IT architecture-based confidentiality risk assessment in networks of organizations

Ayşe Moralı · 2011

Today almost every organization benefits from business opportunities created by digitalization.Digitalization allows, among others, to develop software products on shared platforms, to remotely access and alter patient records or remotely control power generators.This change in the technical environment has triggered changes in the legal environment, and introduced new compliance requirements.Consequently, protecting the confidentiality of digital information assets has become a major concern for many organizations.This concern is even bigger for organizations that connect their IT system with other organizations to reduce costs.Risk assessment methodologies provide stakeholders with sound knowledge on security risks that threaten the business.A risk assessment method should satisfy three conflicting requirements: accuracy, cost-efficiency, and inter-subjectivity.These three requirements form the dilemma of confidentiality risk assessment methods.Accuracy has to do with the level of granularity that a method allows when assessing the risk.Cost-efficiency is the crucial real limitation of all risk assessment methods.In practice, even risk assessments of large and information-intensive company sections rarely last longer than two weeks.The third requirement we look at in this dissertation is intersubjectivity.Nowadays, despite the large use of standardized methods, the very result of a risk assessment is largely subjective, in the sense that other assessors may assess risks differently.This lack of inter-subjectivity means that risk assessments are difficult to replicate and risk assessment results are not comparable.Based on the dilemmas of confidentiality risk assessment methods, in this dissertation we propose five IT confidentiality risk assessment and evaluation methods, each of which extends the previous one.More specifically we present:Extended eTVRA extends the eEurope secure and trusted architecture threat, vulnerability, and risk assessment (eTVRA) method with an information elicitation and structuring step.eTVRA is a model-based method specifically developed for telecom systems.This extension aims at assessing security risks of complex IT systems more accurately than checklist-based approaches.DCRA is a model-based confidentiality method that is automated with a computational tool.It models the information system based on the IT architecture the system vii relies on, so that one can analyze how confidentiality breaches can propagate through the IT components of the system.DCRA aims at assessing confidentiality risks of complex IT systems more accurately than checklist-based approaches.CRAC is a model-based confidentiality risk assessment method that sorts and compares two alternative technical solutions according to their risks.It analyzes risks according to where in the IT architecture information is accessible (information flow) and how difficult it is for different attackers to access it (attack paths).CRAC aims at increasing the inter-subjectivity of assessment results while reducing the assessment costs.CRAC++ extends CRAC by gaining control over the confidentiality requirements in a network of organizations.Thus, it delivers a set of confidentiality control requirements that can be used for extending SLAs.CRAC++ aims at adapting IT architecture-based confidentiality RA methods to control confidentiality risks.RiskREP is a risk-based security requirement elicitation and prioritization method, which is meant to be used for systems that are under development.It links business goals to IT risks based on the IT architecture.RiskREP aims at eliciting assessment-relevant information cost-efficiently.We validate and evaluate these methods in seven real world case studies at multinational companies from telecommunications, electronics and chemical industries.The results indicate that multinational organizations that are connected to other organizations by means of digitalization can benefit from IT architecture-based confidentiality risk assessment.The methods we propose show that assessing risks based on IT architecture (1) helps to reduce the assessment costs, (2) allows one to adjust the accuracy according to the business-criticality of a system and (3) increases the inter-subjectivity of qualitative risk assessment results.viii Samenvatting Tegenwoordig haalt bijna elke organisatie voordeel uit de bedrijfsmogelijkheden van digitalisering.Digitalisering laat o.a.toe om softwareproducten op gedeelde platformen te ontwikkelen, om vanop afstand medische dossiers te raadplegen en wijzigen of elektriciteitsgeneratoren te controleren.Deze verandering in technische omgeving heeft geleid tot veranderingen in de juridische omgeving, en introduceerde nieuwe conformiteitseisen.Bijgevolg is de bescherming van de vertrouwelijkheid van digitale informatiebronnen een grote zorg geworden voor vele organisaties.Dit probleem is zelfs nog groter voor organisaties die hun IT systeem met andere organisaties verbinden om de kosten te verlagen.Methoden voor risk assessment voorzien stakeholders van grondige kennis over de veiligheidsrisico's die het bedrijf bedreigen.Een methode voor risk assessment moet aan drie conflicterende vereisten voldoen: nauwkeurigheid, kostenefficiëntie, en intersubjectiviteit.Deze drie vereisten vormen het dilemma van de methoden voor risk assessment van vertrouwelijkheid.Nauwkeurigheid heeft te maken met de mate van verfijning die een methode toelaat bij het beoordelen van het risico.Kostenefficiëntie is de cruciale echte beperking van alle risk assessment methoden.In de praktijk duren risk assessments zelden langer dan twee weken, zelfs voor grote en informatieintensieve bedrijfsafdelingen.De derde vereiste waarover dit proefschrift handelt is intersubjectiviteit.Tegenwoordig is het resultaat van een risk assessment grotendeels subjectief, ondanks het overwegend gebruik van gestandaardiseerde methoden, in die zin dat verschillende assessoren de risico's anders kunnen bepalen.Dit gebrek aan intersubjectiviteit betekent dat risk assessments moeilijk te herhalen zijn en hun resultaten niet vergelijkbaar.Gebaseerd op de dilemma's van de methoden voor risk assessment van vertrouwelijkheid, stellen we in dit proefschrift vijf methoden voor de assessment en evaluatie van IT vertrouwelijkheidsrisico's voor, waarbij elke methode een uitbreiding is van de vorige.Meer specifiek stellen we voor: Four years ago when I decided to move to the Netherlands for doing a PhD I knew that I chose a hard path.However, I also knew that my family would support me in all possible ways and I would have an enthusiastic supervisor, who would lead me through this path and provide me the motivation to hard working.What I did not know was that I would have great friends, colleagues and Michaël who would fill my four years with fun and ease my pace.Here I would like to thank everyone who turned my last four years into a great experience.Sandro, thank you for leading me and motivating me throughout my PhD period.You promised me in our first meeting that you would make sure that I would successfully get my PhD in four years.And it happened, despite the fact that you were awfully busy with forming the security group at Eindhoven and founding your own start-up company.It was a great comfort for me to know that you were there as my mentor, supervisor and promoter, and would make sure that not only my research is in good shape but also my personal life.You took me as a naive first-year PhD candidate and shaped me up into a PhD.Thank you!Roel, my promoter, thank you for holding my hand just at the right moment.You helped me to see the big picture and draw the path when I was lost in details.You taught me how to conduct practical research.This thesis would not be possible without you.Besides my supervisors, I would like to thank all committee members for reading my dissertation and providing useful feedback.Particularly, I would like to thank Pieter for providing me a warm

Read the paper · More papers on PaperTik