BIT303 Information Security

Information SecurityUnit 912 min read

Security Risk Assessment & Management: Threats, Vulnerabilities, and Mitigation

Unit 9 of Information Security introduces the systematic process of identifying, evaluating, and mitigating security risks in systems, networks, and organizations, using frameworks like NIST, ISO 27001, and COBIT to align with real-world cybersecurity challenges faced by banks, e-commerce platforms, and telecom provide

TAKEAWAYS:

  • Security risk assessment is a structured process to identify threats, vulnerabilities, and impacts, using frameworks like NIST SP 800-30 and ISO 27005.
  • Threats (e.g., hackers, natural disasters) and vulnerabilities (e.g., weak passwords, outdated software) are distinct but interact to create risk (probability × impact).
  • Risk treatment options include avoidance, mitigation, transfer, and acceptance, each with trade-offs in cost and effectiveness.
  • Security auditing (internal/external) and penetration testing are critical for validating controls and uncovering hidden vulnerabilities.
  • Nepal’s NEPSE and NTC use risk assessments to protect financial transactions and network infrastructure from cyber threats.
  • Real-world example: Daraz’s risk management involves queue-based attack prevention (DDoS mitigation) and customer data encryption to handle millions of transactions securely.

1. Definitions and Core Concepts

1.1 What is Security Risk Assessment?

Security risk assessment is the structured evaluation of threats, vulnerabilities, and their potential impact on an organization’s assets (data, systems, reputation). It answers:

  • What can go wrong?
  • How likely is it?
  • What are the consequences?

It is the first step in the risk management cycle:

flowchart TD
    A["Risk Assessment"] --> B["Risk Treatment"]
    B --> C["Risk Monitoring"]
    C --> A

Key frameworks:

  • NIST SP 800-30: U.S. standard for risk assessment (used by government and private sectors).
  • ISO 27005: International standard for information security risk management.
  • COBIT: Framework for IT governance and risk management (adopted by Nepal’s NEPSE for financial systems).

1.2 Threats vs. Vulnerabilities vs. Risk

Term Definition Example (Nepal Context)
Threat Any potential danger that could exploit a vulnerability. Hackers launching phishing attacks on eSewa users.
Vulnerability Weakness in a system that can be exploited by a threat. Outdated NTC routers with unpatched firmware.
Risk Probability × Impact of a threat exploiting a vulnerability. Daraz’s payment system being down due to DDoS.

Visualization:

flowchart TD
    A["Threat"] -->|"Exploits"| B["Vulnerability"]
    B -->|"If exploited"| C["Risk: Impact × Probability"]
    C --> D["Security Controls"]

2. Steps in Security Risk Assessment

A typical risk assessment follows 5 steps (based on NIST SP 800-30):

2.1 Step 1: System Characterization

  • Identify assets (data, systems, people) and their value.
  • Example: For Ncell, assets include:
    • Customer databases (high value).
    • SIM card authentication systems (critical).
    • Customer service chatbots (moderate value).

2.2 Step 2: Threat Identification

  • Internal threats: Employees (e.g., insider theft at Khalti).
  • External threats: Hackers, malware, natural disasters (e.g., earthquake disrupting NTC’s fiber optics).
  • Threat sources:
    • Human: Malicious insiders, social engineering.
    • Environmental: Power outages, floods.
    • Technical: Unpatched software, misconfigurations.

2.3 Step 3: Vulnerability Identification

  • Common vulnerabilities:
    • Weak passwords (e.g., Pathao driver app accounts).
    • Lack of encryption (e.g., unsecured Wi-Fi at cafes).
    • Default credentials (e.g., routers in homes).
  • Tools for detection:
    • Vulnerability scanners (Nessus, OpenVAS).
    • Penetration testing (ethical hacking).

2.4 Step 4: Risk Analysis

  • Qualitative vs. Quantitative Analysis:

    Method Description Example
    Qualitative Uses expert judgment (low/medium/high risk). NEPSE classifying stock trade risks.
    Quantitative Uses numerical values (e.g., dollar loss, downtime cost). Bank’s loan fraud risk = $500K/year.
  • Risk Matrix:

2.5 Step 5: Risk Treatment

  • Options for risk treatment:
    Option Description Example (Nepal)
    Avoidance Eliminate the risk entirely. NTC stopping use of legacy protocols.
    Mitigation Reduce risk (e.g., firewalls, encryption). eSewa using AES-256 for transactions.
    Transfer Shift risk to a third party (e.g., insurance). Daraz buying cyber insurance.
    Acceptance Accept residual risk if cost of mitigation > benefit. Small businesses using basic antivirus.

Worked Example: Scenario: A Nepali bank detects that ATM skimming (a threat) exploits weak PIN entry systems (vulnerability).

  • Risk: 10% chance of $20K loss annually.
  • Treatment Options:
    1. Mitigation: Install PIN pads with cameras ($50K cost).
    2. Transfer: Buy cyber insurance ($30K/year).
    3. Acceptance: If cost of mitigation > potential loss.

3. Security Auditing and Penetration Testing

3.1 Security Auditing Architecture

Auditing ensures controls are working. Types:

  • Internal Audit: Conducted by the organization’s own team.
  • External Audit: Conducted by third parties (e.g., ISO 27001 certification for NEPSE).

Security Auditing Process:

flowchart TD
    A["Plan Audit"] --> B["Gather Evidence"]
    B --> C["Analyze Findings"]
    C --> D["Report Issues"]
    D --> E["Remediation"]
    E --> A

3.2 Penetration Testing

  • Simulated cyberattacks to find vulnerabilities.
  • Types:
    • Black-box: Tester has no prior knowledge (like a real hacker).
    • White-box: Tester knows system details (e.g., NTC’s network topology).
    • Gray-box: Partial knowledge (e.g., Khalti’s API access).

Example:

  • Pathao hires a penetration tester to exploit weak authentication in its driver app.
  • Finds that default admin credentials are still active → Critical risk.

4. Risk Management Frameworks

Framework Description Used By (Nepal)
NIST SP 800-30 U.S. standard for risk assessment. NTC, Ncell (telecom sector).
ISO 27001 International standard for information security management. NEPSE, banks (financial sector).
COBIT IT governance framework. Government IT departments.
CIS Controls Critical security controls for cyber defense. eSewa, Khalti (payment systems).

5. Real-World Applications in Nepal

In the Real World

  1. NEPSE (Nepal Stock Exchange):

    • Uses: Risk assessment to protect trading systems from insider trading and DDoS attacks.
    • How: Implements ISO 27001 and penetration testing to detect vulnerabilities in real-time trading APIs.
  2. NTC (Nepal Telecommunications Authority):

    • Uses: Risk management for fiber optic networks against physical sabotage and cyber espionage.
    • How: Uses NIST SP 800-30 to assess risks from earthquakes (cutting cables) and hackers (SIM swapping).
  3. Daraz (E-commerce):

    • Uses: Risk assessment for payment gateways and customer data.
    • How: Encryption (AES-256) for transactions and DDoS protection to handle Black Friday sales spikes.

Worked Example: Kathmandu Traffic Routes (Analogy)

  • Threat: Accidents due to poor traffic management.
  • Vulnerability: No real-time GPS tracking for buses.
  • Risk: Delays for Pathao drivers and school buses.
  • Treatment:
    • Mitigation: Install smart traffic lights (like NTC’s fiber-based traffic control).
    • Transfer: Use insurance for delays.

6. Common Cyber Attacks and Their Risks

Attack Type Description Example (Nepal) Risk Level
Phishing Fake emails to steal credentials. eSewa users clicking malicious links. High
DDoS Overwhelming a system with traffic. Daraz’s checkout page crashing. Critical
SQL Injection Injecting malicious SQL to steal data. Khalti’s database exposed. High
Man-in-the-Middle Intercepting communications (e.g., MITM on unsecured Wi-Fi). Pathao driver app data stolen. Medium
Insider Threat Employees leaking data (e.g., bank tellers selling customer data). NEPSE insider trading. Critical

Visualization of Attack Flow:

sequenceDiagram
    participant Hacker
    participant Victim
    participant BankServer

    Hacker->>Victim: Sends phishing email (fake login page)
    Victim->>BankServer: Enters credentials (unaware)
    Hacker->>BankServer: Captures credentials

  • Cyber Law in Nepal: Governed by the Information Technology Act, 2065 (2009).
    • Penalties: Up to 10 years in prison for hacking (Section 13).
    • Data Protection: Right to privacy under Article 14 of the Constitution.
  • Ethical Hacking: Only authorized penetration testing is legal (e.g., NTC’s bug bounty program).

Exam Tip

  • Focus on frameworks: NIST, ISO 27001, and COBIT are highly examinable.
  • Compare threats vs. vulnerabilities: Always link them to real examples (e.g., Ncell’s SIM swapping).
  • Risk treatment options: Know when to avoid, mitigate, transfer, or accept risk (cost-benefit analysis).
  • Auditing vs. Penetration Testing: Distinguish between internal audits and ethical hacking.
  • Nepal-specific examples: Always tie answers to NEPSE, NTC, eSewa, or Daraz for full marks.
  • Worked examples: Practice quantitative risk analysis (e.g., calculate expected loss for a scenario).

Common Pitfalls:

  • ❌ Confusing threats and vulnerabilities.
  • ❌ Forgetting to mention risk treatment options.
  • ❌ Not using real-world examples (examiners love this!).

Final Visual:

mindmap
  root((Security Risk Management))
    Framework
      NIST SP 800-30
      ISO 27001
      COBIT
    Steps
      System Characterization
      Threat Identification
      Vulnerability Assessment
      Risk Analysis
      Risk Treatment
    Tools
      Penetration Testing
      Vulnerability Scanners
    Real-World
      NEPSE (Stock Exchange)
      NTC (Telecom)
      Daraz (E-commerce)

Based on the TU BIT syllabus for Information Security (BIT303), unit 9.

Discussion

Loading…