Joseph Sanchez
Central Washington University
December 4, 2018
,Table of Contents
Executie Summary.....................................................................................................................................4
Oieriiew of Assessment..........................................................................................................................4
Identied Risks and Common Risk hndemes..............................................................................................4
Summary of Proposed Mitiaton Actiites.............................................................................................4
Risk Assessment Report...............................................................................................................................4
Oieriiew of Risk Assessment..................................................................................................................5
Risk Measurement Criteria......................................................................................................................5
Scope of Assessment...............................................................................................................................6
Security Controls Assessed......................................................................................................................6
Areas of Concern (or Risks)......................................................................................................................8
Disiruntled employee may access and release employee’s account informaton..............................8
Hacker iain access to employee’s account informaton.....................................................................9
An intruder could iain access to an access panel at tde kiosk macdine..............................................9
An intruder interceptni tde Wi-Fi siinal to obtain informaton.......................................................10
A tdief iainini access to tde locked container...................................................................................12
Risk Heat Map....................................................................................................................................13
Risk Mitiaton.......................................................................................................................................14
Risks to Accept...................................................................................................................................14
Risks to Defer.....................................................................................................................................14
Risks to hnransfer................................................................................................................................14
Risks to Mitiate................................................................................................................................14
Reference List............................................................................................................................................18
Octaie Alleiro Worksdeets.......................................................................................................................19
Worksdeet 1..............................................................................................................................................19
Worksdeet 2..............................................................................................................................................20
Worksdeet 3..............................................................................................................................................21
Worksdeet 4..............................................................................................................................................22
Worksdeet 5..............................................................................................................................................23
Worksdeet 6..............................................................................................................................................24
Worksdeet 7..............................................................................................................................................25
Worksdeet 8..............................................................................................................................................26
,Worksdeet 9a............................................................................................................................................28
Worksdeet 9b............................................................................................................................................30
Worksdeet 9c.............................................................................................................................................32
Worksdeet 10............................................................................................................................................34
Worksdeet 10............................................................................................................................................36
Worksdeet 10............................................................................................................................................38
Worksdeet 10............................................................................................................................................40
Worksdeet 10............................................................................................................................................43
Octaie Alleiro Questonnaires..................................................................................................................46
, Executive Summary
Overview of Assessment
When the assessment took place, I interviewed Oscar Segura who works for Port of Seattle.
During our interview, the information asset we assessed was employee account information. The
assessment took place on November 7, 2018. The purpose of assessing employees’ account
information was to see what are the chances that the employee’s account information would be
compromised.
Identified Risks and Common Risk Themes
There were some area of concerns that I have discovered while the assessment was in-progress.
One of those concerns was a disgruntled employee may release an employee’s account
information. Other areas that were also a concern was a hacker may gain access to employee’s
account information in the following ways. An intruder could gain access to the access panel on
the parking garage fare kiosk and plug a hacking device such as a keyboard or a flash drive. The
Wi-Fi connection from the internal network to the parking garage fare kiosk machine could be
intercepted by an unauthorized individual. Finally, an unauthorized individual could access the
room where the locked containers are stored.
These are the different risk areas that I found within my assessment at the Port of Seattle.
Summary of Proposed Mitigation Activities
The common thing to do when you are mitigating risks is to first start with the basic assessment.
A basic assessment can be something like evaluating the systems settings that has been set by
default; such as a type of encryption, is the computer’s hard drive encryption enabled or
disabled, internet security settings configured or not, etc. these are the general things that would
need to be examined before deciding which security controls to implement to the computer
system.
The proposed mitigation methods are dependent on the area of concerns and findings that were
found during the assessment. For example, an intruder using Wi-Fi to try to obtain information
from the kiosk machine is an area of concern. So, this is the area that will be assessed and
findings that were found would be the evidence to determine which security control would be
appropriate to implement that will resolve this area of concern. Generally, you would first figure
out what basic security controls are in place and possible vulnerabilities that may occur when
evaluating computer system and its infrastructure.
Risk Assessment Report
,Overview of Risk Assessment
I used Octave Allegro methodology method to help me get a better understanding on what areas
to assess and see what the potential impact on those areas would be. For example, Oscar has
provided me the information such as the percentages for worksheet 1 through 3 on the different
levels of each impact area. The usage of the Octave Allegro worksheets has provided me a better
insight as to what kind of questions I could ask Oscar.
During the interview, I have taken Oscar’s comments and wrote them down in the appropriate
box where it best suited. How we approach different stages of the Allegro worksheets was, both
of us worked on them in chronological order. On worksheets 1 through 5, we give each of the
impact areas a number value that best fit for different risk values. I also asked him how the Port
of Seattle would rank their priority on the different impact areas mentioned on worksheet 7.
Oscar gave me a series of numbers from 1 through 5 and assigned a number value from the most
important to the least important in Port of Seattle’s point of view.
This is how I followed the methodology. I used it as a guide and took what the methodology was
asking. I tailored my answers that I received from the interview and then applied them to the
worksheets. Other methods I used was the example risk assessment report from Introducing
Allegro document, so I can get an idea of what the report should look like and see what kind of
information was in each of the boxes.
I completed the rest of the worksheets that were part of the risk assessment. For example, on
worksheet 8 where it said critical asset, I chose to put employee account information under that
specific box; then I provided a description and a reason why that asset is important to Port of
Seattle. All three sections of worksheet 9, the container description states the type of container
and the type of information in the container.
Port of Seattle has made the decision that employee account information is consider an
information asset because it has sensitive information about the staff members which has value
to organization. The type of containers that Port of Seattle decided to use to store employee
records is a server, databases, and workstations. Employees can access the information to
perform necessary duties as well as archive the information.
The Port of Seattle must use the servers, databases and workstations to perform their operation
which revealed some area of concerns. If a disgruntled employee accesses and releases
employee’s information is one concern. Another if a hacker was to gain access and steal
employees’ information, and other concerns were found. These are the areas the Port of Seattle
wanted assessed to see what vulnerabilities exist, what security measures are in place, and test
the security of those systems.
Risk Measurement Criteria
The following impact areas are what Oscar and I determined needed to be assessed. They are
reputation and customer confidence, financial, productivity, safety and health, and fines and
legal penalties. In each of these areas, Oscar and I have agreed that safety and health will be
, ranked number 5 meaning that this area is the most important. Followed by fines and legal
penalties which was ranked number 4, the second most important. Other impact areas were
prioritized according: reputation and customer confidence was ranked number 3. Financial was
ranked number 2, and productivity number 1.
The threshold for each of different impact areas were rated according to the following. Low was
measured as 1% or less. Medium was measured from 2% to 9%. High was measured as 10% or
higher.
Scope of Assessment
Oscar and I identified employee account information as an information asset. The employee
account information contains personal information about the employee(s). The account data
includes social security numbers, bank account and routing numbers, earning statements, credit
card information, etc. Since this information asset contains a lot of sensitive data, the Port of
Seattle wanted to assess the vulnerabilities to unauthorized access to the account information and
the impact to its operation.
Security Controls Assessed
Table 1. Security Control Assessment
Critical
Security
Control
Identifier Assessment of Security Control Results of Assessment
CSC 1.1 Interviewed Oscar Segura
(Informaton Security Eniineer) CSC 1.1 control has been implemented
CSC 1.2 Interiiewed Oscar Seiura
(Informaton Security Eniineer) CSC 1.2 control have been implemented.
CSC 1.3 Interiiewed Oscar Seiura
(Informaton Security Eniineer) CSC 1.3 control have been implemented.
CSC 1.4 Interiiewed Oscar Seiura
(Informaton Security Eniineer) CSC 1.4 control have been implemented.
CSC 1.5
Interiiewed Oscar Seiura CSC 1.5 control has not yet been
(Informaton Security Eniineer) implemented
CSC 1.6 Interiiewed Oscar Seiura
(Informaton Security Eniineer) CSC 1.6 control has been implemented.
CSC 2.1 Interiiewed Oscar Seiura
(Informaton Security Eniineer) CSC 2.1 control has been implemented
CSC 2.2 Interiiewed Oscar Seiura
(Informaton Security Eniineer) CSC 2.2 control has been implemented
CSC 2.3 Interiiewed Oscar Seiura .
(Informaton Security Eniineer) CSC 2.3 control has been implemented
CSC 2.4 Interiiewed Oscar Seiura
(Informaton Security Eniineer)