Verified Document

Risk Identification In Information Security Thesis

Phishing Spear Phishing and Pharming

The following is intended to provide a very brief overview of examples of some the most dangerous and pervasive security risks in the online and networked world. One of the most insidious of identity theft is known as phishing. The term 'phishing' refers to the practice of "fishing for information." This term was originally used to describe "phishing" for credit card numbers and other sensitive information that can be used by the criminal. Phishing attacks use "…spoofed emails and fraudulent websites to deceive recipients into divulging personal financial data, such as credit card numbers, account usernames and passwords, social security numbers etc." (All about Phishing) . Thompson ( 2006) clearly outlines the basics of a phishing attack.

A typical phishing sends out millions of fraudulent e-mail messages that appear to come from popular Web sites that most users trust, such as eBay, Citibank, AOL, Microsoft and the FDIC. According to the Federal Trade Commission, about 5% of recipients fall for the scheme and give information away. Phishers wish to irrationally alarm recipients into providing sensitive information without thinking clearly about the repercussions. Victims might be told someone has stolen their PIN and they must click on the provided link to change the number. (Thompson, 2006. p. 43)

Bielski (2005) illustrates the reality of identity theft and techniques of phishing. He refers to this pervasive threat to major American commercial institutions; "…. The Bank of America's & #8230;loss of government worker data and & #8230; Choicepoint's "data leaks" (Bielski, 2005, p.7). This study also the discuses the risk of phishing to smaller intermediate companies. (Bielski, 2005, p.7)

There are numerous studies that point to the increasing cost of phishing, not only the individual but also to the commercial institutions that are negatively affected.

Phishing costs victims and financial institutions money and time. Victims must correct credit records and repair other phishing-related damage, while financial institutions must absorb customer losses, as well as costs from issuing new credit cards, answering calls and shutting down fraudulent websites. (Wetzel, 2005, p. 46)

Spear phishing is a relatively new and extremely effective form of phishing. A useful definition of this type of ID fraud is as follows;"Spear phishing is an e-mail spoofing fraud attempt that targets a specific organization, seeking unauthorized access to confidential data. As with the e-mail messages used in regular phishing expeditions, spear phishing messages appear to come from a trusted source" ( Spear Phishing). Furthermore, spear phishing attempts are most likely to be conducted by "…sophisticated groups out for financial gain, trade secrets or military information." spear phishing" ( Spear Phishing).

In essence the difference between spear phishing and ordinary phishing is that the former is more directed and does not contact hundreds or thousands of potential victims but focuses on a single company or enterprise. The central problem with this form of identity theft is that it appears to be genuine in that the request to provide information comes from known and trusted sources within company, enterprise or institution. The central factor in this form of phishing is that the phishing e-mails appear to be sent from organizations or individuals that the potential victim recognizes and from whom he or she would normally receive email. This makes it as very deceptive type of identity theft and one that is often very difficult to combat.

Another disconcerting aspect of this form of spear phishing is that it can also be used to trick the victim into downloading malicious codes or malware. This can take place easily if the recipient clicks on the false web site and is unknowingly led to a site that automatically downloads the malware or spyware. This software can hijack or take over the user's computer and gain access to personal files and information, often with devastating consequences for the individual.

Pharming is another form of common identity theft which refers to the redirection of legitimate Web sites to false online addresses. Pundits claim that pharming can even foil experienced computer users and could become one of the most insidious privacy and security threats yet. Experts claim that pharming attacks are on the increase.

Pharming works in the following manner: when a user correctly enters a web address to access online information about his bank and credit cards, chances are the web site that appears may be a sham and operated by scammers. The user assumes that the site on which he or she is entering the data is authentic, as it is a perfect replica of the legitimate site. The user then enters his or her credit card details or other sensitive information, with obvious...

In the light of the type of threats to information security discussed above, it is obvious that the process of security management would not be possible or effective without the clear identification of the risks posed and the way that these risks effect the particular assets of the company to institution. As one commentary notes;
Asset identification is the first step towards a secure organization. Too many companies are too eager to implement the most expensive technology with strong encryption and state-of-the-art authentication systems, without first thoroughly identifying all their assets. (Security+ TechNotes - Risk Identification)

In other words, the link between risk identification and asset identification is that the company should be very clear about the assets that are at risk in order to implement the most effective counter-measures and security strategies to combat these risks. Risk identification is therefore to a large extent dependent on the evaluation of assets. For example, …a company implements a firewall for their 2 Mbps shared Internet connection, but disregards the backup dial-up connection some distinguished employees have in their office. Also laptops including removable media from remote users, such as frequently traveling sales personnel, are too often 'forgotten' when a formal asset identification is not performed prior to developing the company's security program. (Security+ TechNotes - Risk Identification)

Once the assets are identified, a vulnerability assessment usually follows to determine the most vulnerable areas of security concern. This in turn leads to a threat assessment and to a risk identification. Following the logic of this process, risk identification refers to"…the likeliness of a threat actually leading to an incident" (Security+ TechNotes - Risk Identification).

Risk Identification and its importance

As Frame ( 2003) states, "Risk identification is the first step in the risk assessment process: "Its purpose is to surface risk events as early as possible, thereby reducing or eliminating surprises" (p. 49). The importance of risk identification in the process of security management is mainly to develop a sense of the sources of the security problems and issues. Once the possible impact or effect of the risk to the assets of the company has been established then, "… the risk analysts, working with managers and employees in the enterprise, engage in risk response planning to develop strategies" (Frame, 2003, p. 49). In essence, the important aim and rationale of risk identification is "…to avoid surprises" (Frame, 2003, p. 49).

The importance of the risk identification phase in security management is reiterated in a number of studies. Prybylski, (2008) state that;" Effective risk management is dependent on identification. Many risk stakeholders say, 'It's not the risks that I know about that concern me; it's the ones that we have not identified' " (Prybylski, 2008, p. 56).

The importance of the identification process is also underlined by modern concerns that this process should be 'rethought" and improved in the light of the continuing and developing threat to informstion security.

Institutions must reinvent the process of risk identification. They must eliminate "groupthink" situations in which viewpoints that differ from the majority are dismissed without adequate analysis and be mindful of unfocused debates that can skew the view of risk and create additional, unintended risk exposures. (Prybylski, 2008, p. 56)

The Human Element and Other Problematic Areas

Among the criteria that relates to the topic of risk, certain studies have stressed is the human element as being important in risk identification sand assessment. As Lineberry ( 2007) states: "Few companies properly address the human element of information security " ( p. 44 ) A security consultant, Debra Murphy, also notes that the human element in the identification of risk is often of cardinal importance. "There are times when the human element is the leaky faucet" that spills sensitive information…" (Lineberry, 2007, p. 44).

This also relates to the importance of the e-training gap. E-training refers to the training within the organization that enables staff to identity and deal with possible risks and security threats. As one study on this aspect notes, there is generally a lack of this type of training and that this is a possible internal risk factor that should be taken into account (Lineberry, 2007, p. 45). This applies particularly to risks such as scams and various forms of phishing those results in staff giving out information that may be a security risk. It also applies especially to…

Sources used in this document:
references the CISA Review Manual, 2006.

Thompson, S.C. (2006). Phight Phraud: Steps to Protect against Phishing. Journal of Accountancy, 201(2).

This study by Thompson provides some significant aspects that the business owner and customers in online commerce should pay attention to. These include basic but important aspect that should include in e-training; for example, never e-mail personal or financial information or never to respond to requests for personal information in e-mails. This provides useful background to the issue of risk identification and is also related management of this threat.

Wetzel R. ( 2005) Tackling Phishing: It's a Never-Ending Struggle, but the Anti-Fraud Arsenal Continues to Grow. Business Communications Review, 35, 46+.

This study A sheds light on the implications in term of the costs of identity fraud to financial institutions. The study underscores the severity of the vulnerabilities faced by today's organizations in the online world. The author refers to the obvious cost to intuitions like banks and also discusses hidden costs that relate to the erosion of customer confidence as a result of ID theft.
Cite this Document:
Copy Bibliography Citation

Related Documents

Security Information Security and Risk Management in
Words: 1322 Length: 5 Document Type: Term Paper

SECURITY Information Security and Risk Management in IT This essay is designed to present and discuss both an assessment of information security and risk management in IT systems and a comparative discussion of important academic theories related to security and risk. In the first section, An assessment, a conceptual framework will emerge including reference to important terminology and concepts as well as an outline of legislation and authorized usage examples. In the

Security Policy: The Information Security Environment Is
Words: 1208 Length: 4 Document Type: Essay

Security Policy: The information security environment is evolving because organizations of different sizes usually experience a steady stream of data security threats. Small and large business owners as well as IT managers are kept awake with various things like malware, hacking, botnets, and worms. These managers and business owners are usually concerned whether the network is safe and strong enough to repel attacks. Many organizations are plagued and tend to

Security Programs Implementation of Information Security Programs
Words: 1415 Length: 4 Document Type: Essay

Security Programs Implementation of Information Security Programs Information Security Programs are significantly growing with the present reforms in the United States agencies, due to the insecurity involved in the handling of data in most corporate infrastructure systems. Cases such as independent hackers accessing company databases and computerized systems, computer service attacks, malicious software such as viruses that attack the operating systems and many other issues are among the many issues experienced

Information Security Training Program
Words: 3414 Length: 12 Document Type: Research Paper

Federal Information Security Management Act (FISMA) The Federal Information Security Management Act places emphasis on the importance of training and awareness program and states under section 3544 (b).(4).(A), (B) that "security awareness training to inform personnel, including contractors and other users of information systems that support the operations and assets of the agency of- information security risks associated with their activities; and their responsibilities in complying with agency policies and procedures

Information Security
Words: 2504 Length: 8 Document Type: Term Paper

Security The following will look at case review questions based on the book known as Principles of Information Security by Michael E. Whitman. Chapters 4, 5, 6, and 7 were read through and case questions were given for each of these chapters. Case review question answers will be incorporated with material from the chapter reading that accompanies it. Chapter 4's introduction has a scenario of a man known as Charlie. He

Information Security Evaluation for OSI Systems a Case Study
Words: 4698 Length: 10 Document Type: Case Study

OSIIT An analysis of IT policy transformation The aim of this project is to evaluate the effectiveness of information security policy in the context of an organization, OSI Systems, Inc. With presence in Africa, Australia, Canada, England, Malaysia and the United States, OSI Systems, Inc. is a worldwide company based in California that develops and markets security and inspection systems such as airport security X-ray machines and metal detectors, medical monitoring anesthesia

Sign Up for Unlimited Study Help

Our semester plans gives you unlimited, unrestricted access to our entire library of resources —writing tools, guides, example essays, tutorials, class notes, and more.

Get Started Now