Posts

Showing posts matching the search for risk assessment

Thoughts on FAIR

Image
You knew I had risk on my mind given my recent post Economist on the Peril of Models . The fact is I just flew to Chicago to teach my last Network Security Operations class, so I took some time to read the Risk Management Insight white paper An Introduction to Factor Analysis of Information Risk (FAIR) . I needed to respond to Risk Assessment Is Not Guesswork , so I figured reading the whole FAIR document was a good start. I said in Brothers in Risk that I liked RMI's attempts to bring standardized terms to the profession, so I hope they approach this post with an open mind. I have some macro issues with FAIR as well as some micro issues. Let me start with the macro issue by asking you a question: Does breaking down a large problem into small problems, the solutions to which rely upon making guesses, result in solving the large problem more accurately? If you answer yes, you will like FAIR. If you answer no, you will not like FAIR. FAIR defines risk as Risk - the probable f...

Someone Please Explain Threats to Microsoft

Image
It's 2007 and some people still do not know the difference between a threat and a vulnerability. I know these are just the sorts of posts that make me all sorts of new friends, but nothing I say will change their minds anyway. To wit, Threat Modeling Again, Threat Modeling Rules of Thumb : As you go about filling in the threat model threat list, it’s important to consider the consequences of entering threats and mitigations. While it can be easy to find threats, it is important to realize that all threats have real-world consequences for the development team. At the end of the day, this process is about ensuring that our customer’s machines aren’t compromised. When we’re deciding which threats need mitigation, we concentrate our efforts on those where the attacker can cause real damage. When we’re threat modeling, we should ensure that we’ve identified as many of the potential threats as possible (even if you think they’re trivial). At a minimum, the threats we list that we chos...

Risk-Based Security is the Emperor's New Clothes

Donn Parker published an excellent article in the latest issue of The ISSA Journal titled Making the Case for Replacing Risk-Based Security . This article carried a curious disclaimer I had not seen in other articles: This article contains the opinions of the author, which are not necessarily the opinions of the ISSA or the ISSA Journal. I knew immediately I needed to read this article. It starts with a wonderful observation: What are we doing wrong? Is the lack of support for adequate security linked to our risk-based approach to security? Why can't we make a successful case to management to increase the support for information security to meet the needs? Part of the answer is that management deals with risk every day, and it is too easy for them to accept security risk rather than reducing it by increasing security that is inconvenient and interferes with business. I would argue that management decides to "accept security risk" because they cannot envisage the conse...

Risk, Threat, and Vulnerability 101

Image
In my last entry I took some heat from an anonymous poster who seems to think I invent definitions of security terms. I thought it might be helpful to reference discussions of terms like risk, threat, and vulnerability in various documents readers would recognize. Let's start with NIST publication SP 800-30: Risk Management Guide for Information Technology Systems . In the text we read: " Risk is a function of the likelihood of a given threat-source 's exercising a particular potential vulnerability , and the resulting impact of that adverse event on the organization. To determine the likelihood of a future adverse event, threats to an IT system must be analyzed in conjunction with the potential vulnerabilities and the controls in place for the IT system." The document outlines common threats: Natural Threats: Floods, earthquakes, tornadoes, landslides, avalanches, electrical storms, and other such events. Human Threats Events that are either enabled by or caused...

The Dynamic Duo Discuss Digital Risk

I've been reading books and looking at product literature which discuss "security," "risk," "threat," and "vulnerability," each with a different definition. I don't think these terms are difficult to understand. I wrote the hopefully amusing vignette below to communicate my understanding of these terms. At least it won't bore you! Meanwhile, at the Hall of Justice... BATMAN: Robin, why the puzzled look? ROBIN: Sorry, Batman. B: Are my Bat Ears crooked again? R: No Batman. I've been reading some books and vendor marketing literature on security, and I'm confused by their definitions of risk, vulnerability, and threat. B: Oh, you've been researching to protect the Hall of Justice computer? Good for you. Tell me why you're confused. R: I see so many people calling "vulnerabilities" and "threats" the same thing. B: That's certainly not right. A vulnerability is a weakness in an asset w...

NSA IAM and IEM Summary

Image
Two years ago I wrote Thoughts on NSA IAM Course . That post is still in the top ten Google search results for NSA IAM, which is sad because that means there isn't much about the program online. IAM stands for INFOSEC Assessment Methodology. (Ugh, I hate " INFOSEC ".) The only real material about IAM (beyond the public slides used to teach the classes appears in Security Assessment: Case Studies for Implementing the NSA IAM by Russ Rogers, Greg Miles, Ed Fuller, Ted Dykstra. The Syngress sample chapter nicely summarizes the IAM purpose and compares it to alternatives. The National Security Agency (NSA) Information Security (INFOSEC) Assessment Methodology (IAM) is a detailed and systematic method for examining security vulnerabilities from an organizational perspective as opposed to a only a technical perspective. Often overlooked are the processes, procedures, documentation, and informal activities that directly impact an organization’s overall security posture ...

Risk Assessment, Physics Envy, and False Precision

Image
In my last post I mentioned physics. Longtime blog readers might remember a thread from 2007 which ended with Final Question on FAIR , where I was debating the value of numerical outputs from so-called "risk assessments." Last weekend I attended the 2009 Berkshire Hathaway Shareholder meeting courtesy of Gunnar Peterson . He mentioned two terms used by Berkshire's Charlie Munger that now explains the whole numerical risk assessment approach perfectly: Physics Envy , resulting in false precision : In October of 2003 Charlie Munger gave a lecture to the economics students at the University of California at Santa Barbara in which he discussed problems with the way that economics is taught in universities.One of the problems he described was based on what he called "Physics Envy." This, Charlie says, is "the craving for a false precision. The wanting of formula..." The problem, Charley goes on, is, "that it's not going to happen by and large i...

Auditors in Charge, but 0wn3d Anyway

I read in the latest SC Magazine this comment from Lloyd Hession, CSO of Radianz . "'What is really happening is the head of security is losing control over the security agenda, which is being co-opted by audit and this umbrella of controls... The ability to decide which security projects get funded is being taken out of the security officer's hands... This focus on regulatory issues is causing a loss of control over the security agenda, which is being pushed and dictated by the audit and controls group and meeting the requirements of the regulation." I see this focus on "controls" as more of the "prevention first and foremost" strategy that ignores the importance of detection and response. I had this reaction when I saw Dr. Ron Ross of NIST speak at a recent ISSA meeting. The NIST documents seem to focus on prevention through controls, and then they stop. The unfortunate truth is that prevention eventually fails , as readers of the blog and m...

Cybersecurity Domains Mind Map

Image
Last month I retweeted an image labelled "The Map of Cybersecurity Domains (v1.0)". I liked the way this graphic divided "security" into various specialties. At the time I did not do any research to identify the originator of the graphic. Last night before my Brazilian Jiu-Jitsu class I heard some of the guys talking about certifications. They were all interested in "cybersecurity" but did not know how to break into the field. The domain image came to mind as I mentioned that I had some experience in the field. I also remembered an article Brian Krebs asked me to write titled " How to Break Into Security, Bejtlich Edition ," part of a series on that theme. I wrote: Providing advice on “getting started in digital security” is similar to providing advice on “getting started in medicine.” If you ask a neurosurgeon he or she may propose some sort of experiment with dead frog legs and batteries. If you ask a dermatologist you might get advice ...

More Thoughts on FAIR

Image
My post Thoughts on FAIR has attracted some attention, but as often the case some readers choose to obscure my point by overlaying their own assumptions. In this post I will try to explain my problems with FAIR in as simplistic a manner as possible. Imagine if someone proposed the following model for assessing force: F=ma (Yes, this is Newton's Second Law , and yes, I am using words like "model" and "assess" to reflect the risk assessment modeling problem.) I could see two problems with using this model to assess force. Reality check : The model does not reflect reality. In other words, an accurate measurement of mass times an accurate measurement of acceleration does not result in an accurate measurement of force. Input check : To accurately measure force, the values for m and a must not be arbitrary. Otherwise, the value for F is arbitrary. With respect to FAIR, I make the following judgments. Reality check : The jury is out on whether FAIR reflects reali...

The Doomsday Clock

Image
Tonight I finished watching a show called The Doomsday Clock , on the best TV channel (the History Channel , of course). I was vaguely aware of the clock, maintained by the Bulletin of the Atomic Scientists , but I didn't know the history of the project. According to Minutes to Midnight : The Bulletin of the Atomic Scientists’ Doomsday Clock conveys how close humanity is to catastrophic destruction--the figurative midnight--and monitors the means humankind could use to obliterate itself. First and foremost, these include nuclear weapons, but they also encompass climate-changing technologies and new developments in the life sciences and nanotechnology that could inflict irrevocable harm. Interesting -- you know what this is? It's a risk assessment . In my first book I defined risk as the probability of suffering harm or loss. The Doomsday Clock supposedly displays how close we are to world-ending catastrophe. I find two aspects of the clock appealing. First, as depicted by...

Control "Monitoring" is Not Threat Monitoring

Image
As I write this post I'm reminded of General Hayden's advice: "Cyber" is difficult to understand, so be charitable with those who don't understand it, as well as those who claim "expertise." It's important to remember that plenty of people are trying to act in a positive manner to defend important assets, so in that spirit I offer the following commentary. Thanks to John Bambanek's SANS post I read NIST Drafts Cybersecurity Guidance by InformationWeek's J. Nicholas Hoover. The article discusses the latest draft of SP 800-37 Rev. 1: DRAFT Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach . I suspected this to be problematic given NIST's historical bias towards "controls," which I've criticized in Controls Are Not the Solution to Our Problem and Consensus Audit Guidelines Are Still Controls . The subtext for the article was: The National Institute for Standar...

Security Reports Everywhere

The latest Symantec Internet Security Threat Report (volume VI) was released this week, along with Six Secrets of Highly Secure Organizations by CIO , CSO , and PricewaterhouseCoopers . The Symantec report requires "registration," but in return you receive a hefty 50 pages or so of data (ignoring the blank pages, covers, etc.) Here are a few excerpts I found interesting: "Over the past six months, the average time between the announcement of a vulnerability and the appearance of associated exploit code was 5.8 days... This means that, on average, organizations have less than a week to patch all their systems on which the vulnerable application is running. Over the first six months of 2004, the number of monitored bots rose from well under 2,000 computers to more than 30,000. Over the first six months of 2004, Symantec observed worm traffic originating from Fortune 100 corporations. This data was gathered not by monitoring the Fortune 100 companies themselves, but b...

BBC News Understands Risk

This evening I watched a story on BBC News about the problem of bird flu . Here is the story broken down in proper risk assessment language. Two assets are at risk: human health and bird health. We'll concentrate on birds in this analysis. Healthy birds are the asset we wish to protect. The threat is wild migratory birds infected by bird flu. The threat uses an exploit , namely bird flu itself. The vulnerability possessed by the asset and exploited by the threat is lack of immunity to bird flu. A countermeasure to reduce the asset's exposure to the threat is keeping protected birds indoors, away from their wild counterparts. The risk is infection of domesticated birds by wild birds. All infected birds must be killed. The TV story I watched contained this quote by reported Tom Heap: "The lesson learned from foot-and-mouth [disease, which ravaged Europe several years ago] is to do your best to keep the disease out , but assume that will fail . Be ready to tackle an...