Security Posture
An organizations ability to manage its defense of the assets and data , and react to change
Domains of CISSP:
1. Security and Risk Management
Find goals , Objectives , risk mitigation , compliance and legal regulations
2. Asset Security
Protect all the assets that the company have.
3. Security Architecture and Engineering
Focus on security optimization by ensuring by effective tools ,system and processes are in
place or not.
4. Communication and Network Security
Management of physical and wireless connections.
5. Identity and access management
Focus on access and authorization to keep the data secure
6. Security Assessment and Testing
This part is about checking how secure the organization really is
7. Security Operations
This focuses on detecting, responding to, and investigating
security incidents.
8. Software Development Security
Secure coding practices
Key concepts:
* Security Assessment and Testing: The process of identifying and mitigating risks, threats,
and vulnerabilities through security assessments and audits.
* Asset Security: Managing the cybersecurity processes of organizational assets, including
their storage, maintenance, retention, and destruction.
* Security Posture: An organization’s ability to manage its defense of critical assets and data
and react to change.
* Identity and Access Management (IAM): A domain focused on ensuring user identities are
trusted and authenticated, and that access to assets is authorized.
* Principle of Least Privilege: The concept of granting only the minimal access and
authorization required to complete a task.
✅ In Short
Threat: Something that could harm the company
Risk: The chance that harm will happen
Vulnerability: A weakness that makes harm possible
Entry-level analysts help reduce risks by fixing vulnerabilities and educating people.
1. Ransomware and Its Impact on Organizations
Ransomware is one of the most expensive and damaging types of malware. In a ransomware attack,
threat actors encrypt an organization’s data and demand payment in exchange for restoring access.
Once deployed, ransomware can freeze network systems, render devices unusable, and lock
confidential data, making it inaccessible.
To regain access, attackers demand a ransom before providing a decryption key, which functions
like a password used to unlock the data. Ransom negotiations and data leaks commonly occur
through the dark web, where threat actors operate with a high level of anonymity.
2. Understanding the Layers of the Web
Although most people use the internet for activities such as social media or online shopping, this
represents only a small portion of the web. The web consists of three main layers:
Surface Web:
This is the part of the web most users access daily using standard web browsers. It includes
publicly available websites.
Deep Web:
The deep web requires authorization to access. Examples include organizational intranets,
private databases, and email accounts accessible only to authorized users.
Dark Web:
The dark web can only be accessed using specialized software. It is often associated with
illegal activities due to the secrecy and anonymity it provides.
The dark web is commonly used by cybercriminals to conduct illicit activities such as ransomware
negotiations and the sale of stolen data.
3. Key Impacts of Threats, Risks, and Vulnerabilities
Threats, risks, and vulnerabilities can have serious consequences for organizations. The three major
impacts are outlined below.
3.1 Financial Impact
When organizational assets are compromised, financial losses can be significant. These may
include:
Disrupted business operations and services
Costs related to investigation and recovery
Legal penalties and fines due to non-compliance with laws and regulations
3.2 Identity Theft
Organizations often store sensitive data belonging to customers, employees, and third-party
vendors. This data may include personally identifiable information (PII). Storing such data always
carries risk, as it can be stolen, sold, or leaked on the dark web, where attackers can avoid legal
consequences.
3.3 Reputational Damage
An organization’s reputation is critical to maintaining customer trust and achieving business goals.
A security breach can result in customers turning to competitors, negative media coverage, and
long-term damage to brand credibility. In addition to reputational harm, data breaches may also lead
to legal penalties and financial losses.
4. Importance of Security Measures
Organizations are strongly encouraged to implement appropriate security controls and follow
established protocols to minimize the impact of threats, risks, and vulnerabilities. By using a
comprehensive set of security tools and practices, security teams are better prepared to respond to
incidents such as ransomware attacks.
5. NIST Risk Management Framework (RMF)
The National Institute of Standards and Technology (NIST) provides several frameworks used by
security professionals to manage risk. One of the most important is the NIST Risk Management
Framework (RMF). While entry-level analysts may not perform every step, understanding the
framework is essential for effective risk management.
5.1 The Seven Steps of the RMF
1. Prepare
Activities required to manage security and privacy risks before a breach occurs. Entry-level
analysts often monitor risks and identify controls during this phase.
2. Categorize
Systems and information are categorized based on their impact on confidentiality, integrity,
and availability. Analysts follow organizational processes to protect critical assets such as
customer data.
3. Select
Security controls are chosen, customized, and documented. This may include maintaining
playbooks and security documentation.
4. Implement
Security and privacy controls are put into operation. Effective implementation helps reduce
ongoing security risks.
5. Assess
Organizations evaluate whether controls are implemented correctly and effectively. Analysts
identify weaknesses and recommend improvements.
6. Authorize
This step involves accountability for security and privacy risks. Analysts may create reports,
action plans, and project milestones aligned with security objectives.
7. Monitor
Continuous monitoring ensures systems operate securely and align with organizational
security goals. Analysts regularly assess systems and recommend changes when necessary.