Cyber security and Information
Assurance
Accept(Risk) - ANS-Process by using which managers agree to accept the hazard (e.G.,
managers understand hazard and the feasible options for treating it, but determine to just
accept it)
Administrative Control - ANS-control of policy oriented
advanced chronic danger (APT) - ANS-Initial reconnaissance
Initial compromise
set up foothold
escalate privileges
internal reconnaissance
Move laterally
Maintain presence
acquire task objective at the same time as hiding presence.
Asset/Impact-Oriented Approach - ANS-begins with the identification of affects or effects of
difficulty and important property
Then identifies chance activities that would result in the ones impacts or results.
Avoid (Risk) - ANS-Discontinue volatile exercise
(decommission insecure system or prohibit insecure behavior)
Botnet operators - ANS-Botnet operators
Common attack paradigm
Infection of computer through phishing or spear phishing
enlistment of inflamed laptop in botnet
use of pc in unlawful scheme directed in opposition to laptop user or others on Internet
Capabilities: variety of information and assets from low to high
Intent: identity robbery, economic fraud, unsolicited mail, DDoS, click on-fraud, and so on.
Generally, they're cause on always recruiting new bots to make up for attrition
Targeting: may additionally awareness on precise organizations or simply acquire victims of
opportunity
Compensating - ANS-supplements or replaces another manage
Control Functions - ANS-Deterrence
, Prevention
Detective
Compensating
Corrective
Recovery
Controls - ANS-Measures that we put in area to mitigate threat
Corrective - ANS-repair data or systems after an incident
Detective - ANS-Detect threats as, or after, they take region
Deterrence - ANS-Discourage, gradual, or deter a risk actor
Extortionists - ANS-Common attack paradigm:
Ransomware model: Infection -> encrypt facts -> call for $$ for key
DDoS model: assault business website -> call for $$ to halt attack
Blackmail version: Steal sensitive data and demand $$ to now not publicize it
Capabilities:
Range of skills, however ransomware and DDoS are low-ability assaults
Intent
Punish victim till direct charge is made
Targeting
Ransomware: broadcast to sufferers of possibility
DDoS attacks and blackmailers, via their nature, are more targeted
Framing Risk - ANS-is a strategic, governance-driven activity. The goal is a threat management
strategy. The approach will determine how the enterprise intends to...
Assess the chance (selecting the evaluation method, defining the version and approaches
Respond to the hazard (take into account the 4 options)
Monitor the consequences and ongoing changes in the environment, and
Feed that statistics returned into next hazard checks.
Likelihood of Initiation - ANS-Consider risk source characteristics
Capability
Intent
Targeting
Consider historical song document of your agency and those similarly located
Similar industries
Similar sorts of information
Similar public profile
Similar incidents
Malicious Insider - ANS-Common attack paradigm
Assurance
Accept(Risk) - ANS-Process by using which managers agree to accept the hazard (e.G.,
managers understand hazard and the feasible options for treating it, but determine to just
accept it)
Administrative Control - ANS-control of policy oriented
advanced chronic danger (APT) - ANS-Initial reconnaissance
Initial compromise
set up foothold
escalate privileges
internal reconnaissance
Move laterally
Maintain presence
acquire task objective at the same time as hiding presence.
Asset/Impact-Oriented Approach - ANS-begins with the identification of affects or effects of
difficulty and important property
Then identifies chance activities that would result in the ones impacts or results.
Avoid (Risk) - ANS-Discontinue volatile exercise
(decommission insecure system or prohibit insecure behavior)
Botnet operators - ANS-Botnet operators
Common attack paradigm
Infection of computer through phishing or spear phishing
enlistment of inflamed laptop in botnet
use of pc in unlawful scheme directed in opposition to laptop user or others on Internet
Capabilities: variety of information and assets from low to high
Intent: identity robbery, economic fraud, unsolicited mail, DDoS, click on-fraud, and so on.
Generally, they're cause on always recruiting new bots to make up for attrition
Targeting: may additionally awareness on precise organizations or simply acquire victims of
opportunity
Compensating - ANS-supplements or replaces another manage
Control Functions - ANS-Deterrence
, Prevention
Detective
Compensating
Corrective
Recovery
Controls - ANS-Measures that we put in area to mitigate threat
Corrective - ANS-repair data or systems after an incident
Detective - ANS-Detect threats as, or after, they take region
Deterrence - ANS-Discourage, gradual, or deter a risk actor
Extortionists - ANS-Common attack paradigm:
Ransomware model: Infection -> encrypt facts -> call for $$ for key
DDoS model: assault business website -> call for $$ to halt attack
Blackmail version: Steal sensitive data and demand $$ to now not publicize it
Capabilities:
Range of skills, however ransomware and DDoS are low-ability assaults
Intent
Punish victim till direct charge is made
Targeting
Ransomware: broadcast to sufferers of possibility
DDoS attacks and blackmailers, via their nature, are more targeted
Framing Risk - ANS-is a strategic, governance-driven activity. The goal is a threat management
strategy. The approach will determine how the enterprise intends to...
Assess the chance (selecting the evaluation method, defining the version and approaches
Respond to the hazard (take into account the 4 options)
Monitor the consequences and ongoing changes in the environment, and
Feed that statistics returned into next hazard checks.
Likelihood of Initiation - ANS-Consider risk source characteristics
Capability
Intent
Targeting
Consider historical song document of your agency and those similarly located
Similar industries
Similar sorts of information
Similar public profile
Similar incidents
Malicious Insider - ANS-Common attack paradigm