RE: Risk Management Research

"Peter Stephenson" <[email protected]> Fri, 23 Jul 2004 14:50:39 -0400
Newsgroups gmane.comp.security.incident-handling
Message-ID <000b01c470e5$f3582b80$a900a8c0@pstephenson>
Greetings to the list....

I am in the process of collecting research data for analysis of threats =
and
impacts in the context of an advanced quantitative approach to risk =
analysis
and management.  Those of you who might be interested are invited to =
complete
the attached research questionnaire and return it to me at
[email protected]

This will take a bit of time to complete, so I want to express my thanks =
in
advance to those of you who wish to take the time to complete it. =20

At the end of this message (after my sig block) you will find three =
sections
of the survey.  Here are your instructions should you wish to =
participate.

Section 1: Contributory Threats
-------------------------------

Talk to your incident response team and pick a period (at minimum the =
past
year) of computer/network security incidents (including viruses, worms, =
etc. =96
not just intrusions).  Please include only real (declared) incidents =96
scanning your perimeter, for example, does not count.  For each incident =
place
a P next to the threat in the list of 30 threats where the threat was =
the
primary cause of the incident and a C next to all threats that were
contributing factors.=20

It is conceivable that a single threat may have several Ps and/or =
several Cs
next to it.  Of course an individual incident can have many Cs but only =
one P.
Do not tell us how many incidents you had and do not identify your
organization.  That is not part of the study.

Section 2: Resulting Impacts
----------------------------

In the same manner your identified threats, in this section identify =
impacts.
Show a P for the primary impact in an incident and an S for each =
secondary
impact. On this there is a space for =93other=94.  Feel free to add your =
own
impacts here, but try to be consistent with the level of impact in the =
list if
you do. There can be multiple secondary impacts for a given incident, =
but only
one primary one.

Section 3: Cost of Incidents
----------------------------

First, identify your company=92s gross revenue range.  If you are =
reporting only
a single business unit, report that business unit=92s gross revenue =
range.  We
will use these ranges as a weighting scheme to equalize company size =
with
loss. It=92s sort of like a golf handicap.

Second, for each incident divide the cost of the incident by the gross
revenues and express as a percentage (i.e., multiply your result by =
100).
Report a figure for each incident that you reported in 1 and 2 above.  =
Include
the following directly-related results in your cost calculations:

            - Actual =93hard dollar=94 loss
            - Cost of cleanup & remediation
            - Cost of investigation
            - Cost of lost opportunity

You may provide several figures here if you are reporting multiple =
incidents
(one percentage of loss for each reported incident).

We DO NOT want to know who the company is (yes, I=92ll know from your =
emails,
perhaps, but that is not part of the study and as soon as I copy your =
results
into a spreadsheet for analysis I will remove the email and encrypt it =
in an
archive file as backup for the research).  Also, we DO NOT care about =
the
nature of the incidents beyond the data we are requesting.  In other =
words,
don=92t describe the incident.  Call it Incident 1, Incident 2, etc.=20

Finally, do not attempt to tie the incidents reported in Section 3 to =
any of
the data in Sections 1 and 2 =96 Section 3 is completely independent =
and,
although it represents the incidents you are reporting in 1 and 2, we =
are not
interested in any correlation.

If you want to participate and have any questions, please let me know.  =
I hope
to have all data collected in the next 30 days, so if you can help, =
that=92s the
expected time frame for completing the data collection.

Survey follows the sig block=85. (and, again, thanks for your help)

--P
=A0
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D
Even if you=92re on the right track, you=92ll get run over if you just =
sit
there.=A0=A0=A0=A0
=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0

Peter R. Stephenson, CISSP, CISM, FICAF
Director of Information Assurance
=A0 CeRNS - The Center for Regional and National Security,=A0Eastern =
Michigan
University
[email protected][email protected] =
(mobile)
http://cerns.emich.edu=A0=95=95http://home.comcast.net/~prstephenson
Tel:=A0 +1-248-373-2813  =95 eFax:=A0 +1-240-597-6453 =95  Mobile:=A0 =
+1-248-760-1152=A0
PGP Public Key Available At:=A0
http://pgp.mit.edu:11371/pks/lookup?op=3Dindex&search=3Dpeter.stephenson@=
emich.edu
    PGP Fingerprint: F6CE 241B 2EB2 ED3B 5461=A0700F D7EB B16A D783 A0CC
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D
						          =A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=20
COMPUTER SECURITY INCIDENT THREAT AND IMPACT SURVEY
---------------------------------------------------
=20
SECTION 1 =96 THREATS (use ONLY the threats below =96 do NOT add your =
own)

1.   Administrative errors of commission            -          =20
2.   Administrative errors of omission                 -          =20
3.   Hostile administrator modification of user or system data      -

4.   Administrator violates user privacy policy    -          =20
5.   A critical system component fails                 -          =20
6.   Software containing security-related flaws   -          =20
7.   Failure of a distributed system component               -           =

8.   Hacker undetected system access                           -         =
 =20
9.   Hacker attempts resource denial of service  -          =20
10.  Hacker eavesdrops on user data communications    -          =20
11.  Cryptanalysis for theft of information                       -      =
    =20
12.  Hacker masquerading as a legitimate user or as system process       =
-

13.  Message content modification	-	          =20
14.  Exploitation of vulnerabilities in the physical environment of the =
system

15.  Social engineering (includes verbal and email)                      =
-

16.  Malicious code exploitation                                     -
17.  Unexpected disruption of system or component power        -         =
 =20
18.  Recipient denies receiving information                      -       =
   =20
19.  Sender denies sending information                           -       =
   =20
20.  A participant denies performing a transaction           -           =

21.  Legitimate system services are spoofed                   -          =
=20
22.  Hostile user acts cause confidentiality breaches        -           =

23.  User abuses authorization to collect data                 -         =
 =20
24.  User errors cause confidentiality breaches               -          =
=20
25.  User error makes data inaccessible                         -        =
  =20
26.  User errors cause integrity breaches                                =
    -

27.  User errors undermine the system's security features            -

28.  User's misuse causes denial of service                     -        =
  =20
29.  User abuses authorization to modify data                 -          =
=20
30.  User abuses authorization to send data                    -         =
 =20

SECTION 2 =96 RESULTING IMPACTS (You may add your own impacts as =
=93other=94 =96
number 14 below)

1. Brand Image Damaged         -          =20
2. Customer Confidence Damaged        -          =20
3. Data Loss     -          =20
4. Financial Damages Due to Legal Actions       -          =20
5. Financial Loss Due to Other than Legal Actions         -          =20
6. Fines            -          =20
7. Loss of Human Life  -          =20
8. Legal Penalties (Other than Direct Financial Damages)           -

9. Loss of Productivity  -          =20
10. Property Loss         -          =20
11. Loss of or Damage to Reputation    -          =20
12. Safety         -          =20
13. Loss of share value             -          =20
14 Other (PLEASE DESCRIBE)         -          =20

SECTION 3 =96 COST OF INCIDENTS

(a) Size of Reporting Organization in annual gross revenue dollars =
(Place an X
in front of the appropriate range):

__ $0 - $1,000,000
__ $1,000,001 - $10,000,000
__ $10,000,001 - $50,000,000
__$50,000,001 - $100,000,000
__$100,000,001 - $500,000,000
__$500,000,001 - $1,000,000,000
__ More than $1,000,000,000

(b) Value of incident losses as a percentage of gross revenues ($loss =
divided
by $gross revenues, then multiply the result by 100 to get percent). Add =
more
lines if you need to.

Incident 1 - _______ %
Incident 2 - _______ %
Incident 3 - _______ %
Incident 4 - _______ %
Incident 5 - _______ %
Incident 6 - _______ %
Incident 7 - _______ %
Incident 8 - _______ %
Incident 9 - _______ %
Incident 10 - _______ %
Incident 11 - _______ %
Incident 12 - _______ %
Incident 13 - _______ %
Incident 14 - _______ %
Incident 15 - _______ %