| Information Type | Location (device / online service) | Value (High / Medium / Low) | Relevant Threats | Defense Mechanism |
|---|---|---|---|---|
| Private Databases and Core Servers | On-premise servers / Private Cloud | High | Ransomware Insider Threat | Firewall, Access Control, Encryption, Regular Backups |
| Firewall & Network Infrastructure Config | Network Devices / Cloud console | High | Misconfiguration, Unauthorized Access, APT | Change Management Network Segmentation, Logging & Monitoring |
| Shareholder Data + Financial Records | Accounting Software Secure Cloud Storage | High | Data Theft, Identify Theft | Encryption, Audit Logs Role-based Access |
| Company Apps & Web Portals | Web Server / Cloud Hosting | Medium | Brute force, Defacement Attack | Web Application Firewall, Password Complexity Policy, Regular Patching & Updates, Input Validation |
| Customer Data - (View / Edit) | Database Server | Medium | Data Breach, Phishing | Data Encryption, Access Controls, DLP Regular Backups + Audit Logs, Security Awareness Training, Email filtering, Anti-Phishing Policies, MFA |
| Inventory & Supply chain systems | ERP System / Cloud | Medium | Supply Chain Attack, Data Manipulation | Vendor Risk, Assessment, Access Control, Integrity Checks |
| Email & Internal Communication | Email Server / MS365, Gmail | Low | Phishing, Malware Attachments | Spam Filters, Security Awareness Training, Attachment Sandboxing, Antivirus Scanning |
| Agreement & Policies | Document Server / SharePoint / Google Drive / DMS | High | Data Leakage, Unauthorized Modification, Insider Threat, Ransomware | Access Control, Encryption, Digital Signatures + Version Control, Audit Logs, Regular Backups, DLP |
| Centralized System | Main Server / Data Center | High | Single Point of Failure, Ransomware | Disaster Recovery Plan, Network Firewall, Patch Management, Redundancy |
Write down 3 threats towards each security pillar (confidentiality, integrity and availability). Then write down the countermeasures that one can take to avoid those threats towards those pillars to ensure information security.
Threats? → Confidentiality → Countermeasures
Threats? → Integrity → Countermeasures
Threats? → Availability→ Countermeasures
| Item | Security Pillar | Threats | Countermeasures | Justification |
|---|---|---|---|---|
| 1 WhatsApp messages | Confidentiality | Man in the middle attack | Encryption | When data is encrypted even when a third party get access to our data, it cannot be read by them |
| 2 Online banking login | Confidentiality | Shoulder Surfing | Privacy screen filters | Blocks bystanders from seeing typed passwords |
| 3 Company Instagram account | Confidentiality | Sessions Hijack | Session timeouts & MFA | Terminates stolen login tokens automatically |
| 4 Monthly Excel Reports | Integrity | Key Logger | Anti-Malware Software | Stops Malware from recording data-entry typing |
| 5 Website contact Forms | Integrity | Spoofing | CAPTCHA Verification | Blocks bots from sending fake form inputs |
| 6 Customer database | Integrity | Virus | Anti Virus Scanning | Prevents malicious code from corrupting Files |
| 7 Office Wi-Fi network | Availability | Worm | Network Segmentation | Stops self-Replicating malware from spreading |
| 8 Employee Laptops | Availability | Trojan | End Points EDR Software | Blocks hidden malware from locking systems |
| 9 Main Office Server | Availability | Ransomware | Offline backups | Restores data quickly without paying Ransoms |