RE: Risk Management Research
"Peter Stephenson" <[email protected]> Fri, 23 Jul 2004 14:50:39 -0400
| Newsgroups | gmane.comp.security.incident-handling |
|---|---|
| Message-ID | <000b01c470e5$f3582b80$a900a8c0@pstephenson> |
Greetings to the list.... I am in the process of collecting research data for analysis of threats = and impacts in the context of an advanced quantitative approach to risk = analysis and management. Those of you who might be interested are invited to = complete the attached research questionnaire and return it to me at [email protected] This will take a bit of time to complete, so I want to express my thanks = in advance to those of you who wish to take the time to complete it. =20 At the end of this message (after my sig block) you will find three = sections of the survey. Here are your instructions should you wish to = participate. Section 1: Contributory Threats ------------------------------- Talk to your incident response team and pick a period (at minimum the = past year) of computer/network security incidents (including viruses, worms, = etc. =96 not just intrusions). Please include only real (declared) incidents =96 scanning your perimeter, for example, does not count. For each incident = place a P next to the threat in the list of 30 threats where the threat was = the primary cause of the incident and a C next to all threats that were contributing factors.=20 It is conceivable that a single threat may have several Ps and/or = several Cs next to it. Of course an individual incident can have many Cs but only = one P. Do not tell us how many incidents you had and do not identify your organization. That is not part of the study. Section 2: Resulting Impacts ---------------------------- In the same manner your identified threats, in this section identify = impacts. Show a P for the primary impact in an incident and an S for each = secondary impact. On this there is a space for =93other=94. Feel free to add your = own impacts here, but try to be consistent with the level of impact in the = list if you do. There can be multiple secondary impacts for a given incident, = but only one primary one. Section 3: Cost of Incidents ---------------------------- First, identify your company=92s gross revenue range. If you are = reporting only a single business unit, report that business unit=92s gross revenue = range. We will use these ranges as a weighting scheme to equalize company size = with loss. It=92s sort of like a golf handicap. Second, for each incident divide the cost of the incident by the gross revenues and express as a percentage (i.e., multiply your result by = 100). Report a figure for each incident that you reported in 1 and 2 above. = Include the following directly-related results in your cost calculations: - Actual =93hard dollar=94 loss - Cost of cleanup & remediation - Cost of investigation - Cost of lost opportunity You may provide several figures here if you are reporting multiple = incidents (one percentage of loss for each reported incident). We DO NOT want to know who the company is (yes, I=92ll know from your = emails, perhaps, but that is not part of the study and as soon as I copy your = results into a spreadsheet for analysis I will remove the email and encrypt it = in an archive file as backup for the research). Also, we DO NOT care about = the nature of the incidents beyond the data we are requesting. In other = words, don=92t describe the incident. Call it Incident 1, Incident 2, etc.=20 Finally, do not attempt to tie the incidents reported in Section 3 to = any of the data in Sections 1 and 2 =96 Section 3 is completely independent = and, although it represents the incidents you are reporting in 1 and 2, we = are not interested in any correlation. If you want to participate and have any questions, please let me know. = I hope to have all data collected in the next 30 days, so if you can help, = that=92s the expected time frame for completing the data collection. Survey follows the sig block=85. (and, again, thanks for your help) --P =A0 =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D Even if you=92re on the right track, you=92ll get run over if you just = sit there.=A0=A0=A0=A0 =A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0= =A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0= =A0=A0 Peter R. Stephenson, CISSP, CISM, FICAF Director of Information Assurance =A0 CeRNS - The Center for Regional and National Security,=A0Eastern = Michigan University [email protected][email protected] = (mobile) http://cerns.emich.edu=A0=95=95http://home.comcast.net/~prstephenson Tel:=A0 +1-248-373-2813 =95 eFax:=A0 +1-240-597-6453 =95 Mobile:=A0 = +1-248-760-1152=A0 PGP Public Key Available At:=A0 http://pgp.mit.edu:11371/pks/lookup?op=3Dindex&search=3Dpeter.stephenson@= emich.edu PGP Fingerprint: F6CE 241B 2EB2 ED3B 5461=A0700F D7EB B16A D783 A0CC =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D =A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=20 COMPUTER SECURITY INCIDENT THREAT AND IMPACT SURVEY --------------------------------------------------- =20 SECTION 1 =96 THREATS (use ONLY the threats below =96 do NOT add your = own) 1. Administrative errors of commission - =20 2. Administrative errors of omission - =20 3. Hostile administrator modification of user or system data - 4. Administrator violates user privacy policy - =20 5. A critical system component fails - =20 6. Software containing security-related flaws - =20 7. Failure of a distributed system component - = 8. Hacker undetected system access - = =20 9. Hacker attempts resource denial of service - =20 10. Hacker eavesdrops on user data communications - =20 11. Cryptanalysis for theft of information - = =20 12. Hacker masquerading as a legitimate user or as system process = - 13. Message content modification - =20 14. Exploitation of vulnerabilities in the physical environment of the = system 15. Social engineering (includes verbal and email) = - 16. Malicious code exploitation - 17. Unexpected disruption of system or component power - = =20 18. Recipient denies receiving information - = =20 19. Sender denies sending information - = =20 20. A participant denies performing a transaction - = 21. Legitimate system services are spoofed - = =20 22. Hostile user acts cause confidentiality breaches - = 23. User abuses authorization to collect data - = =20 24. User errors cause confidentiality breaches - = =20 25. User error makes data inaccessible - = =20 26. User errors cause integrity breaches = - 27. User errors undermine the system's security features - 28. User's misuse causes denial of service - = =20 29. User abuses authorization to modify data - = =20 30. User abuses authorization to send data - = =20 SECTION 2 =96 RESULTING IMPACTS (You may add your own impacts as = =93other=94 =96 number 14 below) 1. Brand Image Damaged - =20 2. Customer Confidence Damaged - =20 3. Data Loss - =20 4. Financial Damages Due to Legal Actions - =20 5. Financial Loss Due to Other than Legal Actions - =20 6. Fines - =20 7. Loss of Human Life - =20 8. Legal Penalties (Other than Direct Financial Damages) - 9. Loss of Productivity - =20 10. Property Loss - =20 11. Loss of or Damage to Reputation - =20 12. Safety - =20 13. Loss of share value - =20 14 Other (PLEASE DESCRIBE) - =20 SECTION 3 =96 COST OF INCIDENTS (a) Size of Reporting Organization in annual gross revenue dollars = (Place an X in front of the appropriate range): __ $0 - $1,000,000 __ $1,000,001 - $10,000,000 __ $10,000,001 - $50,000,000 __$50,000,001 - $100,000,000 __$100,000,001 - $500,000,000 __$500,000,001 - $1,000,000,000 __ More than $1,000,000,000 (b) Value of incident losses as a percentage of gross revenues ($loss = divided by $gross revenues, then multiply the result by 100 to get percent). Add = more lines if you need to. Incident 1 - _______ % Incident 2 - _______ % Incident 3 - _______ % Incident 4 - _______ % Incident 5 - _______ % Incident 6 - _______ % Incident 7 - _______ % Incident 8 - _______ % Incident 9 - _______ % Incident 10 - _______ % Incident 11 - _______ % Incident 12 - _______ % Incident 13 - _______ % Incident 14 - _______ % Incident 15 - _______ %