<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>risk Archives -</title>
	<atom:link href="https://zymitry.com/tag/risk/feed/" rel="self" type="application/rss+xml" />
	<link>https://zymitry.com/tag/risk/</link>
	<description>Tech &#38; Other Stuff</description>
	<lastBuildDate>Wed, 17 Dec 2025 06:16:24 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://i0.wp.com/zymitry.com/wp-content/uploads/2016/11/favicon.png?fit=32%2C32&#038;ssl=1</url>
	<title>risk Archives -</title>
	<link>https://zymitry.com/tag/risk/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">120106411</site>	<item>
		<title>Basics of Security Awareness: Users are the Weakest Link</title>
		<link>https://zymitry.com/principles-security-awareness/</link>
					<comments>https://zymitry.com/principles-security-awareness/#respond</comments>
		
		<dc:creator><![CDATA[Greg Palmer]]></dc:creator>
		<pubDate>Tue, 23 Jan 2018 21:47:39 +0000</pubDate>
				<category><![CDATA[System Security]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[training]]></category>
		<guid isPermaLink="false">https://zymitry.com/?p=902</guid>

					<description><![CDATA[<p>Basic Principles of Security Awareness. Security experts consider system users the weakest link in information security. User skill levels and experience can greatly vary, and unlike automated controls, human users can be subject to fatigue, or be distracted, which can lead to mistakes resulting in vulnerabilities. Security awareness training is often a user’s first experience… <span class="read-more"><a href="https://zymitry.com/principles-security-awareness/">Read More: Basics of Security Awareness: Users are the Weakest Link &#187;</a></span></p>
<p>The post <a href="https://zymitry.com/principles-security-awareness/">Basics of Security Awareness: Users are the Weakest Link</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Basic Principles of Security Awareness. Security experts consider system users the weakest link in information security. User skill levels and experience can greatly vary, and unlike automated controls, human users can be subject to fatigue, or be distracted, which can lead to mistakes resulting in vulnerabilities. Security awareness training is often a user’s first experience with information security. Most employees want to do a good job and do the right thing, but dependent on their skill level, they might not be aware how to practice good information security. Awareness training provides employees the following:</p>
<ul>
<li>Basic principles of information security</li>
<li>Awareness of information security threats and <a href="https://zymitry.com/risk-management-success/" target="_blank" rel="noopener">risks</a></li>
<li>How to recognize and react to unexpected <a href="https://zymitry.com/risk-management-success/" target="_blank" rel="noopener">risks</a> and <a href="https://web.archive.org/web/20230322085647/https://zymitry.com/information-incident-response/" target="_blank" rel="noopener">security events</a></li>
<li>How to report suspicious activity</li>
<li>Builds a security culture throughout the organization</li>
</ul>
<p>Techniques to keep security awareness fresh in user minds include:</p>
<ul>
<li>Ensure<a href="https://zymitry.com/leaderships-role-information-security/" target="_blank" rel="noopener"> executive and management support</a>. When top executives and management provide noticeable vocal support, it provides a sense of the importance of information security organization-wide.</li>
<li>Use awareness aids such as posters, newsletters, email tips, blogs, and other reminders. People are different and learn in different ways. Using different types of aids helps ensure that the message gets through to employees in many different areas of the organization.</li>
<li>Focus on changing behaviors. The goal is to create a culture of security. One way of doing this is relating awareness to employee’s personal life, family, and home. This allows employees to share security materials and information outside of work with family and friends making information security a part of their personal life as well. Make awareness engaging or interactive. This can often be fun for employees.</li>
<li>Solicit ideas and feedback. Ask employees how security awareness can be improved. This gets employees directly involved in security programs.</li>
<li>Measure success and growth. Track training completion. Get feedback on what employees like about training and what could use improvement.</li>
</ul>
<p>&nbsp;</p>
<p>References</p>
<p>Johnson, R. (2015). <em>Security Policies and Implementation Issues (2nd ed.).</em> Burlington, MA: Jones &amp; Bartlett Learning.</p>
<p>Lohrmann, D. (2014, March 09). <em>Ten Recommendations for Security Awareness Programs. </em>Retrieved September 20, 2017, from <a href="http://www.govtech.com/blogs/lohrmann-on-cybersecurity/Ten-Recommendations-for-Security-Awareness-Programs.html" target="_blank" rel="noopener">http://www.govtech.com/blogs/lohrmann-on-cybersecurity/Ten-Recommendations-for-Security-Awareness-Programs.html</a>.</p>
<p>The post <a href="https://zymitry.com/principles-security-awareness/">Basics of Security Awareness: Users are the Weakest Link</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zymitry.com/principles-security-awareness/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">902</post-id>	</item>
		<item>
		<title>Bring Your Own Device (BYOD) Policies and Practices</title>
		<link>https://zymitry.com/byod-policies-practices/</link>
					<comments>https://zymitry.com/byod-policies-practices/#respond</comments>
		
		<dc:creator><![CDATA[Greg Palmer]]></dc:creator>
		<pubDate>Sun, 21 Jan 2018 20:07:25 +0000</pubDate>
				<category><![CDATA[Information Security Compliance]]></category>
		<category><![CDATA[access]]></category>
		<category><![CDATA[byod]]></category>
		<category><![CDATA[controls]]></category>
		<category><![CDATA[policies]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">https://zymitry.com/?p=880</guid>

					<description><![CDATA[<p>Bring Your Own Device (BYOD): Organizations allowing employees to use their own personal devices such as smart phone and tablets to conduct organization business. The SANS Reading Room article, SANS Survey on Mobility/BYOD Security Policies and Practices found that 61% of organizations allowed personal devices to connect to protected company systems, but only 9% of… <span class="read-more"><a href="https://zymitry.com/byod-policies-practices/">Read More: Bring Your Own Device (BYOD) Policies and Practices &#187;</a></span></p>
<p>The post <a href="https://zymitry.com/byod-policies-practices/">Bring Your Own Device (BYOD) Policies and Practices</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Bring Your Own Device (<a href="https://zymitry.com/security-terms-acronyms/" target="_blank" rel="noopener">BYOD</a>): Organizations allowing employees to use their own personal devices such as smart phone and tablets to conduct organization business.</p>
<p>The SANS Reading Room article, SANS Survey on Mobility/BYOD Security <a href="https://zymitry.com/information-acceptable-use-policy-aup/" target="_blank" rel="noopener">Policies</a> and Practices found that 61% of organizations allowed personal devices to connect to protected company systems, but only 9% of organizations were truly aware of the particular devices that were connecting to protected systems, and what resources they were accessing. Of all the organizations polled, 60% responded that they have a <a href="https://zymitry.com/risk-management-success/" target="_blank" rel="noopener">risk</a> program in place, but 50% of those did not have BYOD<a href="https://zymitry.com/information-acceptable-use-policy-aup/"> Acceptable Use Policies</a> in place even though 95% of those surveyed stated they understood the importance of having a robust <a href="https://zymitry.com/security-policies-standards-procedures/" target="_blank" rel="noopener">policy</a> in place.</p>
<p>The SANS survey specifically mentioned that respondents listed that the most critical practices to implement included; data protection and encryption, secure access to corporate resources, knowing what sensitive data that personal devices can access, and requiring end point protection such as anti-malware, <a href="https://zymitry.com/importance-patch-management-microsoft-systems/" target="_blank" rel="noopener">mandatory updates and patches</a>, data loss prevention, and secure web browsing. Other practices not commonly mentioned in the survey included mandatory user education, application white and black listing, and <a href="https://zymitry.com/measurement-secure-software-development/" target="_blank" rel="noopener">secure distribution of applications</a>, example; corporate app store, keeping an inventory of installed apps, and mandatory “sandboxing”.</p>
<p>In addition to standard end-point controls, organizations should also practice secure network control, example; Virtual Private Networks (VPN), authentication to access data, and encrypting data in motion and at rest.</p>
<p>In conclusion, research shows that most organizations currently rely on traditional tried and true security controls when dealing with BYOD connections to protected systems. What was of note is that control over access can often be inconsistent and decentralized. Often the fall back or backup control was <a href="https://zymitry.com/security-policies-standards-procedures/" target="_blank" rel="noopener">policies</a> that did not specifically address BYOD. Often organizations do not have an organized and centralized way to secure BYOD access. Fortunately, many organizations are starting to respond to BYOD security concerns by implementing stronger <a href="https://zymitry.com/security-policies-standards-procedures/" target="_blank" rel="noopener">policies</a> and mobile-focused controls.</p>
<p>References</p>
<p>Johnson, K., DeLaGrange, T., &amp; Filkins, B. (2012, October). <em>SANS Survey on Mobility/BYOD Security Policies and Practices</em>. Retrieved September 3, 2017, from <a href="https://sansorg.egnyte.com/dl/EqV0VslGEr" target="_blank" rel="noopener">https://www.sans.org/webcasts/survey-results-byod-security-policies-practices-95940/</a>.</p>
<p>Johnson, R. (2015). <em>Security Policies and Implementation Issues (2nd ed.). </em>Burlington, MA: Jones &amp; Bartlett Learning.</p>
<p>The post <a href="https://zymitry.com/byod-policies-practices/">Bring Your Own Device (BYOD) Policies and Practices</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zymitry.com/byod-policies-practices/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">880</post-id>	</item>
		<item>
		<title>Mitigating Insider Security Threats</title>
		<link>https://zymitry.com/mitigating-insider-security-threats/</link>
					<comments>https://zymitry.com/mitigating-insider-security-threats/#respond</comments>
		
		<dc:creator><![CDATA[Greg Palmer]]></dc:creator>
		<pubDate>Sat, 20 Jan 2018 01:00:27 +0000</pubDate>
				<category><![CDATA[System Security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[insider]]></category>
		<category><![CDATA[mitigating]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[threats]]></category>
		<guid isPermaLink="false">https://zymitry.com/?p=853</guid>

					<description><![CDATA[<p>Threats from within an organization. Insider security threats are the most significant threat to today’s information systems. Insiders often have elevated access within an organizations information systems which often gives them a level of authorized access that can cause a lot of damage if misused intentionally, or unintentionally. In the SANS Reading Room article; Insider… <span class="read-more"><a href="https://zymitry.com/mitigating-insider-security-threats/">Read More: Mitigating Insider Security Threats &#187;</a></span></p>
<p>The post <a href="https://zymitry.com/mitigating-insider-security-threats/">Mitigating Insider Security Threats</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><strong>Threats from within an organization.</strong></p>
<p>Insider security threats are the most significant threat to today’s information systems. Insiders often have elevated access within an organizations information systems which often gives them a level of authorized access that can cause a lot of damage if misused intentionally, or unintentionally.</p>
<p>In the SANS Reading Room article; <a href="https://www.sans.org/reading-room/whitepapers/monitoring/insider-threat-mitigation-guidance-36307room/whitepapers/monitoring/insider-threat-mitigation-guidance-36307room/whitepapers/monitoring/insider-threat-mitigation-guidance-36307" target="_blank" rel="noopener">Insider Threat Mitigation Guidance</a>, Balakrishnan &amp; Northcutt explain that mitigating insider threats is often a complex procedure that requires meticulous planning.  Organizations should tailor their approach to ensure that mitigation techniques meet the organizations unique needs.</p>
<p>Balakrishnan &amp; Northcutt lay out a 13 step Insider Threat Mitigation Program (ITMP) road map developed by the Intelligence and National Security Alliance (INSA) as a framework for identifying and mitigating insider threats. This framework maps insider threats to mitigation controls published by the Community Emergency Response Team (CERT), and the National Institute of Standards and Technology (NIST) threat programs and best practices. The ITMP framework steps are as follows</p>
<p><span style="text-decoration: underline;">Step 1:</span> Initial Planning. CERT Program components include; establish insider threat program and framework, implement planning, and formalize the program. CERT best practices used are a formalized insider threat program, and asset identification and control. NIST best practices are asset management.</p>
<p><span style="text-decoration: underline;">Step 2:</span>  Identify stakeholders. CERT practice is to identify all areas of the business affected.</p>
<p><span style="text-decoration: underline;">Step 3:</span>  Leadership buy-in.</p>
<p><span style="text-decoration: underline;">Step 4:</span>  Risk Management. CERT program components are enterprise risk management integration. Best practices include considering all insider threats enterprise-wide, and identifying a risk management program.</p>
<p><span style="text-decoration: underline;">Step 5:</span>  Detailed project planning.</p>
<p><span style="text-decoration: underline;">Step 6:</span>  Develop Governance Structure, Policy, and Procedures. Program CERT components are Policies, Procedures, and Practices, and protection of employee civil liberties and rights. Best practices include:</p>
<ul>
<li>Document and consistently enforce policies</li>
<li>A hiring process that screens employees for disruptive behavior</li>
<li>Anticipate and manage negative issues in the work environment</li>
<li>Implement and enforce strict password and management policies</li>
<li>Enforce principles of separation of duties and least privilege</li>
<li>Explicit Service Level Agreements (SLA)’s for all vendors and cloud services</li>
<li>Stringent access controls</li>
<li>Institutionalize system changes</li>
<li>Comprehensive employee termination procedures</li>
<li>Stringently monitoring social media content</li>
</ul>
<p><span style="text-decoration: underline;">Step 7:</span>  Communication training and awareness. Components are training and awareness, and communicating insider threats. Best practices include insider threat and awareness training, and communication response.</p>
<p><span style="text-decoration: underline;">Step 8:</span>  Develop detection methods. Components are prevention, detection, and response. Best practices include establish baselines, monitor and close data exfiltration holes, monitor and detect anomaly events.</p>
<p><span style="text-decoration: underline;">Step 9:</span>  Data and tool requirements. Components are data collection and analysis. Best practices include Security Information Event Management (SIEM) that encompasses logging and auditing of systems, and protecting access controls and auditing technology.</p>
<p><span style="text-decoration: underline;">Step 10:</span>  Data fusion. Component is data collection and analysis.</p>
<p><span style="text-decoration: underline;">Step 11:</span>  Analysis and incident management. Components are incident response and reporting. Best practices include response and mitigation analysis.</p>
<p><span style="text-decoration: underline;">Step 12:</span>  Management reporting. Components are program compliance and effectiveness oversight.</p>
<p><span style="text-decoration: underline;">Step 13:</span>  Feedback and lessons learned. Best practices include recovery planning, improvements, and communications.</p>
<p>&nbsp;</p>
<p>Overall it is widely recognized that insider threats are the most prevalent and damaging which is line with what both Johnson (2015), and Balakrishnan &amp;Northcutt (2015), have examined and supported. Organizations spend great amounts of money on technical controls such as firewalls, <a href="https://zymitry.com/ids-idps-detection-methods/" target="_blank" rel="noopener">Intrusion Detection (IDS) systems</a>, and anti-malware, but these controls lose much of there benefit when uneducated or careless users click on a phishing email links or exhibit other risky behaviours. Other technical controls can limit the damage, but an organization can still find itself spending a lot of time repairing damage caused by insider threats.</p>
<p>&nbsp;</p>
<p>References</p>
<p>Balakrishnan, B., &amp; Northcutt, S. (2015, October 06). <em>Insider Threat Mitigation Guidance, GIAC  </em><em>GLEG Gold Paper</em>. Retrieved August 25, 2017, from<a href="https://www.sans.org/reading-room/whitepapers/monitoring/insider-threat-mitigation-guidance-36307room/whitepapers/monitoring/insider-threat-mitigation-guidance-36307room/whitepapers/monitoring/insider-threat-mitigation-guidance-36307" target="_blank" rel="noopener"> https://www.sans.org/reading-room/whitepapers/monitoring/insider-threat-mitigation-guidance-36307room/whitepapers/monitoring/insider-threat-mitigation-guidance-36307room/whitepapers/monitoring/insider-threat-mitigation-guidance-36307</a>.</p>
<p>Johnson, R. (2015). <em>Security Policies and Implementation Issues (2nd ed.).</em> Burlington, MA: Jones &amp; Bartlett Learning.</p>
<p>The post <a href="https://zymitry.com/mitigating-insider-security-threats/">Mitigating Insider Security Threats</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zymitry.com/mitigating-insider-security-threats/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">853</post-id>	</item>
		<item>
		<title>The Governance of Cloud-Based Systems</title>
		<link>https://zymitry.com/governance-cloud-systems/</link>
					<comments>https://zymitry.com/governance-cloud-systems/#respond</comments>
		
		<dc:creator><![CDATA[Greg Palmer]]></dc:creator>
		<pubDate>Tue, 29 Nov 2016 22:09:15 +0000</pubDate>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[agreement]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[Governance]]></category>
		<category><![CDATA[legal]]></category>
		<category><![CDATA[Negligence]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[Rights]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SLA]]></category>
		<guid isPermaLink="false">http://zymitry.com/?p=345</guid>

					<description><![CDATA[<p>The Governance of Cloud-Based Systems The Dot Com crash of 2000 and corporate scandals such as Enron highlighted the need for better laws to oversee financial organizations, and also highlighted the need for better corporate governance. IT Governance is the part of corporate governance that includes policies, procedures, and controls that relate to information systems… <span class="read-more"><a href="https://zymitry.com/governance-cloud-systems/">Read More: The Governance of Cloud-Based Systems &#187;</a></span></p>
<p>The post <a href="https://zymitry.com/governance-cloud-systems/">The Governance of Cloud-Based Systems</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></description>
										<content:encoded><![CDATA[<h2 class="TextBody" style="margin-bottom: 0.0001pt; line-height: 200%; text-align: left;" align="center"><span style="font-family: 'Times New Roman','serif'; color: #010101;">The Governance of Cloud-Based Systems</span></h2>
<p>The Dot Com crash of 2000 and corporate scandals such as Enron highlighted the need for better laws to oversee financial organizations, and also highlighted the need for better corporate governance. IT Governance is the part of corporate governance that includes policies, procedures, and controls that relate to information systems use, performance, Return on Investment (ROI), and risk mitigation</p>
<p>When a company moves services to the cloud it must naturally extend its IT governance to include cloud-based systems and services. Governance includes policies, procedures, and controls that ensure confidence in the accuracy and security of the cloud-based systems, and also ensures the strategic alignment of cloud-based systems with the organizations goals. A key component of the governance process begins with Service Level Agreements (SLA)’s that specify contractual obligations that a cloud vendor must provide and adhere to. One important governance issue that is normally specified in a SLA is limited liability provisions. Fox (2015) states that customers generally want service provider&#8217;s liability responsibility to include, among other obligations, coverage for claims arising out of the following:</p>
<ul>
<li>Allegations that the cloud services provided by the vendor infringe upon, or violate, the intellectual property or other proprietary rights of any third party.</li>
</ul>
<ul>
<li>Negligence or willful misconduct of the cloud service provider, including its contractors and agents.</li>
</ul>
<ul>
<li>Claims that the cloud service provider including its contractors and agents caused any bodily injury to the customer&#8217;s staff, or property damage to the customer&#8217;s property.</li>
</ul>
<ul>
<li>A breach of any of the cloud service provider&#8217;s data or system security as well as any other customer data privacy obligations.</li>
</ul>
<p>&nbsp;</p>
<p>In contrast, cloud service providers usually try and reduce the scope of their liability towards customers by attempting to negotiate SLA provisions in their favor, for example, trying to limit its liability obligations to customers using a cap on the amount that it is obligated to indemnify the customer for. Customers who agree to caps run the risk of being held accountable for damages that exceed the cap limit even if the damages can be attributed to the provider, provider contractors, and other third-parties that may be associated with the cloud provider (Fox, 2015).</p>
<p>&nbsp;</p>
<h4>Summary</h4>
<p>Regarding the governance of cloud-based systems, it is of utmost importance that customers clearly understand that if their IT systems are hosted on a cloud-based system, their IT governance extends to include those systems. Service Level agreements with cloud providers are a method that organizations can use to extend that governance to cloud-based systems which specifies a level of service that a vendor agrees to provide, and contains provisions that specify items such as liability.</p>
<p>&nbsp;</p>
<p>References</p>
<p>Fox, A. (2015, May 07). <em>Common Mistakes Made by Customers and Service Providers when Negotiating Cloud Services Agreements.</em> Retrieved August 10, 2017, from Association of Corporate Counsel, http://www.acc.com/legalresources/quickcounsel/negotiating-cloud-services-agreements.cfm.</p>
<p>&nbsp;</p>
<p><a href="http://zymitry.com/zymitry-disclaimer/" target="_blank" rel="noopener noreferrer">Disclaimer</a></p>
<p>The post <a href="https://zymitry.com/governance-cloud-systems/">The Governance of Cloud-Based Systems</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zymitry.com/governance-cloud-systems/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">345</post-id>	</item>
		<item>
		<title>Security Threats to Cloud–Based Systems</title>
		<link>https://zymitry.com/security-threats-cloud-based-systems/</link>
					<comments>https://zymitry.com/security-threats-cloud-based-systems/#respond</comments>
		
		<dc:creator><![CDATA[Greg Palmer]]></dc:creator>
		<pubDate>Tue, 29 Nov 2016 19:31:41 +0000</pubDate>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[attacks]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[mitigate]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[threats]]></category>
		<guid isPermaLink="false">http://zymitry.com/?p=333</guid>

					<description><![CDATA[<p>Security Threats to Cloud–Based Systems Threats to both cloud-based and on-site solutions should be evaluated with an additional focus directed towards security issues specific to cloud services. Cloud security threats can come from internal or external sources, and can originate as human or software based attacks. Threat agents are as follows; anonymous attackers, malicious service… <span class="read-more"><a href="https://zymitry.com/security-threats-cloud-based-systems/">Read More: Security Threats to Cloud–Based Systems &#187;</a></span></p>
<p>The post <a href="https://zymitry.com/security-threats-cloud-based-systems/">Security Threats to Cloud–Based Systems</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></description>
										<content:encoded><![CDATA[<h2 style="text-align: left;" align="center">Security Threats to Cloud–Based Systems</h2>
<p>Threats to both cloud-based and on-site solutions should be evaluated with an additional focus directed towards security issues specific to cloud services. Cloud security threats can come from internal or external sources, and can originate as human or software based attacks. Threat agents are as follows; anonymous attackers, malicious service agents, trusted attackers, and malicious insiders. The following is a list of common security threats to cloud-based environments and methods that can be used to mitigate them.</p>
<ul>
<li>Traffic eavesdropping. This is a passive attack that can occur when data is being transmitted between cloud services and clients. This include actions such as packet sniffing which examines data in transmission packets, and Man-In-The-Middle (MITM) attacks where an attacker intercepts transmission packets, then can alter messages before forwarding them to their destination.  A MITM attack commonly uses a technique called ARP spoofing. Example, trick user 1 computer into thinking that it is communicating with user 2 computer, and vice versa. To prevent these types of attacks communications between machines should take place over Virtual Private Networks (VPN) when possible. Another mitigation strategy is to ensure communications use Secure Socket Layer (SSL) protocols. Example, web traffic using HTTPS instead of HTTP.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Denial of Service. Denial of Service (DoS), and Distributed Denial of Services (DDoS) occur when an attacker uses one or many different computers to send a bombardment of message traffic to a system to try and overwhelm it’s resources and take them out of use. Defending against DoS and DDoS attacks is difficult and common strategies to mitigate them usually apply only after the attack has started and caused problems. The best defense against these types of attacks are specialized network firewalls designed to track and recognize DoS attacks, and the use of a number of reverse proxy mechanisms. Reverse proxies determine if incoming traffic is legitimate and allows or drops the incoming packets accordingly.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Insufficient Authorization. This attack occurs when access or unauthorized levels of access are granted to an attacker in error. This can occur from weak authentication vulnerabilities related to weak passwords or shared accounts. The best protection against this threat includes both logical and physical security controls. Logical controls include administrative policies such as password policies, use firewalls and keep them updated, and auditing of systems. Physical controls include keeping system equipment in locked spaces with controlled access.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Virtualization Attacks. Since cloud service providers often grant customers administrative rights to virtualized resources, this means they might also be used to attack underlying IT resources. This attack is commonly known as hyperjacking and it is directed towards the virtualization hypervisor software layer where an attacker will try and get control over the hypervisor and gain access to the underlying hardware. Controls such as separate Virtual Local Area Network (VLAN) connections for each service, and the use of separate management networks are the most effective way to mitigate hyperjacking attacks. Example, keep web facing traffic separate from internal traffic, and keep management interfaces on networks separate from all other services.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Overlapping Trust Boundaries. Since cloud services often share resources among many different customers great care must be taken in establishing boundaries between them. Attackers can target shared resources with the intention of compromising other customers, or the underlying infrastructure as a way to get access to other customers resources. This attack can also include guest-hopping. This is an attack where an attacker might have access to one Operating System (OS), and use that access to try and compromise a different OS within the same cloud system. Establishing secondary private VLANs for each entity provides traffic isolation and is the ideal method for mitigating this threat.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Malicious Employees. Staff such as software developers often has extensive access to systems which can be misused by disgruntled or terminated employees. Moving services to the cloud reduces this risk with local employees, but cloud service staff still require a stringent screening. Malicious insider threats can be mitigated by using access controls, policies and enforcement, and layered security. Examples; Access controls should be put in place so employees and third-parties can only access specified information and systems. A policy that would explain that when employees and contractors fail to comply, they could face termination of their employment or contractual relationship and lawsuits depending on how the information was misused. Taken together these methods form layered security.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>SQL Injection. This type of attack is directed towards trying to compromise or gain control over database servers and databases. It commonly takes advantage of form type data being sent from a client such as a web browser to an application database server. The attacker alters “injects” their own SQL commands into the data being sent to the server in order to get control of the server, or force the server to divulge data within the database. Controls to mitigate SQL injection threats include; use parameterized queries, use stored procedures, include code that escapes all user supplied input, enforce the concept of least privilege on user access, and the use of white lists to validate user inputs.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Compromised Interfaces and API’s. APIs and interfaces are commonly the most exposed part of a system because they&#8217;re usually accessible from the open Internet. The use of separate VLAN’s for API and management traffic is the most effective method of mitigating this threat.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Data Loss. Cloud providers generally provide multiple layers of redundancy and extensive data replication. Although a rare occurrence, data loss due to provider error or system problems can still occur. Cloud providers recommend distributing data and applications across multiple zones as additional protection against this threat.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Loosely defined service contracts. Sometimes organizations do not fully understanding cloud provider contracts and environments and encounter many commercial, financial, technical, legal, and compliance risks. The Cloud Security Alliance (CSA) states that organizations must perform extensive due diligence to understand the risks they assume when they subscribe to a cloud service as the primary mitigation strategy for this risk.</li>
</ul>
<p>&nbsp;</p>
<h4>Conclusions</h4>
<p>Cloud-based services are exposed to many of the same threats that on-site services are. To protect against these threats, the use of established and proven mitigation strategies should be applied. It is important to recognize though that cloud-based environments are subject to additional threats such as virtualization attacks that do require additional assessment and controls to mitigate the additional security risks. If the common and specific security risks are both properly mitigated, cloud-based services should be just as safe to use as on-site services.</p>
<p>&nbsp;</p>
<p>References</p>
<p>Berry-Tayman, L. (2015, January 16). <em>3 Ways to Protect Your Company Against Malicious Insiders. </em>Retrieved July 28, 2016, from <a href="https://web.archive.org/web/20160801063521/http://idt911.com/education/blog/3-ways-to-protect-your-company-against-malicious-insiders" target="_blank" rel="noopener noreferrer">http://idt911.com/education/blog/3-ways-to-protect-your-company-against-malicious-insiders</a>.</p>
<p>Burns, S. (2015, August 05). <em>Virtualization Security Tips: Preventing Hyper Jumping</em>. Retrieved July 28, 2016, from http://www.tomsitpro.com/articles/virtual-security-tips-hyper-jumping,2-776.html.</p>
<p>CloudPatterns. (n.d.). <em>Data Link and Network Layer Trust Boundary Isolation.</em> Retrieved July 28, 2016, from http://cloudpatterns.org/candidate_patterns/data_link_and_network_layer_trust_boundary_isolation.</p>
<p>Hargrave, V. (2012, November 28). <em>What Are Man-in-the-Middle Attacks and How Can I Protect Myself From Them? </em>Retrieved July 28, 2016, from <a href="http://blog.trendmicro.com/what-are-man-in-the-middle-attacks-and-how-can-i-protect-myself-from-them/" target="_blank" rel="noopener noreferrer">http://blog.trendmicro.com/what-are-man-in-the-middle-attacks-and-how-can-i-protect-myself-from-them/</a>.</p>
<p>OWASP Prevent SQL Injection. (2016, May 25). <em>SQL Injection Prevention Cheat Sheet. </em>Retrieved July 28, 2016, from <a href="https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html" target="_blank" rel="noopener noreferrer">https://www.owasp.org/index.php/SQL_Injection_Prevention_Cheat_Sheet</a>.</p>
<p>Rashid, F. (2016, March 11). <em>The dirty dozen: 12 cloud security threats.</em> Retrieved July 27, 2016, from <a href="https://web.archive.org/web/20171127225731/https://www.infoworld.com/article/3041078/security/the-dirty-dozen-12-cloud-security-threats.html" target="_blank" rel="noopener noreferrer">http://www.infoworld.com/article/3041078/security/the-dirty-dozen-12-cloud-security-threats.html</a>.</p>
<p>Schultz, G. (2006, August 03). <em>Top 10 ways to secure your stored data.</em> Retrieved July 28, 2016, from <a href="https://web.archive.org/web/20190204122333/https://www.computerworld.com/article/2546352/data-center/top-10-ways-to-secure-your-stored-data.html" target="_blank" rel="noopener noreferrer">http://www.computerworld.com/article/2546352/data-center/top-10-ways-to-secure-your-stored-data.html</a>.</p>
<p>Weiss, A. (2012, July 02). <em>How to Prevent DoS Attacks.</em> Retrieved July 28, 2016, from <a href="https://web.archive.org/web/20191022184723/https://www.esecurityplanet.com/network-security/how-to-prevent-dos-attacks.html" target="_blank" rel="noopener noreferrer">http://www.esecurityplanet.com/network-security/how-to-prevent-dos-attacks.html</a>.</p>
<p>&nbsp;</p>
<p><a href="http://zymitry.com/zymitry-disclaimer/" target="_blank" rel="noopener noreferrer">Disclaimer</a></p>
<p>The post <a href="https://zymitry.com/security-threats-cloud-based-systems/">Security Threats to Cloud–Based Systems</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zymitry.com/security-threats-cloud-based-systems/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">333</post-id>	</item>
		<item>
		<title>Risk management is essential to the success of every company</title>
		<link>https://zymitry.com/risk-management-success/</link>
					<comments>https://zymitry.com/risk-management-success/#respond</comments>
		
		<dc:creator><![CDATA[Greg Palmer]]></dc:creator>
		<pubDate>Sun, 27 Nov 2016 17:21:37 +0000</pubDate>
				<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[800-30]]></category>
		<category><![CDATA[business assets]]></category>
		<category><![CDATA[business functions]]></category>
		<category><![CDATA[business risk]]></category>
		<category><![CDATA[cost of risk]]></category>
		<category><![CDATA[identify]]></category>
		<category><![CDATA[information systems]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[mitigate]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[profitability]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[risk management frameworks]]></category>
		<category><![CDATA[risk mitigation]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sucess]]></category>
		<category><![CDATA[survivability]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[vulnerability]]></category>
		<guid isPermaLink="false">http://zymitry.com/?p=307</guid>

					<description><![CDATA[<p>In business, understanding and managing risk is crucial for success. Risk refers to the potential loss that may occur when a threat exposes a vulnerability within an organization. To thrive, businesses must take calculated risks while also recognizing the importance of risk mitigation. This article explores various risk-related concerns, including compromised business functions, business assets, the cost of risk management, profitability, and survivability. It emphasizes the need for a comprehensive risk management program to protect businesses from potential losses and ensure their long-term success.</p>
<p>The post <a href="https://zymitry.com/risk-management-success/">Risk management is essential to the success of every company</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></description>
										<content:encoded><![CDATA[<h2>Risk management is essential to the success of every company</h2>
<p>&nbsp;</p>
<p><strong>Risk management is essential to the success of every company</strong></p>
<p><em>Revised July 1, 2023</em></p>
<p>Risk is an inherent aspect of business operations, representing the likelihood of a loss occurring when a threat exposes a vulnerability. While organizations need to take risks to thrive, they must also recognize the importance of managing those risks. To effectively mitigate risks, it is crucial to understand the threats and vulnerabilities involved and take appropriate measures to reduce vulnerability or minimize the impact of the risks. Consider the following risk-related concerns:</p>
<ol>
<li><span style="text-decoration: underline;">Compromise of Business Functions:</span> The activities performed by a business to sell products or services can be negatively affected by threats. If these essential functions are compromised, the organization may experience a significant loss of revenue.</li>
<li><span style="text-decoration: underline;">Business Assets:</span> Business assets encompass anything of measurable value to a company, which can be tangible or intangible. This includes items such as repair costs, lost revenue, loss of future revenue, cost of gaining customers, customer influence, IT system equipment, network equipment, software, and data. Protecting these assets is vital for the overall well-being of the organization.</li>
<li><span style="text-decoration: underline;">Driver of Business Costs:</span> Risk management controls add an additional cost to running a business. While managing risks is essential, it is crucial to strike a balance between risk mitigation and cost-effectiveness in order to optimize business operations.</li>
<li><span style="text-decoration: underline;">Profitability vs. Survivability:</span> Profitability reflects a company&#8217;s ability to make a profit, while survivability refers to its ability to withstand losses resulting from risks. It is important to allocate funds for risk mitigation while considering their impact on profitability. Risk management should involve weighing the cost of risk controls against the potential threats that can jeopardize the company&#8217;s survivability. Over-investing in risk controls can hinder profit generation and fail to adequately address significant threats, potentially leading to business failure.</li>
</ol>
<p>The National Institute of Standards and Technology (NIST) Special Publication 800-30 provides a guideline for applying risk management frameworks to federal information systems. This publication emphasizes that organizations heavily rely on information technology and systems to carry out their missions and business functions. Recognizing the growing danger posed by threats, it is crucial for leadership at all levels of an organization to prioritize the management of information system-related security risks and implement well-defined risk management systems.</p>
<p>In summary, since risk can result in losses that negatively affect business functions and even cause a business to fail, implementing a comprehensive risk management program is essential for the success and sustainability of every company.</p>
<h4>References and Related Articles</h4>
<p><a href="https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final" target="_blank" rel="noopener">https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final</a></p>
<p><a href="https://web.archive.org/web/20240725064719/https://www.forbes.com/sites/steveculp/2020/10/01/why-risk-management-is-more-important-than-ever/?sh=7ee5469a30b6" target="_blank" rel="noopener">https://www.forbes.com/sites/steveculp/2020/10/01/why-risk-management-is-more-important-than-ever/?sh=7ee5469a30b6</a></p>
<h4>Additional Articles</h4>
<p><a href="https://zymitry.com/sarbanes-oxley-act-sox-finanical-reporting/" target="_blank" rel="noopener">Sarbanes-Oxley Act (SOX): Strengthening Financial Reporting and Accountability</a></p>
<p><a href="https://zymitry.com/network-data-compression-performance/" target="_blank" rel="noopener">Compression of Network Data and Performance Issues</a></p>
<p><a href="https://zymitry.com/cloud-acrchitectural-models/" target="_blank" rel="noopener">Cloud Architecture Models</a></p>
<p><a href="https://zymitry.com/artificial-intelligence-implications-exploration/" target="_blank" rel="noopener">Exploring the Implications of Artificial Intelligence</a></p>
<p><a href="https://zymitry.com/artificial-intelligence-texas-higher-ed/" target="_blank" rel="noopener">Artificial Intelligence in Texas Higher Education: Ethical Considerations, Privacy, and Security</a></p>
<p>&nbsp;</p>
<p><span style="font-size: 10pt;"><strong>Note:</strong> <em>This article has been drafted and improved with the assistance of AI, incorporating ChatGPT suggestions and revisions to enhance clarity and coherence. The original research, decision-making, and final content selection were performed by a human author.</em></span></p>
<p><a href="http://zymitry.com/zymitry-disclaimer/" target="_blank" rel="noopener noreferrer">Disclaimer</a></p>
<p><a href="https://zymitry.com/terms-conditions-use/" target="_blank" rel="noopener">Terms and Conditions of Use</a></p>
<p>The post <a href="https://zymitry.com/risk-management-success/">Risk management is essential to the success of every company</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zymitry.com/risk-management-success/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">307</post-id>	</item>
	</channel>
</rss>
