping or EavesdroppingHardware Threat Essential Hardware FailureSoftware Threat Programmer/Operator Error Essential Software Failure Malicious Software Invasion Unauthorized access or Execution PrivilegesEnvironmental/Physical Security Theft or Equipment TamperingThreat Loss of stable Electrical Power Facility or Equipment Fire Natural Disaster Temperature/Humidity ExtremesHowever, working with the five threat categories raised areas of concern.
7 Although aquasi-analytical approach in determining the perception of a systems Security posture wasattempted, the analyses became increasingly subjective. In reviewing the list of Threats ,several anomalies were noticed, which could have questioned the validity of the overallfindings. The specific areas of concern included: The threat categories were composed of a differing number of Threats ( , personneland administrative had six Threats , software had four Threats , and hardware had onlyone threat). The level of detail of the Threats seemed too uneven ( , masquerading as anauthorized user versus activity for personal gain). Some common Threats appeared to be missing ( , personnel losses). Most of the recommended safeguards mapped to the same threat category ( , themajority mapped to personnel and administrative).
8 The number of safeguards recommended (and mapped) to the threat categories wasvastly different between threat categories ( , personnel and administrative had 254recommened safegaurds, software had 149 recommended safeguards, and hardwarehad 123 recommended safeguards). The categories seemed to be composed of Threats with vastly different screenThus, a complete and balanced list of the Threats from which the Information systemscould be protected must be developed. This article describes the process, in step form, usedto formulate an enterprises threat 1 Define Terms For ConsistencyTo identify the threat population, the terms: threat, threat agent, and threat event must beconsistently defined. Threat can be defined in several ways, including: the potential forharm; any circumstances or set of circumstances with the potential to cause harm to anautomated asset; or an event or method that can potentially compromise the integrity,availability, or confidentiality of automated Information systems.
9 The process described inthis article uses the last threat agent is an individual or entity, real or perceived, that may initiate, enhance, orotherwise support a threat occurrence. Derived, from the preceding definitions, a definitionof a threat event is the manifestation of a threat. Simply, a threat becomes the what ( ,what can potentially compromise an automated Information system?). The threat agentbecomes the who ( , who can cause the automated Information systems to becompromised?). Finally, the threat event becomes the how. For example, if a threat isexercised by an agent, how, by what mechanism exactly, will the automated informationsystems be compromised? Using the preceding definitions, the task of Identifying the threatpopulation can begin. Exhibit 2 illustrates the first attempt of creating a comprehensivethreat list.
10 This list should be made up of these elements: The list should contain a limited number of Threats ( , between six and 12 to facilitatemanagement-level presentations). The list should use access permission as a major criterion ( , insider versus badgedoutsider versus outsider). The list should use motivation as a criterion ( , malicious versus accidental).Although the Threats noted in Exhibit 2 comply with the previously discusseddefinitions of threat, these observations are also evident: Some of these Threats appear too general ( , theft, hardware failure, and softwarefailure), and others seem too specific ( , unauthorized access to files by an insider). The list seems incomplete ( , power failure or fluctuation and sniffing appears to bemissing). A single threat has several threat agents ( , disaster may have been caused by naturalor human actions).