Why Risk Management? Enterprise Risk Management has become a mandated business function involving the security of the entire organization. If you are tasked with designing an ERM you may be wondering “is my goal to determine if we are secure or if we can enable a more secure enterprise?  Am I expected to engage business partners, provide meaningful metrics, to inform choices and decisions? Does the organization expect me to account for security responsibilities or am I the provider of a business service?"

… “yes”

This presentation is the largest body of work that we've committed to training. It takes 6 hours to deliver and involves quite a bit of discussion and activities. We hope you get some great ideas and encouragement.

Yes, if you are registered, you can have the PDF. This and all of our collateral will be made available to our clients and future clients in the EnterpriseGRC Reading Room.

Registration opens February First, 2022. 

For now, we are sifting through several thousand pages of content to assure they are the most current and secure version of Adobe Acrobat. You'd be surprised what people can stuff in an old SWF or PDF, and you'd be sickened to find all the vulnerabilities on the endpoint of free marketing tools.

Aligning Enterprise Cyber & Security Risk Management - EnterpriseGRC Solutions Risk Management and GRC Support Solution

The content

  • Proposed ERM Solution for Cybersecure Enterprises
  • Agenda
  • Why Risk Management?
  • Minimizing material loss: Fraud, critical system failure, political damage, missed strategic milestones or significant loss of revenue.
  • Ensures delivery of risk information to the business
  • Enable business decisions via process for capturing, analyzing, mitigating and monitoring risks to the business
  • Provide a unified management process for risk response
  • Cyber Risk: What could go wrong?
  • Reputation is a main target for cyber attacks
  • Criminals value information – financial, health, critical infrastructure
  • Cyber risk is challenging to understand and address
  • Increased regulation over highly dispersed data
  • Pace of technology change increases unknown dependency on third parties and shadow IT
  • Capacity to trace our data making it harder to detect exfiltration
  • The increased role of government and information custody results in enormous potential for financial sanctions
  • Net Neutrality is no longer neutral
  • Too Many Industries Mandates
  • Why focus on the value of implementing Cybersecurity Oversight and Enterprise Risk Management
  • Reduce operational expense through streamlined control structures
  • Identifies cross-enterprise risks
  • Aligns risk appetite and corporate strategy
  • Enhance efficient risk response and rapid consistent decisions
  • Seize opportunities to prevent the loss, rather than repair loss
  • Align Process & Cybersecurity Tags to an Integrated Risk Approach

Risk Management goals include common security & information management practices found across enterprise management regulation and standards

  • One Common Conceptual ERM Approach uses NIST Framework for Improving Critical Infrastructure Cybersecurity
  • NIST CSF (Cyber Security Framework) provides a cyber security model

Like International CIS Critical Controls, other countries and the 28 member states of the EU, (such as United Kingdom and Australia), provide national cybersecurity strategy in the form of mandates, regulations and guidance.

  • Another approach to ERM involves using Center for Internet Security’s Critical Security Controls – they are mapped!
  • CIS – NIST CSF – FedRAMP /NIST 800-53 – ISO27002 – GDPR – PCI – SOC 2 Share Common Risk Control Requirements; Leverage Unified Approach
  • Cybersecurity Governance & Committee Approach
  • Success Factors – Cybersecurity & Governance Committee
  • Methodology is simple and understood
  • The approach is proven and tested
  • Action plans are monitored and measured, using management processes already in place
  • Governance approach is clear, endorsed by leadership, sustains continuous corporate interests.
  • Governance & Risk Management program adapts to the organization’s culture

GRC Requires a Balanced Approach

  • Phase I. Establish Enterprise Risk Management
    Map to Security Risk & Compliance and Program Infrastructure
  • Risk Management Process - Purpose and Scope
  • GRC via Facilitated Compliance Management (FCM)
  • Cybersecurity Risk Oversight – Highs and Lows
  • Initial program matures from spreadsheets to GRC Application – is not robust, depends on a few highly skilled individuals, checks the boxes but doesn’t really move the needle to affect a more secure organization
  • Moderate Maturity small to mid-size enterprise – outsourced ERM, up to 3 yearly audit events, can leverage a reporting product but isn’t heavily integrated to cybersecurity channels and enterprise security architecture
  • Moderate to High Maturity: Enterprise GRC application sources from Legal, Corporate, and InfoSec, dedicated staff, supplies 4 or more audit types, Integrated GRC channels reflects the full Security Architecture, Continuous Monitoring, Risk-Based Automated Controls.

Corporate Risk

  • External Risks – Global and Economy
  • Cost Risks
  • Schedule Risks
  • Cyber & Technology Risks
  • Operational Risks
  • Legal and Regulatory Risks
  • Market Risks
  • Project Risk (Cost)
  • Cost Risks: directly or indirectly under the project manager's control or within his or her area of influence
  • Cost overruns by project teams or subcontractors, vendors, and consultants
  • Scope creep, expansion, and change that has not been managed
  • Poor estimating or errors that result in unforeseen costs
  • Overrun of budget and schedule
  • Schedule Risks: can cause project failure by missing or delaying a market opportunity for a product or service.
  • Inaccurate estimating, resulting in errors
  • Increased effort to solve technical, operational, and external problems
  • Resource shortfalls, including staffing delays, insufficient resources, and unrealistic expectations of assigned resources
  • Unplanned resource assignment--loss of staff to other, higher priority projects
  • Enterprise Risk Management Channels

Enterprise Risk

  • Problems with immature technology
  • Use of the wrong tools
  • Software that is untested or fails to work properly, Requirement changes with no change management
  • Failure to understand or account for product complexity
  • Integration problems
  • Software/hardware performance issues--poor response times, bugs, errors
  • Inadequate resolution of priorities or conflicts
  • Failure to designate authority to key people
  • Insufficient communication or lack of communication plan,
  • Size of transaction volumes--too great or too small
  • Rollout and implementation risks--too much, too soon
  • Access Control Administration
  • Firewall Policy Administration
  • Security Incident Detection
  • Security Incident Response
  • Security Policy Awareness
  • Data Backup
  • Data Recovery
  • Threat & Vulnerability Monitoring and Management
  • Virus Control
  • Business disruption, the inability of the client to access business services
  • Business failure, the inability of internal operations to process any business process
  • Increase in software licensing cost, or unanticipated software licensing cost
  • Increase in hardware-related expense or unanticipated hardware expense
  • Hardware Software Integration or compatibility issues
  • Network/LAN availability including general and secure access to file shares
  • Personnel resource and availability, general attendance by consultants and internal employees
  • Loss of key personnel due to illness, resignation or reassignment
  • Change in market impacting fiscal viability of engagement
  • Natural disaster such as flood or fire

Mature Cybersecurity Translates Monitored Enterprise Activities to Control Domains and Program Objectives

  • Identify – CMDB, People, Process, Technology, relationships, alignment to controls
  • Protect – Architecture, Infrastructure, Monitoring
  • Detect – Defined Sources, Collection, Interpretation, Reporting Methods
  • Respond – RCA, Corrective Action, Management Meetings, Plans, Optimization Targets
  • Recover – Configuration baselines, response plans, lessons learned, documentation, BIA

Outputs of a functioning Cybersecurity & Enterprise Risk Management Process

  • Threats are identified and categorized to risks
  • Events are captured and reported
  • Risks have context
  • Risk Treatment provides for risk analysis
  • Risk response plans - Treat risks
  • Routine activities evaluate risk and their treatment
  • Monitor and review
  • Communicate and consult – GC committee
  • Tools, Process, Measures, and Continuous Improvement

Looking for weaknesses and vulnerabilities is good but failing to adapt process and culture based on those findings is bad

  • Phase II. Assess Cybersecurity and Business Risk
  • Security Assessment
  • Security assessment is comprehensive review of systems and applications performed by trained security professionals (CISSP/ CCIE/ CCNA/ CISM)
  • Security assessments normally include use of testing tools and goes beyond automated scanning
  • Involves thoughtful review of the threat environment, current and future risk, and value definition of the targeted environments
  • The output of assessment is a report addressed to management with recommendations in both technical and non technical language
  • Audit velocity increases resilience
  • An approach: Find a flaw, fix a flaw
  • Approach: Find a lot of flaws and keep a list
  • Best approach: align vulnerability metrics into a continual service improvement model

Auditing Security Assessment & Verification

  • Compliance checks
  • Internal and external
  • Frequency of review
  • Standard of due care

Internal Audit typically performs an assessment for internal audience

External Audits are performed for external investors and as part of third-party due diligence requirements

Third Party review is emphasized to avoid “conflict of interest”

  • At Moderate Maturity, GRC/ERM includes Incident Response and Continuous Improvement
  • Phase II: Assess Cybersecurity and Business Risk
  • Communicating Risk- Inputs and Agenda
  • Execute – Program, Meetings, Risk Response
  • Measure – Risk Measurement & Impact Analysis, Performance
  • Record – Meeting Minutes, Management Reporting
  • Archive – Meeting Minutes, KPI Results
  • Enterprise Risk Management Can Start Small. To be effective you need a GRC.
  • Phase II. Assessing Business Risk - Tools and Deliverables

RiskWatch is a free POC tool offered in our consulting practice.  We use it to stage risk information that is implemented to fully functioning GRC products.  It is not meant to take the place of the selected GRC tool.

  • Significance of Risk – Analyze the Risks - So What?
  • Risk analysis determines cadence + magnitude of events and their consequences.
  • The significance of risk is consequence or impact on business objectives
  • Consequence and likelihood may be accounted for using a qualitative, semi-qualitative or quantitative approach.
  • The likelihood criteria are expressed as a probability of the annual occurrence on a descriptive scale from rare to almost certain. Impact is described on a scale from 1 insignificant to 5 catastrophic.
  • Significance as a scale of 1 to 5 in Likelihood factored against a scale of 1 to 5 in Impact.
  • On a scale of 1 to 25, the organization can establish criteria for action and a matrix of activity that would meet that criterion.
  • Phase II Tool: Risk Heat Map
  • Phase III. Develop Risk Response
  • Responsibilities that must be adopted
  • Phase III. Develop Risk Response

Key activities within this phase

  • Determine appropriate risk response
  • Key Outputs

Risk Management Action Plans

  1. Phase III. Develop Risk Response
  2. Risk Mitigation
  3. Phase III: we collectively define our risk appetite
  4. Risk management demonstrates a methodology and criteria
  5. Risk management provides evidence of the criteria behind our choices
  6. Corporate Risk Management Tools address
  7. Corporate level reviews company-specific risk
  8. Assignment of relative risk criteria
  9. Owner communicates risk to shareholders
  10. Governs how corporate leadership interprets & assigns weighted value
  11. Initial risk assessment & accountability rests at the individual company level
  12. Disclosure committee reviews & determines disclosure requirements

Risks and Response - Ongoing Risk Tracking

  1. respond
  2. report
  3. reduce

Technology Risk Tracking – by Service, Asset, Policy

  1. technology Controls Map
  2. report Classification
  3. key Vs. Non-Key
  4. definition of Terms and Controls
  • Project Risk Management
  • Facilitates the effective management of risk within an enterprise project
  • Enables project team to collaborate in

 Identifying risk, analyzing risk, and planning appropriate actions. 

  • Risk-related actions are planned, scheduled and tracked as additional tasks in the project plan
  • Risk tracking occurs in a risk watch list
  • On-going activity throughout the project
  • Depends on all project team members being risk-aware, utilizing the defined risk management process
  • Phase IV. Implement and Monitor
  • Integrated Evidence for ISO27001+ISO27017, SOC 2, HITRUST, PCI-DSS ROC
  • Mature Enterprises, Harmonize Control Frameworks, Risk Based Approach
  • Risk Response requires cybersecurity programs
  • Incident Response
  • Security Playbooks
  • Computer Security Incident Response Team (CSIRT)
  • Event Analysis (CSIRT EA) tuning meeting
  • Investigation's meeting
  • Operations and Engineering biweekly and monthly meetings
  • Delivery and Implementation meetings
  • Threat Intelligence meetings
  • Threat and Vulnerability Management
  • Configuration Management: Secure Host Baseline Config

Let’s take out a high-profile target

  1. Get access to the target’s outlook calendar (schedule)
  2. Discover the route they travel (location)
  3. Get fake uniforms so we blend in (identity)
  4. Distract the guards (opportunity)
  5. Interrupt the live camera feed so they don’t see us (time)
  6. Purchase a weapon that can’t be traced (malware, spyware…)
  7. Go – Go – Go: Take out the target

Burn down the structure so there’s nothing left, or just encrypt everything and sell the target their own key. (ransomware)

  • A successful kill only requires 5 elements
  • Systems & Configuration Management Objective
  • Incidents Require Root Cause Analysis
  • What is the root cause for any failure?
  • Example: “metrics indicate 80% of malicious code infections are attributed to vulnerable versions of Java”
  • What were the steps to create the finding?
  • What are the expectations as a result of this finding?
  • What is the measure of Security Program health?

Products and Systems Require Technical Risk Assessment

  • Looking for security weaknesses
  • Vulnerability Assessment
  • Network Penetration Testing
  • Web Application Penetration Testing
  • Source Code Analysis
  • Vulnerability Assessment
  • Scanning systems looking for a set of vulnerabilities (a list)
  • Looks for common and known vulnerabilities
  • Uses a scanning tool
  • Performed in house and by third party

Let’s look at common and recommended scanning tools. 

Source is OWASP

  • OWASP Listed Vulnerability Scanning Tools
  • OWASP Listed Vulnerability Scanning Tools
  • What to do with a list of known vulnerabilities
  • Scanners provide a score of 1 to 5 (relative to what?)
  • CVSS Common Vulnerability Scoring System is the method used to classify
  • OCTAVE Operational Critical Threat, Asset, and Vulnerability Evaluation

OCTAVE defines three phases, is criticized as complex, and not provide a detailed quantitative analysis of security exposure.

  • Penetration Tests
  • Red Team Exercises or Ethical Hacking – (Yes, I’m compelled to talk about blue team, but not yet.)
  • We know we have flaws - pen test seeks to exploit them
  • Simulates attacker (does not cause harm)
  • Output: Identification of susceptible assets (sites)
  • In short: As good as the people who perform them and as valuable as the reduced risk on the items that get remediated
  • Penetration Testing – Operations Evaluation
  • War Dialing (looking for modems – especially plugged into older enterprise hardware)
  • Eavesdropping
  • Radiation monitoring
  • Dumpster diving
  • Social Engineering
  • Sniffing – Wireshark -Configuring a monitor port on a managed switch - network tap
  • You typically insert a network tap inline between two nodes in a network, such as between your firewall and your first switch. $$$ Not typically in audit budget

Stuff U Need 2 Read

  • International Organization for Standardization, Risk management – Principles and guidelines, ISO 31000:2009, 2009. http://www.iso.org/iso/home/standards/iso31000.htm
  • International Organization for Standardization/International Electrotechnical Commission, Information technology – Security techniques – Information security risk management, ISO/IEC 27005:2011, 2011. http://www.iso.org/iso/catalogue_detail?csnumber=56742
  • Joint Task Force Transformation Initiative, Managing Information Security Risk: Organization, Mission, and Information System View, NIST Special Publication 800-39, March 2011. http://csrc.nist.gov/publications/nistpubs/800-39/SP800-39-final.pdf
  • U.S. Department of Energy, Electricity Subsector Cybersecurity Risk Management Process, DOE/OE-0003, May 2012. http://energy.gov/sites/prod/files/Cybersecurity%20Risk%20Management%20Process%20Guideline%20%20Final%20-%20May%202012.pdf
  • Technical Security Testing: Assesses risk by discovering flaws that persist in systems and applications
  • Technical testing is looking for security flaws, specifically impacts to confidentiality, integrity or availability, ways to steal, alter or destroy information
  • Vulnerability Assessments are looking for weakness
  • Penetration testing adds human factor
  • Code review includes errors that make it susceptible, e.g., to buffer overflow, SQL insertion, etc.
  • Phishing is to see what users do when presented with typical malicious email scenarios
  • Password assessments evaluate password settings and practices, (sometimes as a part of scanning)
  • Risk Programs Continuously Explore and reduce Threat Vectors – A.K.A The Attack Surface
  • Methods attackers use to touch or exploit vulnerabilities
  • A systems attack surface represents all of the ways in which an attacker could attempt to introduce data to exploit a vulnerability

If you look at a list of vulnerabilities, you get too much information, so we have to start by analyzing our network, our data, evaluating our assets and their attack surface, then their vulnerabilities to known threats

  • One way to reduce risk is to minimize the attack vectors

Once we know those vectors, we remediate prioritized threats by reducing the likelihood of exploiting vulnerabilities

  • Shift in attack vectors: Server Side v. Client Side Attacks
  • Attacks against a listening service are called “Server-side attacks”
  • TCP server side attacks are initiated by an attacker (client)
  • Client-side attacks work in reverse, where victim initiates the traffic, usually by clicking on a link or email.
  • STRIDE – Microsoft Privacy Standard (MPSD) response to FIPS
  • Spoofing v. Authentication
  • Tampering v. Integrity
  • Repudiation v. Non-Repudiation
  • Information Disclosure v. Confidentiality
  • Denial of Service v. Availability
  • Elevation of Privilege v. Authorization
  • Risk Process Recap
  • Inputs, Status, Activity, Maturity, Exit Criteria, Holistic Approach
  • Risk Management and Cybersecurity has multiple triggers
  • Risk management process should be invoked for every capital or strategic program, asset, or project.
  • Risk management should commence by establishing a risk owner who is accountable to assure a risk treatment plan.
  • 3rd party Vendor dependency with significance >9 risk
  • Change request with significance >9 risk
  • Release with significance >9 risk
  • IT project with significance >9 risk
  • Application service with significance > 9 risk
  • Maintenance service with significance > 9 risk

Risk Management Workflows

  • Process Exit Criteria
  • Risk process continues until the process response is implemented
  • Risk is mitigated to acceptable managed residual risk or removed
  • Mitigated risk where significance is less than “9” & appropriate controls are identified for ongoing risk management
  • Measurements
  • Number of risk management meetings
  • Number of improvement projects
  • Number of improvements to the risk assessment process
  • Level of funding allocated to risk management projects
  • Number & frequency of updates to published Governance Committee reports
  • Risk limits & policies
  • To Sum it Up – Just Do It
  • Risks management policy signed by CISO, CFO and CIO
  • ERM & Security manager responsibilities assigned
  • Appropriate funding allocated (if required)
  • Risk awareness training
  • Meeting time and standard agenda format established
  • Support sessions to enter risk items
  • Risk meeting agenda posted
  • Risk meetings and Quarterly Governance Meetings
  • Posted risk meeting action items and notes
  • Follow up risk response

Iterate enter risks - update risks - post agenda – meeting - post notes - follow up risk response

Main Menu