1/89
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
National Institute of Standards and Technology (NIST)
Established to remove barriers to industrial competitiveness and improve access to resources to promote U.S. research capabilities; Also is in the cybersecurity field
Cybersecurity Framework (CSF), Privacy Framework, SP 800-53 (Security and Privacy Controls for Information Systems and Organizations)
What are the three most prolific sets of standardized frameworks promulgated by NIST?
Cybersecurity Framework (CSF)
Voluntary framework that includes three primary components to manage cybersecurity risk:
CSF Core
CSF Tiers
CSF Organizational Profiles
NIST CSF Core
Describes cybersecurity outcomes that can be used by an organization of any size
The focus is to reduce an organization’s cybersecurity risks
Has six functions
Govern, Identify, Protect, Detect, Respond, Recover
What are the six functions of NIST CSF Core?
Identify
Function of NIST CSF Core that focuses on understanding the assets and suppliers of an organization and the cybersecurity risks related to assets and suppliers
Identifies improvement opportunities related to the organization’s cybersecurity risk management policies, plans, processes, procedures, and practices
Protect
Function of NIST CSF Core that focuses on an organization’s ability to secure its assets to prevent or reduce the likelihood and impact of adverse cybersecurity events
Examples include identity management, authentication, access control, awareness/training, data security, platform security, and infrastructure resiliency
Detect
Function of NIST CSF Core that focuses on the timely discovery of cybersecurity attacks and incidents by analyzing anomalies, indicators of compromise, and other potentially adverse events that may indicate an attack or incident is occurring
Response
Function of NIST CSF Core that focuses on a company’s ability to contain the effects of cybersecurity incidents
Outcomes cover incident management, analysis, mitigation, reporting, and communication
Recover
Function of NIST CSF Core that focuses on supporting the restoration of a company’s normal operations to reduce the impact of incidents and communicating recovery efforts effectively and appropriately
NIST CSF Tiers
Categorize the degree to which information security practices are integrated throughout an organization
Should complement an organization’s existing cybersecurity risk management methodology and can be used as a benchmark to communicate its organization-wide approach to managing cybersecurity risks
CSF Organizational Profiles
Mechanisms by which NIST recommends companies measure cybersecurity risk and how to minimize such risk
Determine success or failure of information security implementation
Should have a Current Profile (the outcome that an organization is achieving) and a Target Profile (the desired outcome that an organization has prioritized achieving)
Community Profiles
Baseline outcomes developed among a number of organizations due to the shared interest and goals of a particular industry sector, topic, or use case
Scope Profile, Gather Information, Create Profile, Analyze Gaps, Implement Action Plan
What is the repeatable, five-step approach in using Organization Profiles to help inform continuous improvement of an organization’s cybersecurity posture?
Partial, Risk-Informed, Repeatable, Adaptive
What are the four NIST CSF Tiers?
Partial
NIST CSF Tier in which risk management is ad hoc and reactive where prioritization of information security efforts is not formally based on organizational objectives or threat environment
There is limited awareness of cybersecurity risks at the organizational level
The organization implements cybersecurity risk management on an irregular, case-by-case basis and does not have processes that allow cybersecurity information to be shared within the organization for general awareness
Risk-Informed
NIST CSF Tier in which cybersecurity prioritization is based on organizational risk, and management approves cybersecurity efforts; however, cybersecurity policies may be isolated and not be established as organizational-wide policies
The organization is aware of the cybersecurity risks in general and specific risks associated with its suppliers, as well as the products and services it acquires and uses, but it does not act consistently or formally in response to those risks
Repeatable
NIST CSF Tier in which the organization utilizes cybersecurity in planning and has enshrined cybersecurity practices in formal, documented policies that are frequently updated based on shifts in business requirements, threats, and technological landscape
There is an organization-wide risk approach to cybersecurity where risks of assets, suppliers, and products and services are consistently and accurately monitored, as well as regularly communicated among senior leadership
Adaptive
NIST CSF Tier in which there is a risk-informed, organization-wide approach in managing cybersecurity risks
Senior executives monitor cybersecurity risks in the same context as financial and other organizational risks and cybersecurity risk management is part of the organizational culture
Through a process of continuous improvement that incorporates advanced cybersecurity technologies and practices, the organization actively adapts to a changing technological landscape and responds in a timely, effective manner to evolving, sophisticated threats
Identify, Govern, Control, Communicate, Protect
What are the five functions of the NIST Privacy Framework?
NIST Privacy Framework
Framework that was developed to protect individuals’ data as used in data processing applications and to be industry agnostic
Leverages a similar structure to the NIST CSF, so there is a degree of overlap between both frameworks
NIST SP 800-53
Set of security and privacy controls applicable to all information systems and now the standard for federal information security systems
Stricter standard compared to the NIST CSF or Privacy Frameworks
Controls are designed for protecting information systems against sophisticated threats; It can become burdensome given that there are nearly 1,200 detailed controls
Common (Inheritable), System-Specific, Hybrid
What are the three control implementation approaches that are to be implemented on a per-control basis according to NIST SP 800-53?
Common (Inheritable) Control
Implement controls at the organizational level, which are adopted by information systems
System-Specific Control
Implement controls at the information system level
Hybrid Control
Implement controls at the organization level where appropriate and the rest at the information system level
True
There is no single federal law that applies generally and regulates all personal data.
True or False?
Data Breach
The exposure of confidential information to unauthorized persons
Have significant consequences such as business disruption, reputational harm, financial loss, data loss, potential legal/regulatory implications, etc
Unintentional Data Breach
A breach resulting from negligence or error
Intentional Data Breach
A breach resulting from bad actors illegally gaining access to data
Detection/Escalation, Notification, Post-Breach Response, Loss of Business/Revenue
What are the four categories of expenditures related to a data breach?
Health Insurance Portability and Accountability Act (HIPAA)
Required the Department of Health and Human Services to adopt national standards promoting health care privacy and security
Applies to specific healthcare-related entities and businesses, called “covered entities,” which include health care providers, health plans, health care clearing houses, and service providers
Health Information Technology for Economic and Clinical Health (HITECH) Act
Amendment to HIPAA to promote the transition from paper to electronic records
Increased penalties for HIPAA violations, required that patients receive the option to obtain records in electronic form, and added “business associates” as a covered entity
Added breach notification rules requiring that covered entities provide notice of a breach to impacted individuals within 60 days after discovery of the breach
General Data Protection Regulation (GDPR)
Became the EU’s general applicability law regulating the privacy of data
Provides circumstances when it is lawful to process personal data, such as with proper consent or when complying with a legal obligation
One of the strictest privacy laws in the world
Scope extends well beyond the EU
Payment Card Industry Data Security Standard (PCI DSS)
A framework for entities to apply in an effort to promote data security when processing payments
Subjected data includes both cardholder data and sensitive authentication data (collectively referred to as account data)
Build/Maintain Secure Network/Systems, Protect Account Data, Maintain Vulnerability Management Program, Implement Strong Access Control Measures, Regularly Monitor/Test Networks, Maintain Information Security Policy
What are the six goals of PCI DSS?
Center for Internet Security (CIS) Controls
Recommended set of actions, processes, and best practices that can be adopted and implemented by organizations to strengthen their cybersecurity defenses
Currently supported by the SANS Institute which provides training, administers certification, and performs research
Task-focused and organized by activities
Each one has recommendations prescribed to achieve the control objective, which are referred to as Safeguards
Context, Coexistence, Consistency
What are the three design principles of CIS Controls?
IG1
Implementation group for CIS Controls that is for small or medium-sized organizations that have a limited cybersecurity defense mechanism in place in terms of personnel or IT assets
The main focus of this group is to keep the company operational because their cybersecurity expertise is limited, the data being used is not sensitive, and the company cannot sustain long periods of downtime
Tiers 1 and 2 (from the NIST Cybersecurity Framework) would fall into this group
IG2
Implementation group for CIS Controls that is for companies that have IT staff who support multiple departments that have various risk profiles
These organizations typically have sensitive client data, and they can tolerate short interruptions in service
One of the biggest concerns for these entities is loss of trust in the event of a data breach
Tier 3 (from the NIST Cybersecurity Framework) would fall into this group
IG3
Implementation group for CIS Controls that is for organizations that have security experts in all of the domains within cybersecurity like penetration testing, risk management, and application security
Data assets under management at these companies include those that are sensitive and likely subject to compliance with standards or regulatory oversight
Attacks on these organizations can cause significant damage to the company and the public welfare
Tier 4 (from the NIST Cybersecurity Framework) would fall into this group
Inventory and Control of Enterprise Assets (CIS Control 01)
This control helps organizations actively track and manage all IT assets connected to a company’s IT infrastructure physically or virtually within a cloud environment
This allows companies to know the totality of IT assets that should be monitored and protected
Using an IT inventory list will allow organizations to track various data points for company assets
Having a comprehensive view of company assets will also give visibility into how data flows throughout an organization
Companies should also focus on the potential for external devices to connect to a company’s network through means such as guest networks, even if they are segregated from the core network
Inventory and Control of Software Assets (CIS Control 02)
This control provides recommendations for organizations to track and actively manage all software applications so that only authorized software is installed on company devices
Also provides guidance on finding unmanaged and unauthorized software already installed so that it can be removed and remediated
Control lists and policies should be in place so that only approved software is installed on company devices
Data Protection (CIS Control 03)
This control helps organizations develop ways to securely manage the entire life cycle of their data, from the initial identification and classification data to its disposal
Organizations must identify, archive, label, and classify their data to understand the implications of the data being lost or compromised
Classification categories are labeled at the discretion of the enterprise and should be assigned based on sensitivity, such as “internal,” “public,” “sensitive,” and “confidential”
Data mapping should be developed that identifies the various software applications that access each of these sensitivity levels
Retention requirements, access control lists, access logging mechanisms, and data disposal plans can also be implemented in a tailored fashion once data classification levels are assigned
Secure Configuration of Enterprise Assets and Software (CIS Control 04)
This control helps organizations establish and maintain secure baseline configurations for their enterprise assets including servers, network devices, mobile/portable end-user devices, non-computing assets, operating systems, and other corporately managed hardware or software
Publicly available security standards can be used by organizations as a starting point for asset reconfiguration
Security hardening can be incorporated into adjusting target security configurations so that they are continuously “hardened” against new forms of attack
Account Management (CIS Control 05)
This control outlines best practices for companies to manage credentials and authorization for user accounts, privileged user accounts, and service accounts for company hardware and software
Accounts must be inventoried and tracked so that appropriate controls may be applied
Administrator accounts should be restricted to specific use cases
One common and convenient form of authentication is single sign-on (SSO)
Access Control Management (CIS Control 06)
This control expands on Account Management (CIS Control 05) by specifying the type of access that user accounts should have
These methodologies assist with the goal that users only have access to systems, services, and data needed to perform their job duties
Accounts that do not follow these principles pose a security risk to the organization by allowing unauthorized access
Protocols should be put in place for granting access and revoking access based on job duties, roles, and responsibilities
A comprehensive solution, ideally centralized, for provisioning and de-provisioning employee access should also be in place
Continuous Vulnerability Management (CIS Control 07)
This control assists organizations in continuously identifying and tracking vulnerabilities within its infrastructure so that it can remediate and eliminate weak points or windows of opportunity for bad actors
An evolving cybersecurity landscape requires organizations to keep abreast of threats and vulnerabilities to be able to defend against them
Organizations must remain proactive in scanning, monitoring, and managing vulnerabilities to reduce the window of opportunity for attackers to capitalize on them
Audit Log Management (CIS Control 08)
This control establishes an enterprise log management process so that organizations can be alerted and recover from an attack in real time, or near real time, using log collection and analytic features
Having access to event logs is critical to incident response, and it can also facilitate processes for legal matters, such as eDiscovery, accountability for auditing, lessons learned for process improvement, and data retention for compliance requirements
An enterprise log management process should address the entire life cycle of audit logs beginning with log collections and ending with log disposal
Audit logs may be captured from a variety of connection methods
Organizations should also be notified when failed user attempts are made to connect to resources without the appropriate privileges
Email and Web Browser Protections (CIS Control 09)
This control provides recommendations on how to detect and protect against cybercrime attempted through email or the internet by directly engaging employees
Attacks such as phishing scams and business email compromise can be conducted by attackers using email to target senior executives who control data and financial resources or target high-value assets with data that could be used for exploitation or financial gain
It is recommended that policies and tools be put in place to enforce URL filtering, block certain file types, and restrict options such as the ability for users to install add-ons
Malware Defenses (CIS Control 10)
This control assists companies in preventing the installation and propagation of malware onto company assets and its network
Malware can come in many forms such as viruses, worms, spyware, adware, keyloggers, and ransomware
Endpoint assets and devices can be leveraged as both entry points and targets for malware
Anti-malware solutions should be automated, centrally managed, maintained, and deployed to all potential entry points
As malware defenses become better at defending against threats, some malicious actors have adjusted their tactics to what is known as LotL, or “living-off-the-land”
Hackers use stolen credentials, power shell, FTP, Windows Management Instrumentation (WMI) interface, and other built-in tools
Data Recovery (CIS Control 11)
This control establishes data backup, testing, and restoration processes that allow organizations to effectively recover company assets to a pre-incident state
Organizational data is a critical resource for conducting business and can be targeted by ransomware attacks that encrypt data and leave criminals demanding ransom for its restoration
Human error, misconfigurations, and natural factors (power outages, flooding, etc) can also cause data to become unusable or unavailable
Data value, sensitivity, classification, and retention requirements all factor into the mechanisms and cadence that will be used for backup and storage methods
Automating the backup process, utilizing off-site storage in a different geographical location, and using encryption are all recommended practices
Network Infrastructure Management (CIS Control 12)
This control establishes procedures and tools for managing and securing a company’s network infrastructure
Network architecture documentation and diagrams should be kept up to date to accurately reflect the organization’s network topology and layout
Organizations must continuously identify and remediate insecure default network configuration settings, misconfigured network settings, insecure protocol usage, and outdated network software
Network Monitoring and Defense (CIS Control 13)
This control establishes processes for monitoring and defending a company’s network infrastructure against internal and external security threats
Two common ways networks can be attacked include denial of service (DoS) attacks and ransomware
Organizations should establish event logging and alerting mechanisms that can be implemented through tools such as security information and event management (SIEM) to help centralize and assist in log analysis
Traffic flow monitoring, alerting, and detection safeguards can also be implemented with tools such as NIPS, NGFW, DLP, and EDR systems
Many organizations have their own security or network operations center that is uniquely equipped to run a robust IT networking operation
Denial of Service (DoS) Attacks
Involve a perpetrator overwhelming a company’s network by flooding the network with illegitimate requests so that it is effectively rendered useless
Ransomware Attacks
Situations in which an attacker or group of attackers gain access to a company’s system, block employees from accessing it, demand payment to regain access, and threaten to either keep all systems blocked or publish sensitive data to the public (or dark web) if the company doesn’t comply
Security Awareness and Skills Training (CIS Control 14)
This control guides organizations in establishing a security awareness and training program to reduce cybersecurity risk
One of the goals of this type of training is to influence employee behavior in a way that makes them conscious about the various tactics that can be employed by attackers to allow unauthorized access
Uninformed employees pose one of the greatest risks to the security of an organization and risks can originate externally or internally
Regular training is one of the best ways to establish security awareness
Training should not be reduced to an annual occurrence, but should be more frequent and include messages that resonate with users
Service Provider Management (CIS Control 15)
This control helps organizations develop processes to evaluate third-party service providers that have access to sensitive data or are responsible for managing some or all of a company’s IT functions
Risks can be introduced by third-party service providers that do not hold themselves to the same security standards as the other organization
It is recommended that companies establish service provider management processes to oversee the entire service provider lifecycle
Application Software Security (CIS Control 16)
This control establishes safeguards that manage the entire lifecycle of software that is acquired, hosted, or developed in-house to detect, deter, and resolve cybersecurity weaknesses before they are exploited
Software vulnerabilities may exist for various reasons like a flawed design, poor infrastructure, coding errors, poor authentication protocols, and the failure to test for software anomalies
IT managers must consider whether best practices and safeguards are being followed such as secure design standards, secure code reviews, and security testing tools are integrated into the software development lifecycle
One common blind spot modern organizations have is the lack of visibility into Software-as-a-Service (SaaS) platforms
Some larger organizations may consider implementing a bug bounty program in which employees are paid for finding flaws in company-produced or company-used software
Incident Response Management (CIS Control 17)
This control provides the recommendations necessary to establish an incident response management program to detect, respond, and prepare for potential cybersecurity attacks, because when these attacks occur, their impact can be widespread throughout the organization
In certain cases, laws and regulations may require notification of data breaches and impose fines for noncompliance, which makes it imperative to have programs in place to detect, contain, and eliminate threats
The incident response process should include the designation of a key contact, the establishment of an incident response team, and the development of communication plans for notifying impacted business units, stakeholders, and regulatory agencies
It is also important to periodically carry out exercises to test the incident response process to ascertain its effectiveness and identify opportunities for improvement
Penetration Testing (CIS Control 18)
This control helps organizations test the sophistication of their cybersecurity defense system in place by simulating actual attacks in an effort to find and exploit weaknesses
Testing in this control is different than vulnerability testing in Control 7 in that this testing seeks to go beyond identifying weaknesses
“Red Team” exercises focus on specific tactics, techniques, and procedures (TTPs) to see how an organization fares against certain types of attackers; Each industry is exposed to a different mix of cybersecurity risks, with some bearing more risk simply due to the nature of the business
Generally begins with a discovery or observation of an organization’s environment, followed by scanning to locate vulnerabilities that can be used to gain access
Control Objectives for Information and Related Technologies (COBIT)
Widely used IT governance framework
Provides a roadmap that organizations can use to implement best practices for IT governance and management
Governance
Organizational ______ is typically the responsibility of a company’s board of directors, consisting of a chairperson and focused organizational structures (e.g., audit committee, executive committee, marketing committee)
Management
Selected and guided by the board of directors and is responsible for the daily planning and administration of company operations
Generally consists of CEO, CFO, COO, and other executive leaders
Internal Stakeholders
Include the board of directors and management
Others include business managers, IT managers, assurance providers, and risk managers
External Stakeholders
Include regulators, investors, business partners, and IT vendors
Parties who are entitled to some information about compliance and risk mitigation but are not entitled to the same information given to internal parties
Value, Holistic, Dynamic, Distinct, Tailored, End-to-End
What are the six principles for a governance system that were used to develop the COBIT 2019 core model?
Provide Stakeholder (Value)
Principle for a governance system
Governance systems should create value for the company’s stakeholders by balancing benefits, risks, and resources
This should be accomplished through a well-designed governance system with an actionable strategy
(Holistic) Approach
Principle for a governance system
Governance systems for IT can comprise diverse components, collectively providing a holistic model
(Dynamic) Governance System
Principle for a governance system
When a change in one governance system occurs, the impact on all others should be considered so that the system continues to meet the demands of the organization
Governance (Distinct) From Management
Principle for a governance system
Management activities and governance systems should be clearly distinguished from each other because they have different functions
(Tailored) to Enterprise Needs
Principle for a governance system
Governance models should be customized to each individual company, using design factors to prioritize and tailor the system
(End-to-End) Governance System
Principle for a governance system
More than just the IT function should be considered in a governance system; All processes in the organization involving information and technology should be factored into this approach
Conceptual, Flexible, Aligned
What are the three principles for a governance framework?
COBIT Core Model
Governance and management objectives should be set so that information technology and systems contribute to company goals
Goals are established
Governance and management objectives are developed to help achieve goals
Information technology and systems are utilized to help meet objectives and ultimately reach goals
Governance Objectives
Always relate to a governance process, which board of directors are responsible for
Management Objectives
Always associated with management processes, which middle and senior management are responsible for
Evaluate, Direct, and Monitor (EDM)
Domain that governance objectives are grouped into in the COBIT Core Model
Those charged with governance evaluate strategic objectives, direct management to achieve those objectives, and monitor whether objectives are being met
There are five more specific objectives within this domain
Align, Plan, and Organize (APO)
One of the domains that management objectives are grouped into in the COBIT Core Model
Focuses on aligning information technology’s overall strategy, planning how to utilize technology in business operations of the organization, and organizing the resources for their most effective and efficient usage
There are fourteen more specific objectives within this domain (Managed Data is one of the most significant)
Build, Acquire, and Implement (BAI)
One of the domains that management objectives are grouped into in the COBIT Core Model
Addresses the building, acquiring, and implementation of information technology solutions in the organization’s business processes
There are eleven more specific objectives within this domain that offer guidance on requirements definition, identifying solutions, managing capacity, dealing with organizational and IT change, managing knowledge, administering of assets, and managing configuration
Deliver, Service, and Support (DSS)
One of the domains that management objectives are grouped into in the COBIT Core Model
Addresses the delivery, service, and support of IT services
There are six more specific objectives within this domain that cover managed operations, service requests, managed problems, continuity, security services, and business process controls
Monitor, Evaluate, and Assess (MEA)
One of the domains that management objectives are grouped into in the COBIT Core Model
Addresses information technology’s conformance to the company’s performance targets and control objectives along with external requirements
This is accomplished through continuous monitoring, evaluation, and assessment of information technology systems, controls, and components
There are four more specific objectives within this domain that cover managed performance/conformance monitoring, managed system of internal control, compliance with external requirements, and managed assurance
This must be done over the other three management objectives (APO, BAI, DSS)
Processes, Organization Structures, Principles/Policies/Frameworks, Information, Culture/Ethics/Behavior, People/Skills/Competencies, Services/Infrastructure/Applications
What are the seven components of the governance system per the COBIT Core Model?
Design Factors
Per COBIT, these influence the design of a company’s IT governance system, with a total of eleven factors that should be considered:
Enterprise Strategy
Enterprise Goals (Financial, Customer, Internal, Growth)
Risk Profile
Information and Technology
Threat Landscape
Compliance Requirements
Role of IT
Sourcing Model for IT
IT Implementation Methods
Technology Adoption Strategy
Enterprise Size
Support IT
An IT system that is not critical for operating a business or maintaining continuity
Factory IT
An IT system that will have an immediate impact in business operations and continuity if it fails
Turnaround IT
An IT system that drives innovation for the business but is not required for critical business operations
Strategic IT
An IT system that is crucial for both innovation and business operations
Focus Areas
Different types of governance issues, domains, or topics that can be solved by a combination of management and governance objectives, along with their underlying components
Introduction/Methodology (Framework), Governance/Management Objectives (Framework), Designing IT Governance Solution (Design Guide), Implementing/Optimizing IT Governance Solution (Implementation Guide)
What four publications are the roadmap to help achieve proper customization of the COBIT framework recommendations?