100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Class notes

Brunel - Computer Science - CS3609 Cybersecurity Lecture Notes (Exam Revision)

Rating
-
Sold
11
Pages
62
Uploaded on
28-02-2022
Written in
2020/2021

These are the lecture notes I created which I used to revise for the CS3609 Cybersecurity exam at Brunel University in which I received a First Class in.

Institution
Course











Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
Study
Course

Document information

Uploaded on
February 28, 2022
Number of pages
62
Written in
2020/2021
Type
Class notes
Professor(s)
David bell
Contains
All classes

Subjects

Content preview

Module: CS3609
Lecture Topic: Information and Risk
Week: 2

Risk Management

Risk management is the process of understanding and responding to factors that may lead to a
failure in the confidentiality, integrity, or availability of an information system.




Confidentiality is about keeping information confidential and not allowing people who shouldn’t see
it, access that information.

Integrity is about ensuring that information is not altered or tampered with. (Blockchain e.g.)

Availability is who should have access to that information who can see it.

Risk is a situation or event that exposes an asset to harm, and the probability of that risk being
realised. If it is, that can cause a loss of money. (Fines: could be 4% of turnover, poor security or not
declaring breaches)

, Information security is the preservation of CIA. Other properties such as
authentication, authorization, non-reputation, audit and accountability
can also be involved.




Why risk management? It’s not a matter of IF but WHEN…
No organization is exempt from data breaches.

Tesco bank was fined 16.8 million pounds 2016-2019 for data breaches.
You must continuously identify and quantify risk; you need to access the effectiveness of deployed
goals to reduce impact.




(This one always included in the exam)

,These 7 factors need to be understood.

Stakeholders are risk owners, system owners, asset owners, or anyone who has a stake in the
information system or the asset.

An asset is anything that has value, tangible, people, information, intellectual property. Consider
what assets are at Risk in your network topology in terms of the vulnerabilities.

Threats is a single potential cause of an unwanted instant. These come from Threat agents.

Controls are implemented to mitigate Vulnerabilities, which is a weakness in an asset or the
absence of a security control that can be exploited by a threat. (e.g. insufficient maintenance, single
point of absence, as well as floods/fire)

Controls are the means of managing risk and can place limits on the activities that might pose a risk,
such as proactive, as safeguards, or counter measures, once an incident occurs – how to detect,
contain and recover from an incident.



CVE – Common Vulnerabilities and Exposures

Cve.mitre.org

You can explore the threats. The CVE system provides a reference method for publicly known
information security vulnerabilities and exposures.

Mitre attack framework.

, Risk Analysis

Risks can be analysed by either Quantitative or Qualitative risk methodologies




Quantitative relies on specific numbers, which makes it more precise, allows decision makers to
make better decisions about risk and quantify the risk. Usually involves money (£/$). Relies on the
accuracy and completeness of the numerical values. Quantifies the loss.

Qualitative you don’t have hard data, ask people what they think based on their experience,
subjective data, based on risk perception by the stakeholders. Quantitative gives a handle on risk
which is not covered by the hard numbers. This allows you to think about the risk register.

Ideally, you would take a hybrid approach and use both.
$9.35
Get access to the full document:

100% satisfaction guarantee
Immediately available after payment
Both online and in PDF
No strings attached


Also available in package deal

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
cslbrunel Brunel University
Follow You need to be logged in order to follow users or courses
Sold
63
Member since
3 year
Number of followers
34
Documents
29
Last sold
4 months ago
Brunel Computer Science (1st Class Honours)

I achieved a First Class Honours degree in Computer Science from Brunel University - I will be uploading some of my work. Please do not purchase any documents looking for the solution to your assignments or deliverables. No refunds / exchanges.

5.0

2 reviews

5
2
4
0
3
0
2
0
1
0

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions