Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

7/3/2019
01:00 PM
Joshua Goldfarb
Joshua Goldfarb
Commentary
Connect Directly
Twitter
RSS
E-Mail vvv
50%
50%

20 Questions to Ask During a Real (or Manufactured) Security Crisis

There are important lessons to be learned from a crisis, even the ones that are more fiction than fact.

I've heard the statement "society doesn't deal with problems until they become a crisis" many times. Unfortunately, this is often the case in information security, but it doesn't need to be this way. As security practitioners, we can't fix the ills of society. We can, however, learn how to distinguish a real security crisis from a manufactured one. Furthermore, from each crisis (real or manufactured) that we go through, we can learn how to avert them all together.

In this spirit, I offer 20 questions to ask during a real or manufactured security crisis.

1. What is the threat that the issue at hand poses? Regardless of the noise surrounding a given situation, you need to understand the actual threat you're dealing with. Conjecture and hype won't help. Rather, you need to objectively understand how the threat could manifest itself as a risk to the organization.

2. What is the organization's exposure to the threat? Once you understand the threat, you can evaluate your exposure to that threat. This needs to be done in order to fully understand the gravity of the situation.

3. What risk does this threat pose to the organization? Once you understand the organization's exposure, you can assess the risk posed to the organization. This is where you really begin to understand how seriously to consider the threat and how aggressively to respond.

4. Is the hype surrounding this threat justified? Separating fact from fiction is important. If the facts support the hype surrounding a given threat, then it needs to be dealt with as such. However, if the facts tell a different story, it's time to spin this one down.

5. Does the hype surrounding the threat translate to a real risk for the organization? If the risk is real, then it's time to respond appropriately. That includes the communication necessary to keep the right stakeholders informed.

6. When did we first become aware of the issue? Were you just made aware of this, or have you been aware of it for quite some time? The difference is important. If you knew about a significant risk to the organization and didn't act on it or escalate appropriately, that's a fairly significant lapse in security.

7. Why wasn't this raised earlier? If there is a reason, it can be addressed as part of continual process improvement. If there is no reason, it's important to understand why.

8. Could we have avoided this issue? In many cases, issues can be avoided if risk assessment were done more proactively, or if the attack surface had been reduced significantly. Not in all cases, of course, but it's good to ask the question.

9. Why didn't we avoid this issue? Once you understand how you could have avoided an issue, you need to ask why you didn't.

10. Has any damage to the organization occurred? This is, of course, the quintessential question. If no damage occurred, you need to remediate the risk, learn from your mistakes, and be thankful. If damage has occurred, then you still need to remediate the risk, learn from your mistakes, and, of course, perform incident response.

11. What are the steps required to remediate the issue? If you need to respond and remediate, the first step is to map out the steps required to do so properly. Taking a few moments to get organized and ensure all bases are covered yields a higher-quality result and saves time down the line.

12. What are the lessons learned from this issue? After any issue is dealt with, lessons need to be extracted and studied. This allows the security organization to improve and mature.

13. Can we apply those lessons to avoid a similar situation in the future? Obviously, crisis mode is a last resort. If you can apply lessons learned, you can avoid making the same mistake.

14. What other potential crises might we encounter? Post-crisis is a great time to think outside of the box and do some analysis. Understanding what other pitfalls you may encounter allows you to mitigate those risks ahead of time and improve the security posture of the organization.

15. What else can we tighten up to avoid future issues? You may have patched, tightened controls, or improved monitoring after the crisis, but what else can you do to keep from having to relive this or a similar experience?

16. How can we ensure that our remediation of the issue will be effective? Your plan may sound good on paper, but to be more certain, map the technologies and applications the issue affects, then conduct a sanity check to see whether it will achieve your desired goals.

17. Have we verified that remediation was effective? If you've already remediated, have you tested to ensure that the remediation was effective? If not, you could be exposed to a recurrence.

18. What steps have we taken to avoid a similar situation in the future? You need to ensure that whatever remediation you've done, whatever lessons you've learned, and whatever improvements you've made are lasting and not a one-time fix.

19. Have we precisely and effectively communicated actions to management and executives? Regardless of whether or not you had a real crisis, whether or not you handled it appropriately, and whether or not you've made improvements to the security organization, your actions need to be documented and communicated to management and executives. This builds confidence in the security team's ability and avoids excessive spin-up when the next issue arises.

20. Have we taken steps to avoid future damage? In the end, it all comes down to whether or not you avoid or minimize damage to the organization. This is perhaps is the hardest question to answer. But it is likely the most important.

Related Content:

Black Hat USA returns to Las Vegas with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions, and service providers in the Business Hall. Click for information on the conference and to register. 

Josh (Twitter: @ananalytical) is currently Director of Product Management at F5.  Previously, Josh served as VP, CTO - Emerging Technologies at FireEye and as Chief Security Officer for nPulse Technologies until its acquisition by FireEye.  Prior to joining nPulse, ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
tdsan
50%
50%
tdsan,
User Rank: Ninja
7/7/2019 | 7:30:02 PM
Creating a framework to help address some of the questions brought up
NIST has a site where they provide similar questions but they revolve the questions about developing a framework. This framework is based on the Risk Management framework from NIST - Risk Assessment Framework chart.

The questions you bring up are listed in this flowchart, it addresses
  • Page 20 - Identify the threats and their severity
  • Page 24 - Mgmt, Operational, Technical Security
  • Page 31 - Risk Level Matrix with weights
  • Page 34 - Risk Mitigation Strategy
  • Page 39 - Technical Security Controls
  • Page 43 - Preventative Operational Controls
  • Page 46 - Implemented Controls and Residual Risk
  • Page 47 - Evaluation & Assessment (Good Security Practice/Keys to Success)
  • Page 48 - Sample Interview Questions (Acronym)*

* Interview questions that can assist in the assessment and risk mitigation strategy. Sample Questions listed below:
APPENDIX A: Sample Interview Questions Interview questions should be tailored based upon where the IT system assessed is in the SDLC. Sample questions to be asked during interviews with site personnel to gain an understanding of the operational characteristics of an organization may include the following:
  • Who are valid users?
  • What is the mission of the user organization?
  • What is the purpose of the system in relation to the mission?
  • How important is the system to the user organization's mission?
  • What is the system-availability requirement?
  • What information (both incoming and outgoing) is required by the organization?
  • What information is generated by, consumed by, processed on, stored in, and retrieved by the system?
  • How important is the information to the user organization's mission?
  • What are the paths of information flow?
  • What types of information are processed by and stored on the system (e.g., financial, personnel, research and development, medical, command and control)?
  • What is the sensitivity (or classification) level of the information?
  • What information handled by or about the system should not be disclosed and to whom?
  • Where specifically is the information processed and stored?
  • What are the types of information storage?
  • What is the potential impact on the organization if the information is disclosed to unauthorized personnel?
  • What are the requirements for information availability and integrity?
  • What is the effect on the organization's mission if the system or information is not reliable?
  • How much system downtime can the organization tolerate?
  • How does this downtime compare with the mean repair/recovery time?
  • What other processing or communications options can the user access?
  • Could a system or security malfunction or unavailability result in injury or death?

Todd
Manchester United Suffers Cyberattack
Dark Reading Staff 11/23/2020
As 'Anywhere Work' Evolves, Security Will Be Key Challenge
Robert Lemos, Contributing Writer,  11/23/2020
Cloud Security Startup Lightspin Emerges From Stealth
Kelly Sheridan, Staff Editor, Dark Reading,  11/24/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-27660
PUBLISHED: 2020-11-30
SQL injection vulnerability in request.cgi in Synology SafeAccess before 1.2.3-0234 allows remote attackers to execute arbitrary SQL commands via the domain parameter.
CVE-2020-27659
PUBLISHED: 2020-11-30
Multiple cross-site scripting (XSS) vulnerabilities in Synology SafeAccess before 1.2.3-0234 allow remote attackers to inject arbitrary web script or HTML via the (1) domain or (2) profile parameter.
CVE-2020-29127
PUBLISHED: 2020-11-30
An issue was discovered on Fujitsu Eternus Storage DX200 S4 devices through 2020-11-25. After logging into the portal as a root user (using any web browser), the portal can be accessed with root privileges when the URI cgi-bin/csp?cspid=&csppage=cgi_PgOverview&csplang=en is visit...
CVE-2020-25624
PUBLISHED: 2020-11-30
hw/usb/hcd-ohci.c in QEMU 5.0.0 has a stack-based buffer over-read via values obtained from the host controller driver.
CVE-2020-29378
PUBLISHED: 2020-11-29
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. It is possible to elevate the privilege of a CLI user (to full administrative access) by using the password [email protected]#y$z%x6x7q8c9z) for the e...