Products and Systems Require Technical Risk Assessment
- Looking for security weaknesses
- Vulnerability Assessment
- Network Penetration Testing
- Web Application Penetration Testing
- Source Code Analysis
- Vulnerability Assessment
- Scanning systems looking for a set of vulnerabilities (a list)
- Looks for common and known vulnerabilities
- Uses a scanning tool
- Performed in house and by third party
Let’s look at common and recommended scanning tools.
Source is OWASP
- OWASP Listed Vulnerability Scanning Tools
- OWASP Listed Vulnerability Scanning Tools
- What to do with a list of known vulnerabilities
- Scanners provide a score of 1 to 5 (relative to what?)
- CVSS Common Vulnerability Scoring System is the method used to classify
- OCTAVE Operational Critical Threat, Asset, and Vulnerability Evaluation
OCTAVE defines three phases, is criticized as complex, and not provide a detailed quantitative analysis of security exposure.
- Penetration Tests
- Red Team Exercises or Ethical Hacking – (Yes, I’m compelled to talk about blue team, but not yet.)
- We know we have flaws - pen test seeks to exploit them
- Simulates attacker (does not cause harm)
- Output: Identification of susceptible assets (sites)
- In short: As good as the people who perform them and as valuable as the reduced risk on the items that get remediated
- Penetration Testing – Operations Evaluation
- War Dialing (looking for modems – especially plugged into older enterprise hardware)
- Eavesdropping
- Radiation monitoring
- Dumpster diving
- Social Engineering
- Sniffing – Wireshark -Configuring a monitor port on a managed switch - network tap
- You typically insert a network tap inline between two nodes in a network, such as between your firewall and your first switch. $$$ Not typically in audit budget
Stuff U Need 2 Read
- International Organization for Standardization, Risk management – Principles and guidelines, ISO 31000:2009, 2009. http://www.iso.org/iso/home/standards/iso31000.htm
- International Organization for Standardization/International Electrotechnical Commission, Information technology – Security techniques – Information security risk management, ISO/IEC 27005:2011, 2011. http://www.iso.org/iso/catalogue_detail?csnumber=56742
- Joint Task Force Transformation Initiative, Managing Information Security Risk: Organization, Mission, and Information System View, NIST Special Publication 800-39, March 2011. http://csrc.nist.gov/publications/nistpubs/800-39/SP800-39-final.pdf
- U.S. Department of Energy, Electricity Subsector Cybersecurity Risk Management Process, DOE/OE-0003, May 2012. http://energy.gov/sites/prod/files/Cybersecurity%20Risk%20Management%20Process%20Guideline%20%20Final%20-%20May%202012.pdf
- Technical Security Testing: Assesses risk by discovering flaws that persist in systems and applications
- Technical testing is looking for security flaws, specifically impacts to confidentiality, integrity or availability, ways to steal, alter or destroy information
- Vulnerability Assessments are looking for weakness
- Penetration testing adds human factor
- Code review includes errors that make it susceptible, e.g., to buffer overflow, SQL insertion, etc.
- Phishing is to see what users do when presented with typical malicious email scenarios
- Password assessments evaluate password settings and practices, (sometimes as a part of scanning)
- Risk Programs Continuously Explore and reduce Threat Vectors – A.K.A The Attack Surface
- Methods attackers use to touch or exploit vulnerabilities
- A systems attack surface represents all of the ways in which an attacker could attempt to introduce data to exploit a vulnerability
If you look at a list of vulnerabilities, you get too much information, so we have to start by analyzing our network, our data, evaluating our assets and their attack surface, then their vulnerabilities to known threats
- One way to reduce risk is to minimize the attack vectors
Once we know those vectors, we remediate prioritized threats by reducing the likelihood of exploiting vulnerabilities
- Shift in attack vectors: Server Side v. Client Side Attacks
- Attacks against a listening service are called “Server-side attacks”
- TCP server side attacks are initiated by an attacker (client)
- Client-side attacks work in reverse, where victim initiates the traffic, usually by clicking on a link or email.
- STRIDE – Microsoft Privacy Standard (MPSD) response to FIPS
- Spoofing v. Authentication
- Tampering v. Integrity
- Repudiation v. Non-Repudiation
- Information Disclosure v. Confidentiality
- Denial of Service v. Availability
- Elevation of Privilege v. Authorization
- Risk Process Recap
- Inputs, Status, Activity, Maturity, Exit Criteria, Holistic Approach
- Risk Management and Cybersecurity has multiple triggers
- Risk management process should be invoked for every capital or strategic program, asset, or project.
- Risk management should commence by establishing a risk owner who is accountable to assure a risk treatment plan.
- 3rd party Vendor dependency with significance >9 risk
- Change request with significance >9 risk
- Release with significance >9 risk
- IT project with significance >9 risk
- Application service with significance > 9 risk
- Maintenance service with significance > 9 risk

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics