Information SecurityUnit 912 min read
Security Risk Assessment & Management: Threats, Vulnerabilities, and Mitigation
Unit 9 of Information Security introduces the systematic process of identifying, evaluating, and mitigating security risks in systems, networks, and organizations, using frameworks like NIST, ISO 27001, and COBIT to align with real-world cybersecurity challenges faced by banks, e-commerce platforms, and telecom provide
TAKEAWAYS:
- Security risk assessment is a structured process to identify threats, vulnerabilities, and impacts, using frameworks like NIST SP 800-30 and ISO 27005.
- Threats (e.g., hackers, natural disasters) and vulnerabilities (e.g., weak passwords, outdated software) are distinct but interact to create risk (probability × impact).
- Risk treatment options include avoidance, mitigation, transfer, and acceptance, each with trade-offs in cost and effectiveness.
- Security auditing (internal/external) and penetration testing are critical for validating controls and uncovering hidden vulnerabilities.
- Nepal’s NEPSE and NTC use risk assessments to protect financial transactions and network infrastructure from cyber threats.
- Real-world example: Daraz’s risk management involves queue-based attack prevention (DDoS mitigation) and customer data encryption to handle millions of transactions securely.
1. Definitions and Core Concepts
1.1 What is Security Risk Assessment?
Security risk assessment is the structured evaluation of threats, vulnerabilities, and their potential impact on an organization’s assets (data, systems, reputation). It answers:
- What can go wrong?
- How likely is it?
- What are the consequences?
It is the first step in the risk management cycle:
flowchart TD
A["Risk Assessment"] --> B["Risk Treatment"]
B --> C["Risk Monitoring"]
C --> AKey frameworks:
- NIST SP 800-30: U.S. standard for risk assessment (used by government and private sectors).
- ISO 27005: International standard for information security risk management.
- COBIT: Framework for IT governance and risk management (adopted by Nepal’s NEPSE for financial systems).
1.2 Threats vs. Vulnerabilities vs. Risk
| Term | Definition | Example (Nepal Context) |
|---|---|---|
| Threat | Any potential danger that could exploit a vulnerability. | Hackers launching phishing attacks on eSewa users. |
| Vulnerability | Weakness in a system that can be exploited by a threat. | Outdated NTC routers with unpatched firmware. |
| Risk | Probability × Impact of a threat exploiting a vulnerability. | Daraz’s payment system being down due to DDoS. |
Visualization:
flowchart TD
A["Threat"] -->|"Exploits"| B["Vulnerability"]
B -->|"If exploited"| C["Risk: Impact × Probability"]
C --> D["Security Controls"]2. Steps in Security Risk Assessment
A typical risk assessment follows 5 steps (based on NIST SP 800-30):
2.1 Step 1: System Characterization
- Identify assets (data, systems, people) and their value.
- Example: For Ncell, assets include:
- Customer databases (high value).
- SIM card authentication systems (critical).
- Customer service chatbots (moderate value).
2.2 Step 2: Threat Identification
- Internal threats: Employees (e.g., insider theft at Khalti).
- External threats: Hackers, malware, natural disasters (e.g., earthquake disrupting NTC’s fiber optics).
- Threat sources:
- Human: Malicious insiders, social engineering.
- Environmental: Power outages, floods.
- Technical: Unpatched software, misconfigurations.
2.3 Step 3: Vulnerability Identification
- Common vulnerabilities:
- Weak passwords (e.g., Pathao driver app accounts).
- Lack of encryption (e.g., unsecured Wi-Fi at cafes).
- Default credentials (e.g., routers in homes).
- Tools for detection:
- Vulnerability scanners (Nessus, OpenVAS).
- Penetration testing (ethical hacking).
2.4 Step 4: Risk Analysis
Qualitative vs. Quantitative Analysis:
Method Description Example Qualitative Uses expert judgment (low/medium/high risk). NEPSE classifying stock trade risks. Quantitative Uses numerical values (e.g., dollar loss, downtime cost). Bank’s loan fraud risk = $500K/year. Risk Matrix:
2.5 Step 5: Risk Treatment
- Options for risk treatment:
Option Description Example (Nepal) Avoidance Eliminate the risk entirely. NTC stopping use of legacy protocols. Mitigation Reduce risk (e.g., firewalls, encryption). eSewa using AES-256 for transactions. Transfer Shift risk to a third party (e.g., insurance). Daraz buying cyber insurance. Acceptance Accept residual risk if cost of mitigation > benefit. Small businesses using basic antivirus.
Worked Example: Scenario: A Nepali bank detects that ATM skimming (a threat) exploits weak PIN entry systems (vulnerability).
- Risk: 10% chance of $20K loss annually.
- Treatment Options:
- Mitigation: Install PIN pads with cameras ($50K cost).
- Transfer: Buy cyber insurance ($30K/year).
- Acceptance: If cost of mitigation > potential loss.
3. Security Auditing and Penetration Testing
3.1 Security Auditing Architecture
Auditing ensures controls are working. Types:
- Internal Audit: Conducted by the organization’s own team.
- External Audit: Conducted by third parties (e.g., ISO 27001 certification for NEPSE).
Security Auditing Process:
flowchart TD
A["Plan Audit"] --> B["Gather Evidence"]
B --> C["Analyze Findings"]
C --> D["Report Issues"]
D --> E["Remediation"]
E --> A3.2 Penetration Testing
- Simulated cyberattacks to find vulnerabilities.
- Types:
- Black-box: Tester has no prior knowledge (like a real hacker).
- White-box: Tester knows system details (e.g., NTC’s network topology).
- Gray-box: Partial knowledge (e.g., Khalti’s API access).
Example:
- Pathao hires a penetration tester to exploit weak authentication in its driver app.
- Finds that default admin credentials are still active → Critical risk.
4. Risk Management Frameworks
| Framework | Description | Used By (Nepal) |
|---|---|---|
| NIST SP 800-30 | U.S. standard for risk assessment. | NTC, Ncell (telecom sector). |
| ISO 27001 | International standard for information security management. | NEPSE, banks (financial sector). |
| COBIT | IT governance framework. | Government IT departments. |
| CIS Controls | Critical security controls for cyber defense. | eSewa, Khalti (payment systems). |
5. Real-World Applications in Nepal
In the Real World
NEPSE (Nepal Stock Exchange):
- Uses: Risk assessment to protect trading systems from insider trading and DDoS attacks.
- How: Implements ISO 27001 and penetration testing to detect vulnerabilities in real-time trading APIs.
NTC (Nepal Telecommunications Authority):
- Uses: Risk management for fiber optic networks against physical sabotage and cyber espionage.
- How: Uses NIST SP 800-30 to assess risks from earthquakes (cutting cables) and hackers (SIM swapping).
Daraz (E-commerce):
- Uses: Risk assessment for payment gateways and customer data.
- How: Encryption (AES-256) for transactions and DDoS protection to handle Black Friday sales spikes.
Worked Example: Kathmandu Traffic Routes (Analogy)
- Threat: Accidents due to poor traffic management.
- Vulnerability: No real-time GPS tracking for buses.
- Risk: Delays for Pathao drivers and school buses.
- Treatment:
- Mitigation: Install smart traffic lights (like NTC’s fiber-based traffic control).
- Transfer: Use insurance for delays.
6. Common Cyber Attacks and Their Risks
| Attack Type | Description | Example (Nepal) | Risk Level |
|---|---|---|---|
| Phishing | Fake emails to steal credentials. | eSewa users clicking malicious links. | High |
| DDoS | Overwhelming a system with traffic. | Daraz’s checkout page crashing. | Critical |
| SQL Injection | Injecting malicious SQL to steal data. | Khalti’s database exposed. | High |
| Man-in-the-Middle | Intercepting communications (e.g., MITM on unsecured Wi-Fi). | Pathao driver app data stolen. | Medium |
| Insider Threat | Employees leaking data (e.g., bank tellers selling customer data). | NEPSE insider trading. | Critical |
Visualization of Attack Flow:
sequenceDiagram
participant Hacker
participant Victim
participant BankServer
Hacker->>Victim: Sends phishing email (fake login page)
Victim->>BankServer: Enters credentials (unaware)
Hacker->>BankServer: Captures credentials7. Ethical and Legal Considerations
- Cyber Law in Nepal: Governed by the Information Technology Act, 2065 (2009).
- Penalties: Up to 10 years in prison for hacking (Section 13).
- Data Protection: Right to privacy under Article 14 of the Constitution.
- Ethical Hacking: Only authorized penetration testing is legal (e.g., NTC’s bug bounty program).
Exam Tip
- Focus on frameworks: NIST, ISO 27001, and COBIT are highly examinable.
- Compare threats vs. vulnerabilities: Always link them to real examples (e.g., Ncell’s SIM swapping).
- Risk treatment options: Know when to avoid, mitigate, transfer, or accept risk (cost-benefit analysis).
- Auditing vs. Penetration Testing: Distinguish between internal audits and ethical hacking.
- Nepal-specific examples: Always tie answers to NEPSE, NTC, eSewa, or Daraz for full marks.
- Worked examples: Practice quantitative risk analysis (e.g., calculate expected loss for a scenario).
Common Pitfalls:
- ❌ Confusing threats and vulnerabilities.
- ❌ Forgetting to mention risk treatment options.
- ❌ Not using real-world examples (examiners love this!).
Final Visual:
mindmap
root((Security Risk Management))
Framework
NIST SP 800-30
ISO 27001
COBIT
Steps
System Characterization
Threat Identification
Vulnerability Assessment
Risk Analysis
Risk Treatment
Tools
Penetration Testing
Vulnerability Scanners
Real-World
NEPSE (Stock Exchange)
NTC (Telecom)
Daraz (E-commerce)Based on the TU BIT syllabus for Information Security (BIT303), unit 9.
Discussion
Loading…