Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 6 out of 47 pages
Thesis

Port of Seattle IT Security Risk Assessment – OCTAVE Allegro Full Report with Real-World Information Security Engineer Insights

Document preview thumbnail
Preview 6 out of 47 pages

Explore a comprehensive IT security risk assessment focused on the Port of Seattle and informed by the OCTAVE Allegro risk assessment methodology. This report combines academic risk assessment concepts with practical insights gathered through interviews with an information security engineer, offering a real-world perspective on how information security risks and organizational security considerations can be examined. The complete 50-page resource includes a 17-page main IT security risk assessment report, integrated OCTAVE Allegro worksheets, threat scenario questionnaires, and supporting reference material—providing a comprehensive resource for studying and understanding practical information security risk assessment. Academic Achievement: This report received a 74/75 (98.7%) overall grade, demonstrating a high level of academic quality and thoroughness in its original assessment context. Topics and features include: IT security risk assessment OCTAVE Allegro methodology Risk identification and analysis Information security assets and threats Risk assessment considerations Organizational information security Real-world insights from an information security engineer interview Port of Seattle case context Practical application of information security risk assessment concepts This resource may be useful for students and learners studying information security, cybersecurity risk management, IT security risk assessment, or the OCTAVE Allegro methodology. Note: This is an independent academic/educational report and is not an official Port of Seattle security assessment or official OCTAVE Allegro publication.

Content preview

Port of Seattle IT Security Risk Assessment

Joseph Sanchez
Central Washington University


December 4, 2018





,Table of Contents
Executie Summary.....................................................................................................................................4
Oieriiew of Assessment..........................................................................................................................4
Identied Risks and Common Risk hndemes..............................................................................................4
Summary of Proposed Mitiaton Actiites.............................................................................................4
Risk Assessment Report...............................................................................................................................4
Oieriiew of Risk Assessment..................................................................................................................5
Risk Measurement Criteria......................................................................................................................5
Scope of Assessment...............................................................................................................................6
Security Controls Assessed......................................................................................................................6
Areas of Concern (or Risks)......................................................................................................................8
Disiruntled employee may access and release employee’s account informaton..............................8
Hacker iain access to employee’s account informaton.....................................................................9
An intruder could iain access to an access panel at tde kiosk macdine..............................................9
An intruder interceptni tde Wi-Fi siinal to obtain informaton.......................................................10
A tdief iainini access to tde locked container...................................................................................12
Risk Heat Map....................................................................................................................................13
Risk Mitiaton.......................................................................................................................................14
Risks to Accept...................................................................................................................................14
Risks to Defer.....................................................................................................................................14
Risks to hnransfer................................................................................................................................14
Risks to Mitiate................................................................................................................................14
Reference List............................................................................................................................................18
Octaie Alleiro Worksdeets.......................................................................................................................19
Worksdeet 1..............................................................................................................................................19
Worksdeet 2..............................................................................................................................................20
Worksdeet 3..............................................................................................................................................21
Worksdeet 4..............................................................................................................................................22
Worksdeet 5..............................................................................................................................................23
Worksdeet 6..............................................................................................................................................24
Worksdeet 7..............................................................................................................................................25
Worksdeet 8..............................................................................................................................................26

,Worksdeet 9a............................................................................................................................................28
Worksdeet 9b............................................................................................................................................30
Worksdeet 9c.............................................................................................................................................32
Worksdeet 10............................................................................................................................................34
Worksdeet 10............................................................................................................................................36
Worksdeet 10............................................................................................................................................38
Worksdeet 10............................................................................................................................................40
Worksdeet 10............................................................................................................................................43
Octaie Alleiro Questonnaires..................................................................................................................46

, Executive Summary
Overview of Assessment
When the assessment took place, I interviewed Oscar Segura who works for Port of Seattle.
During our interview, the information asset we assessed was employee account information. The
assessment took place on November 7, 2018. The purpose of assessing employees’ account
information was to see what are the chances that the employee’s account information would be
compromised.

Identified Risks and Common Risk Themes
There were some area of concerns that I have discovered while the assessment was in-progress.
One of those concerns was a disgruntled employee may release an employee’s account
information. Other areas that were also a concern was a hacker may gain access to employee’s
account information in the following ways. An intruder could gain access to the access panel on
the parking garage fare kiosk and plug a hacking device such as a keyboard or a flash drive. The
Wi-Fi connection from the internal network to the parking garage fare kiosk machine could be
intercepted by an unauthorized individual. Finally, an unauthorized individual could access the
room where the locked containers are stored.
These are the different risk areas that I found within my assessment at the Port of Seattle.

Summary of Proposed Mitigation Activities
The common thing to do when you are mitigating risks is to first start with the basic assessment.
A basic assessment can be something like evaluating the systems settings that has been set by
default; such as a type of encryption, is the computer’s hard drive encryption enabled or
disabled, internet security settings configured or not, etc. these are the general things that would
need to be examined before deciding which security controls to implement to the computer
system.
The proposed mitigation methods are dependent on the area of concerns and findings that were
found during the assessment. For example, an intruder using Wi-Fi to try to obtain information
from the kiosk machine is an area of concern. So, this is the area that will be assessed and
findings that were found would be the evidence to determine which security control would be
appropriate to implement that will resolve this area of concern. Generally, you would first figure
out what basic security controls are in place and possible vulnerabilities that may occur when
evaluating computer system and its infrastructure.


Risk Assessment Report

,Overview of Risk Assessment
I used Octave Allegro methodology method to help me get a better understanding on what areas
to assess and see what the potential impact on those areas would be. For example, Oscar has
provided me the information such as the percentages for worksheet 1 through 3 on the different
levels of each impact area. The usage of the Octave Allegro worksheets has provided me a better
insight as to what kind of questions I could ask Oscar.
During the interview, I have taken Oscar’s comments and wrote them down in the appropriate
box where it best suited. How we approach different stages of the Allegro worksheets was, both
of us worked on them in chronological order. On worksheets 1 through 5, we give each of the
impact areas a number value that best fit for different risk values. I also asked him how the Port
of Seattle would rank their priority on the different impact areas mentioned on worksheet 7.
Oscar gave me a series of numbers from 1 through 5 and assigned a number value from the most
important to the least important in Port of Seattle’s point of view.
This is how I followed the methodology. I used it as a guide and took what the methodology was
asking. I tailored my answers that I received from the interview and then applied them to the
worksheets. Other methods I used was the example risk assessment report from Introducing
Allegro document, so I can get an idea of what the report should look like and see what kind of
information was in each of the boxes.
I completed the rest of the worksheets that were part of the risk assessment. For example, on
worksheet 8 where it said critical asset, I chose to put employee account information under that
specific box; then I provided a description and a reason why that asset is important to Port of
Seattle. All three sections of worksheet 9, the container description states the type of container
and the type of information in the container.
Port of Seattle has made the decision that employee account information is consider an
information asset because it has sensitive information about the staff members which has value
to organization. The type of containers that Port of Seattle decided to use to store employee
records is a server, databases, and workstations. Employees can access the information to
perform necessary duties as well as archive the information.
The Port of Seattle must use the servers, databases and workstations to perform their operation
which revealed some area of concerns. If a disgruntled employee accesses and releases
employee’s information is one concern. Another if a hacker was to gain access and steal
employees’ information, and other concerns were found. These are the areas the Port of Seattle
wanted assessed to see what vulnerabilities exist, what security measures are in place, and test
the security of those systems.

Risk Measurement Criteria
The following impact areas are what Oscar and I determined needed to be assessed. They are
reputation and customer confidence, financial, productivity, safety and health, and fines and
legal penalties. In each of these areas, Oscar and I have agreed that safety and health will be

, ranked number 5 meaning that this area is the most important. Followed by fines and legal
penalties which was ranked number 4, the second most important. Other impact areas were
prioritized according: reputation and customer confidence was ranked number 3. Financial was
ranked number 2, and productivity number 1.
The threshold for each of different impact areas were rated according to the following. Low was
measured as 1% or less. Medium was measured from 2% to 9%. High was measured as 10% or
higher.

Scope of Assessment
Oscar and I identified employee account information as an information asset. The employee
account information contains personal information about the employee(s). The account data
includes social security numbers, bank account and routing numbers, earning statements, credit
card information, etc. Since this information asset contains a lot of sensitive data, the Port of
Seattle wanted to assess the vulnerabilities to unauthorized access to the account information and
the impact to its operation.

Security Controls Assessed
Table 1. Security Control Assessment
Critical
Security
Control
Identifier Assessment of Security Control Results of Assessment
CSC 1.1 Interviewed Oscar Segura
(Informaton Security Eniineer) CSC 1.1 control has been implemented
CSC 1.2 Interiiewed Oscar Seiura
(Informaton Security Eniineer) CSC 1.2 control have been implemented.
CSC 1.3 Interiiewed Oscar Seiura
(Informaton Security Eniineer) CSC 1.3 control have been implemented.
CSC 1.4 Interiiewed Oscar Seiura
(Informaton Security Eniineer) CSC 1.4 control have been implemented.
CSC 1.5
Interiiewed Oscar Seiura CSC 1.5 control has not yet been
(Informaton Security Eniineer) implemented
CSC 1.6 Interiiewed Oscar Seiura
(Informaton Security Eniineer) CSC 1.6 control has been implemented.
CSC 2.1 Interiiewed Oscar Seiura
(Informaton Security Eniineer) CSC 2.1 control has been implemented
CSC 2.2 Interiiewed Oscar Seiura
(Informaton Security Eniineer) CSC 2.2 control has been implemented
CSC 2.3 Interiiewed Oscar Seiura .
(Informaton Security Eniineer) CSC 2.3 control has been implemented
CSC 2.4 Interiiewed Oscar Seiura
(Informaton Security Eniineer)

Connected book
 image
Publisher: 2011 ISBN: 9781466509177 Edition: Unknown

Document information

Uploaded on
December 11, 2018
Number of pages
47
Written in
2018/2019
Type
Thesis
Supervisor(s)
Unknown
Year
2011
$8.99
Purchased by 2 students

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
titanium
4.4
(12)
Sold
43
Followers
32
Items
192
Last sold
3 year ago

Reviews from verified buyers




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions