Cyber Security

Cyber security increasingly dominates the headlines. As AI improves, so too do the tools to corrupt. The dragon chases its tail.

There is a lot of great work being done on Cyber defence. If you can't measure it, you can't manage it. Likewise, if you don't name a thing (label it), you won't look for it.

USA

There is a lot of great work that has been done by the Americans.

SOC: System and Organization Controls

SOC comes in different levels:

SOC 1: Specific focus on internal controls for financial reporting.
Useful for evidencing a commitment to financial data security e.g. when outsourcing a function like payroll. 

SOC 2: Much deeper and broader scope. The standard examines five key areas, called “trust service principles”, such as: Security, Availability, Processing integrity, Confidentiality, and Privacy.
Cloud service providers, data centres, and SaaS companies commonly obtain (i.e. they pay vendors to provide them with) SOC 2 reports.

A good SOC 2 checklist will include heading such as:
Governance
Policies & Procedures
Information Security
Risk Assessment
Risk Mitigation
Internal Controls
Asset Inventory
Monitoring
Incident Management
Change Management
Vendor Management
Business Continuity
Business Recovery
Confidentiality (Data protection & Privacy)


SOC 3: SOC 3 is a simplified version of SOC 2, designed for public visibility. It confirms security without diving into the nitty-gritty details.

See also:
https://www.fortinet.com/uk/resources/cyberglossary/soc1-compliance


NIST

NIST, National Institute of Standards and Technology.
https://www.nist.gov/cyberframework

This is one of my go to resources. I believe their framework is excellent.




UK

The UK has adopted a more pragmatic approach with caters to all firms form start up to institution (and you scale according to your own level of materiality and proportionality).

Cyber Essentials
Protect your business against the most common cyber threats with Cyber Essentials.
https://www.ncsc.gov.uk/cyberessentials/overview

5 Cyber Essentials Technical Controls

1. Firewalls:
Create a security filter between the internet and your network
2. Secure configuration:
Set up computers securely to minimise ways that a cyber-criminal can find a way in 
3. Security update management:
Prevent cyber criminals using vulnerabilities they find in software as an access point to your systems
4. User access control:
Control who can access your data and services and what level of access they have
5. Malware protection:
Identify and immobilise viruses or other malicious software before it has a chance to cause harm

CREST
CREST is an international not-for-profit, membership body representing the global cyber security industry.
https://www.crest-approved.org/
What CREST does do, is give you a guide to who can offer you the services you are looking for locally.

CBEST
CBEST originally stood for Cyber Security Testing Framework, though it is now used simply as a title rather than an acronym (aka Critical National Infrastructure Banking Supervision and Evaluation Testing - I guess once upon a time it may have just been Critical Banking Evaluation and Stress Test). 

BoE
As you move up the Financial Market Infrastructure ladder, the testing regime rises accordingly.
https://www.bankofengland.co.uk/financial-stability/operational-resilience-of-the-financial-sector/cbest-threat-intelligence-led-assessments-implementation-guide


Australia

The Essential Eight.


Patch applications
Patch operating systems
Multi-factor authentication
Restrict administrative privileges
Application control
Restrict Microsoft Office macros
User application hardening
Regular backups

The essential eight make perfect sense. What I really like is that the Australian Signals Directorate has recognised the importance of materiality from small business through to large, with their Maturity Model.

To assist organisations with their implementation of the Essential Eight, four maturity levels have been defined (Maturity Level Zero through to Maturity Level Three). With the exception of Maturity Level Zero, the maturity levels are based on mitigating increasing levels of tradecraft (i.e. tools, tactics, techniques and procedures) and targeting.
https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight/essential-eight-maturity-model



No comments: