Showing posts with label CIA. Show all posts
Showing posts with label CIA. Show all posts

Tuesday, December 3, 2019

Threat to Data

Threats to Data is when threat agent can cause violation of CIA. Some examples of compromise


  • Confidentiality

- User account or system compromise
- Loss or theft of laptop, removable media, printed content
- Eavesdropping, shoulder surfing, sniffer, dumpster diving

  • Integrity

- Errors and Omission. People making mistake, simple mistake, not willful nor malicious in nature. I meant to type 10 while it so happened is 100.
- Insider Threat: Your accountant cooks the book by writing himself cheque of $10,000 while he was supposed to write for $1000.
- Man in the Middle
- Falsified invoices

  • Availability

- Hard disk drive crash
- Server failure, Newtork failure
- Corruption
- DoS, DDoS

Monday, July 4, 2016

Talking Security: The Basics

In any discussion of security, there are some basic terms that will be used a lot. This step will introduce you to the basic terminology of information security.

 

CIA
The guiding principles behind information security are summed up in the acronym CIA (and we’re pretty sure there’s a joke in there somewhere), standing for confidentiality, integrity and availability.

We want our information to:
  • be read by only the right people (confidentiality)
  • only be changed by authorised people or processes (integrity)
  • be available to read and use whenever we want (availability).
It is important to be able to distinguish between these three aspects of security. So let’s look at an example.

Case study: PlayStation Network
In April 2011, Sony revealed that the PlayStation Network, used by millions of consumers worldwide, had been breached by hackers. The breach went unnoticed by Sony for several days and ultimately resulted in the theft of up to 70 million customer records. The records included customer names, addresses, emails, dates of birth and account password details. Information which could have enabled additional attacks or identity theft.

In order to assess the scale of the damage and repair the vulnerabilities that led to the attack Sony took the PlayStation Network offline, a move which cost the company, and merchants who offered services via the network, significant amounts of revenue.

In addition to the cost of fixing the breach, Sony was fined £250,000 by the Information Commissioner’s Office as a result of a ‘serious breach’ of the Data Protection Act, stating that ‘The case is one of the most serious ever reported to us. It directly affected a huge number of consumers, and at the very least put them at risk of identity theft.’


The precise financial cost to Sony is unclear but estimates place it at approximately £105 million, excluding the revenue loss by partner companies, damage to its reputation and potential damage to its customers.

Analysis
So how do the principles of CIA apply to the PlayStation case? Quite obviously, confidentiality was violated: there was a chance that unauthorised people could read the data. However, authorised users still had full access to the data, so it remained available; and the data was not changed, so its integrity was preserved.



Information assets
Time for another definition. When talking about valuable data we use the term ‘information assets’. In the PlayStation case, the information assets were the data about Sony’s customers.

When we consider security of online communications and services, we also need two additional concepts: ‘authentication’ and ‘non-repudiation’.

When we receive a message, we want to be confident that it really came from the person we think it came from. Similarly, before an online service allows a user to access their data, it is necessary to verify the identity of the user. This is known as authentication.

Non-repudiation is about ensuring that users cannot deny knowledge of sending a message or performing some online activity at some later point in time. For example, in an online banking system the user cannot be allowed to claim that they didn’t send a payment to a recipient after the bank has transferred the funds to the recipient’s account.

https://www.futurelearn.com/courses/introduction-to-cyber-security/8/steps/83026

Tuesday, April 21, 2015

Information Security - CIA - Examples


Examples
The three levels of impact on organizations or individuals should there be a breach of security (i.e. a loss of confidentiality, integrity and/or availability). These levels are defined in FIPS 199:
Low: The loss could be expected to have a limited adverse effect on organizational operations, organizational assets, or individuals. A limited adverse effect means that, for example, the loss of confidentiality, integrity, or availability might
·      Cause degradation in mission capability to an extent and duration that the organization is able to perform its primary functions, but the effectiveness of the functions is noticeably reduced;
·      Result in minor damage to organizational assets;
·      Result in minor financial loss; or
·      Result in minor harm to individuals.
Moderate: The loss could be expected to have a serious adverse effect on organizational operations, organizational assets, or individuals. A serious adverse effect means that, for example, the loss might

·      Cause significant degradation in mission capability to an extent and duration that the organization is able to perform its primary functions, but the effectiveness of the functions is significantly reduced;
·      Result in significant damage to organizational assets;
·      Result in significant financial loss; or
·      Result in significant harm to individuals that do not involve loss of life or serious, life-threatening injuries.
High: The loss could be expected to have a severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals. A severe or catastrophic adverse effect means that, for example, the loss might
·      Cause a severe degradation in or loss of mission capability to an extent and duration that the organization is not able to perform one or more of its primary functions;
·      Result in major damage to organizational assets;
·      Result in major financial loss; or
·      Result in severe or catastrophic harm to individuals involving loss of life or serious, life-threatening injuries.


CONFIDENTIALITY Student grade information is an asset whose confidentiality is considered to be highly important by students. In the United States, the Family Educational Rights and Privacy Act (FERPA) regulate the release of such information. Grade information should only be available to students, their parents, and employees that require the information to do their job. Student enrollment information may have a moderate confidentiality rating. While still covered by FERPA, this information is seen by more people on a daily basis, is less likely to be targeted than grade information, and results in less damage if disclosed. Directory information (such as lists of students, faculty, or departmental lists) may be assigned a low confidentiality rating or indeed no rating. This information is typically freely available to the public and published on a school’s Web site.
INTEGRITY Several aspects of integrity are illustrated by the example of a hospital patient’s allergy information stored in a database. The doctor should be able to trust that the information is correct and current. Now suppose that an employee (e.g., a nurse) who is authorized to view and update this information deliberately falsifies the data to cause harm to the hospital. The database needs to be restored to a trusted basis quickly, and it should be possible to trace the error back to the person responsible. Patient allergy information is an example of an asset with a high requirement for integrity. Inaccurate information could result in serious harm or death to a patient and expose the hospital to massive liability.
An example of an asset that may be assigned a moderate level of integrity requirement is a Web site that offers a forum to registered users to discuss some specific topic. Either a registered user or a hacker could falsify some entries or deface the Web site. If the forum exists only for the enjoyment of the users, brings in little or no advertising revenue, and is not used for something important such as research, and then potential damage is not severe. The Web master may experience some data, financial, and time loss.
An example of a low-integrity requirement is an anonymous online poll. Many Web sites, such as news organizations, offer these polls to their users with very few safeguards. However, the inaccuracy and unscientific nature of such polls is well understood.
AVAILABILITY The more critical a component or service, the higher is the level of availability required. Consider a system that provides authentication services for critical systems, applications, and devices. An interruption of service results in the inability for customers to access computing resources and for the staff to access the resources they need to perform critical tasks. The loss of the service translates into a large financial loss due to lost employee productivity and potential customer loss.
An example of an asset that typically would be rated as having a moderate availability requirement is a public Web site for a university; the Web site provides information for current and prospective students and donors. Such a site is not a critical component of the university’s information system, but its unavailability will cause some embarrassment.

An online telephone directory lookup application would be classified as a low-availability requirement. Although the temporary loss of the application may be an annoyance, there are other ways to access the information, such as a hardcopy directory or the operator.


 Lecture Reference:

W. Stallings, “Network Security Essentials: Applications and Standards, Fourth Edition.”