200 likes | 384 Vues
Risk Assessment. Farrokh Alemi, Ph.D. Monday, July 14, 2003. Objectives. To assess the probability of release of PHI Almost never occurs When it occurs, steps are taken to avoid it happening in same fashion in future. Risk Analysis. A set of scenarios Probability of occurrence of hazard
E N D
Risk Assessment Farrokh Alemi, Ph.D. Monday, July 14, 2003
Objectives • To assess the probability of release of PHI • Almost never occurs • When it occurs, steps are taken to avoid it happening in same fashion in future
Risk Analysis • A set of scenarios • Probability of occurrence of hazard • Probability of containment • Probability of consequence
Historical Precedence • Aerospace industry and Apollo flights • Accidents lead to revision of probabilities • Nuclear industry • Three mile island led to revisions
Law of Total Probability p (B) = i p(B|Ai) p(Ai) A2 A3 B A4 A1
Fault Tree Analysis • The top event is release of PHI • The intermediate events are ways in which PHI can be released • The basic events are observable events • Fault trees rely on Boolean logic to analyze probability of an event • “And” is shown as • “Or is shown as
Components of Risk Analysis • EPHI boundary definition • Threat identification • Vulnerability identification • Security control analysis • Risk likelihood determination • Impact analysis • Risk determination • Security control recommendations Based on Steve Weil’s recommendations
Inventory of PHI Internal and external interfaces of information systems Identification of the primary users of the information systems and PHI Top Event: PHI Definition
Intermediate Events: Threats Unauthorized Disclosure Natural Human Environment Flood HAZMAT Intentional Unintentional Hurricane Power Failure Omission Error entry Physical IT attack
Basic Events: Causes of Intermediate Events IT Attack Successful IT Attacked Controls fail Access Network failure Desktop Spy ware Authentication
Boolean Algebra • If X and Y must happen before the event happens, the probability of the event is p(X)p(Y) • If X or Y can lead to the event, then the probability of the event is p(X) + p(Y)
Unauthorized Disclosure Natural Human Environment Flood HAZMAT Intentional Unintentional Hurricane Power Failure Omission Error entry Physical IT attack Equivalent Descriptions • P(Unauthorized disclosure) = p(Natural) + p(Human) + p(Environment) • P(Natural) = p(Flood) + p(Hurricane) • P(Human) = p(Intentional) + p(Unintentional) • P(Intentional) = p(Physical) + p(IT attack) • Etc.
IT Attack Successful IT Attacked Controls fail Access Network failure Desktop Spy ware Authentication Equivalent Descriptions • P(IT attack successful) = p(IT attack) . p(Controls failure) • P(IT attack) = p(Network) + p(Desktop) • P(Control failure) = p(authentication) + p(Access)
Assessment of Basic Event Probabilities • Subjective • Frequency • One observation of rare event after s days of success • P(day of success)=Number of days of success / (1 + Number of days of success) • Provides a procedure for converting days between two failures to probability of failure • Last flood was 2 months ago, what is probability of no floods in any day? =1 - 59/60 • On average time between virus infection of desk top is 2 weeks, what is probability of infection per day? = 1/14
Estimate Probability of Unauthorized Disclosure Unauthorized Disclosure Natural Human Environment Flood HAZMAT Intentional Unintentional Hurricane Power Failure Omission Error entry Physical IT attack
Recommendations After Risk Assessment • Mitigate • Eliminate • Insure • Hedge