1/28
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
NIST framework incl what 3 3 other frameworks
CSF
Priv framework
Sec. & priv. cntrls for info sys & orgs
cybersecurity framework (CSF) contains which 3 things
CSF = voluntary framework
CSF core
CSF tiers
CSF org profiles
6 components of CSF core
ID
understand risks of assets & suppliers of an org
protect
org’s aability to secure assets and prevent attacks
detect
timely disovery of attacks & incidents
respond
ability to contain effects of incidents
recover
restore ops and comm efforts
govern
anything governing related
CSF tiers
1) partial (limited awareness, case by case basis)
2) risk-informed (isolated policies, acts inconsistently)
3) repeatable (policies get updated & doc’d, good comms)
4) adaptive (part of the culture, contd. improvement)
each tier subdivided into risk governance & risk mgmt
CSF org profiles
should have 1 or both of either target profile or current profile (obv)
NIST priv. framework (5 steps)
some steps shared with CSF
1) ID (also in csf)
2) govern (also csf)
3) control (only priv) (anything related to processing)
4) communicate (only priv)
5) protect (in csf as well)
same 4 implementation tiers as before
NIST security & privacy cntrls (SP 800-53)
stricter compared to CSF & privacy, those are about cost effectiveness but this one is about sophisticated threats
must satisfy:
office of mgmt & budget (OMB)
fed info sec. modernization act (FISMA)
3 control implementation approaches to be used on a per control basis (for NIST sec & privacy cntrls / SP 800-53)
common (inheritable) cntrls
implement at org level
sys-specific cntrls
implement at infy-sys level
hybrid cntrls
implement at both levels
what is the EU’s set of priv laws
GDPR, way stricter than US
covered entities in HIPAA
HC providers
H plans
HC clearing houses
service providers who access PHI (priv health info)
also recently now incl business things (idr the name)
when can covered entities use / disclose PHI w/o auth?
to the patient
for treatment, pmt, & HC ops
valid auth
after giving patient opportunity to agree or object
public interest / lawful activities
research or public benefit stuff
all covered entities must: 3 things
ensure protection of all PHI
prot against reasonably anticipated threats
ensure workfore compliance
HIPAA safeguards (3)
admin
physical
technical
HITECH of 2009
paper → electronic
increased penalties
60d notice to breached individuals
who does GDPR apply to
anyone who does business in the EU or is located in EU / a EU embassy
privacy shield / safe harbor
declared INVALID by EU (companies in EU gotta be careful sending their data across the atlantic to the US)
pmt card industry data sec. standard (PCIDSS) (
for cashless transactions
pen testing / vuln scanning every 3mo!!
6 goals / reqs of PCIDSS:
build & maintain secure networks
protect acct data
vuln mgmt program
implement access cntrls
monitor & test cntrls
maintain info sec. policy
what are CIS cntrls (center for internet security)
these are the 18 rec’d cntrls, also incl IG1-3
IG1-3 (implementation groups) for CIS cntrls
1
small / med firms w/ limited IT experience
partial / risk informed
NO PHI or PII
2
incl. 1
for firms that have sensitive client info & IT staffs
repeatable
3
incl 1-2
firms have sec. experts in all domains
they have data sets subject to regulations
adaptive
CIS cntrls 1-6
1) inventory & cntrl of enterprise assets
org & track all IT assets (physical or virtual) to know which ones should be monitored / protected. know which ones have sensitive info, also focus on potential external devices that could connect via guest network
2) inventory & cntrl of software assets
track & manage all software so that only auth’d software is used, also so unauth’d software is located and removed quickly and make sure software is up to date
3) data protection
manage entire life cycle of data, classify based on sensitivity, ID & archive properly
4) secure config of enterprise assets & software
basically change the default / initial config to make it actually fit your business.. incl. ‘sec hardening’ which is to constantly improve against new attacks
5) acct mgmt
best practices for managing credentials, auth for user accts, privileged user accts, service accts for hardware / software, admin accts should be restricted to specific cases, SSO & MFA
6) access cntrl mgmt
expands on cntrl 5 by clarifying the type of cntrl that user accts should have = least privilege / need to know. incl protocols for granting / revoking access
CIS cntrls 7-12
7) continuous vuln mgmt
continuously track & ID vulns so that you can find the weak points, 0-day exploits = attack when there’s no known solution
8) audit log mgmt
get alerted / recover from attacks in real time. Sys logs = events, restoration points, crashes, start and end times. audit logs = access times
9) email & web browser protection
URL filtering, block certain file types, restrict user options
10) malware defense
prevents installation and spread of malware. living off land = using org’s tools against itself
11) data recovery
data backup, testing, & restoration. offsite storage = good
12) network infrastructure mgmt
procedures & tools for managing network infrastructure, firewalls, routers, switches, wireless access points, architecture docs and diagrams, always ID & remediate insecure network config settings
CIS cntrls 13-18
13) network monitoring & defense
monitor against internal & external threats, like DoS or ransomware. use traffic flow monitoring
14) security awareness & skills training
positively influence employee behavior & educate them on threats, MORE than annual training
15) service provider mgmt
eval all 3rd party services that have access to sensitive data or if they manage IT functions. SOC reports can help
16) application software security
safeguards to manage entire lifecycle of any software to resolve weaknesses, incl buffer overflows, XCC, sql injections, be aware of lack of visibility of SaaS programs
17) incident response mgmt
detect, respond, prepare for attacks. might have to notify
18) penetration testing
testing sec by simulating attacks. red team = focus on specific tasks, techniques, & procedures
COBIT 2019 governance vs mgmt
gov
usually BoD, focused on committees & org structures
mgmt
selected & guided by BoD, handles d2d ops, c suite
what principles are in COBIT 2019
6 principles for gov system
3 principles for a gov framework
6 principles for gov system COBIT 2019
SH value
holistic approach (18 CIS cntrls)
dynamic gov sys
gov distinct from mgmt
tailored to enterprise needs
end to end gov sys (should consider more than just IT functions)
3 principles for gov framework
based on conceptual model (ID key stuff for best efficiency)
open & flexible
aligned to major standards
governance objectives (COBIT 2019) (EDM)
EDM = eval, direct, monitor
incl:
ensure benefits delivery
gov framework setting
risk optimization
resource optimization
SH engagement
4 domains of mgmt objectives (BAI, DSS, MEA, APO)
build acquire implement (BAI)
deliver service support (DSS)
monitor, eval, assess (MEA)
align plan organize (APO)
available COBIT 2019 publications
introduction & methodology
obvious
gov & mgmt objectives
comprehensive outline of the 40 objectives / components
design guide: designing IT gov solutions
basically everything ‘design’
implementation guide
continuous improvement