Security Process

What is ARBIL?Asset and Risk Based INFOSECorganization carry out its mission.Organizations should
lifecycle.To implement a comprehensive security plan inlook at threats, vulnerabilities, assets and
I.T. and strategies for risk management.What issafeguards.Risk AssessmentThe goal is to have a list
CIA?Confidentiality, Integrity, andof your critical assets. Critical in understanding mission,
AvailabilityConfidentiality- making sure your data isobjectives and operations and what if scenarios.Then
available to only those allowed.Integrity- making sureto implement safeguards to protect those
your data has not been altered in any way. Think bankassets.Vulnerability AssessmentThis is when you look
transactions or chemical formulas.Availability- makingfor vulnerabilities in existing applications and determine
sure your data is available. Hackers often use denial ofthere severity. The vulnerabilities will be rated. This
services attacks to bring down your servers orincludes physical security, web application reviews,
networks by overloading them with packets.Hackerspolicy and procedure reviews, host assessments and
use attack trees to determine every possible entranceOS reviews, and vulnerability scans.Threat
into your networks. This can be through modemsAssessmentThis is the process, of identifying existing
connected to your network, routers, switches, andand potential threats to assets and environments. This
application vulnerabilities, almost anything connected towill also be based on severity.Where can threats
your internet.Make it difficult to determine your OS,come from? Disgruntled employees, script kiddies,
which hackers use for Banner Grabbing. This is ahackers, crackers, foreign governments, and your
simple fix that many systems administratorscompetition. You can look for threat indicators in your
leave.Change your banner to display a securityserver, logs, CCTV, intrusion detection systems like
warning.Many people have difficulty understandingSNORT. can threats cause?Loss of business
security processes alone implementing solutions.WhatDeath
is SMIRA? Simple methodology for INFOSEC basedFinancial loss
risk assessment.Risk management is the practice andCorruption of data.
process of identifying threats and vulnerabilities toInability to work, servers down or running slowly.
assets. This helps making the correct decisions toConfidentiality issues.What are assets?
implement the necessary safeguards to help your