Module 3
Module 3
Security frameworks are guidelines used for building plans to help mitigate risks and threats to data
and privacy. Security frameworks provide a structured approach to implementing a security
lifecycle. The security lifecycle is a constantly evolving set of policies and standards that define how
an organization manages risks, follows established guidelines, and meets regulatory compliance, or
laws. There are several security frameworks that may be used to manage different types of
organizational and regulatory compliance risks.
Frameworks have four core components and understanding them will allow you to better manage
potential risks. The first core component is (GDPR = general data protection regulation )
Security controls are safeguards designed to reduce specific security risks. For example, your
company may have a guideline that requires all employees to complete a privacy training to reduce
the risk of data breaches. As a security analyst, you may use a software tool to automatically assign
and track which employees have completed this training. Security frameworks and controls are vital
to managing security for all types of organizations and ensuring that everyone is doing their part to
maintain a low level of risk. Understanding their purpose and how they are used allows analysts
to support an organization's security goals and protect the people it serves. In the following
videos, we'll discuss some well-known frameworks and principles that analysts need to be aware of
to minimize risk and protect data and users.
The confidentiality, integrity, and availability (CIA) triad is a model that helps inform how
organizations consider risk when setting up systems and security policies.
CIA are the three foundational principles used by cybersecurity professionals to establish appropriate
controls that mitigate threats, risks, and vulnerabilities.
As you may recall, security controls are safeguards designed to reduce specific security risks. So they
are used alongside frameworks to ensure that security goals and processes are implemented
correctly and that organizations meet regulatory compliance requirements.
Security frameworks are guidelines used for building plans to help mitigate risks and threats to data
and privacy. They have four core components:
The National Institute of Standards and Technology (NIST) is a U.S.-based agency that develops
multiple voluntary compliance frameworks that organizations worldwide can use to help manage
risk. The more aligned an organization is with compliance, the lower the risk.
Examples of frameworks include the NIST Cybersecurity Framework (CSF) and the NIST Risk
Management Framework (RMF).
Note: Specifications and guidelines can change depending on the type of organization you work for.
In addition to the NIST CSF and NIST RMF, there are several other controls, frameworks, and
compliance standards that are important for security professionals to be familiar with to help keep
organizations and the people they serve safe.
The Federal Energy Regulatory Commission - North American Electric Reliability Corporation (FERC-
NERC)
FERC-NERC is a regulation that applies to organizations that work with electricity or that are involved
with the U.S. and North American power grid. These types of organizations have an obligation to
prepare for, mitigate, and report any potential security incident that can negatively affect the power
grid. They are also legally required to adhere to the Critical Infrastructure Protection (CIP) Reliability
Standards defined by the FERC.
FedRAMP is a U.S. federal government program that standardizes security assessment, authorization,
monitoring, and handling of cloud services and product offerings. Its purpose is to provide
consistency across the government sector and third-party cloud providers.
CIS is a nonprofit with multiple areas of emphasis. It provides a set of controls that can be used to
safeguard systems and networks against attacks. Its purpose is to help organizations establish a
better plan of defense. CIS also provides actionable controls that security professionals may follow if
a security incident occurs.
GDPR is a European Union (E.U.) general data regulation that protects the processing of E.U.
residents’ data and their right to privacy in and out of E.U. territory. For example, if an organization is
not being transparent about the data they are holding about an E.U. citizen and why they are holding
that data, this is an infringement that can result in a fine to the organization. Additionally, if a breach
occurs and an E.U. citizen’s data is compromised, they must be informed. The affected organization
has 72 hours to notify the E.U. citizen about the breach.
PCI DSS is an international security standard meant to ensure that organizations storing, accepting,
processing, and transmitting credit card information do so in a secure environment. The objective of
this compliance standard is to reduce credit card fraud.
HIPAA is a U.S. federal law established in 1996 to protect patients' health information. This law
prohibits patient information from being shared without their consent. It is governed by three rules:
1. Privacy
2. Security
3. Breach notification
Organizations that store patient data have a legal obligation to inform patients of a breach because if
patients' Protected Health Information (PHI) is exposed, it can lead to identity theft and insurance
fraud. PHI relates to the past, present, or future physical or mental health or condition of an
individual, whether it’s a plan of care or payments for care. Along with understanding HIPAA as a law,
security professionals also need to be familiar with the Health Information Trust Alliance (HITRUST®),
which is a security framework and assurance program that helps institutions meet HIPAA compliance.
The American Institute of Certified Public Accountants® (AICPA) auditing standards board developed
this standard. The SOC1 and SOC2 are a series of reports that focus on an organization's user access
policies at different organizational levels such as:
Associate
Supervisor
Manager
Executive
Vendor
Others
They are used to assess an organization’s financial compliance and levels of risk. They also cover
confidentiality, privacy, integrity, availability, security, and overall data safety. Control failures in these
areas can lead to fraud.
Pro tip: There are a number of regulations that are frequently revised. You are encouraged to keep
up-to-date with changes and explore more frameworks, controls, and compliance. Two suggestions
to research: the Gramm-Leach-Bliley Act and the Sarbanes-Oxley Act.
Key takeaways
In this reading you learned more about controls, frameworks, and compliance. You also learned how
they work together to help organizations maintain a low level of risk.
As a security analyst, it’s important to stay up-to-date on common frameworks, controls, and
compliance regulations and be aware of changes to the cybersecurity landscape to help ensure the
safety of both organizations and people.
Ethical concepts that guide cybersecurity decisions
Previously, you were introduced to the concept of security ethics. Security ethics are guidelines for
making appropriate decisions as a security professional. Being ethical requires that security
professionals remain unbiased and maintain the security and confidentiality of private data. Having a
strong sense of ethics can help you navigate your decisions as a cybersecurity professional so you’re
able to mitigate threats posed by threat actors’ constantly evolving tactics and techniques. In this
reading, you’ll learn about more ethical concepts that are essential to know so you can make
appropriate decisions about how to legally and ethically respond to attacks in a way that protects
organizations and people alike.
In the U.S., deploying a counterattack on a threat actor is illegal because of laws like the Computer
Fraud and Abuse Act of 1986 and the Cybersecurity Information Sharing Act of 2015, among others.
You can only defend. The act of counterattacking in the U.S. is perceived as an act of vigilantism. A
vigilante is a person who is not a member of law enforcement who decides to stop a crime on their
own. And because threat actors are criminals, counterattacks can lead to further escalation of the
attack, which can cause even more damage and harm. Lastly, if the threat actor in question is a state-
sponsored hacktivist, a counterattack can lead to serious international implications. A hacktivist is a
person who uses hacking to achieve a political goal. The political goal may be to promote social
change or civil disobedience.
For these reasons, the only individuals in the U.S. who are allowed to counterattack are approved
employees of the federal government or military personnel.
The International Court of Justice (ICJ), which updates its guidance regularly, states that a person or
group can counterattack if:
The counterattack will only affect the party that attacked first.
Organizations typically do not counterattack because the above scenarios and parameters are hard to
measure. There is a lot of uncertainty dictating what is and is not lawful, and at times negative
outcomes are very difficult to control. Counterattack actions generally lead to a worse outcome,
especially when you are not an experienced professional in the field.
To learn more about specific scenarios and ethical concerns from an international perspective,
review updates provided in the Tallinn Manual online.
Because counterattacks are generally disapproved of or illegal, the security realm has created
frameworks and controls—such as the confidentiality, integrity, and availability (CIA) triad and others
discussed earlier in the program—to address issues of confidentiality, privacy protections, and
laws. To better understand the relationship between these issues and the ethical obligations of
cybersecurity professionals, review the following key concepts as they relate to using ethics to
protect organizations and the people they serve.
Confidentiality means that only authorized users can access specific assets or data. Confidentiality as
it relates to professional ethics means that there needs to be a high level of respect for privacy to
safeguard private assets and data.
Privacy protection means safeguarding personal information from unauthorized use. Personally
identifiable information (PII) and sensitive personally identifiable information (SPII) are types of
personal data that can cause people harm if they are stolen. PII data is any information used to infer
an individual's identity, like their name and phone number. SPII data is a specific type of PII that falls
under stricter handling guidelines, including social security numbers and credit card numbers. To
effectively safeguard PII and SPII data, security professionals hold an ethical obligation to secure
private information, identify security vulnerabilities, manage organizational risks, and align security
with business goals.
Laws are rules that are recognized by a community and enforced by a governing entity. As a security
professional, you will have an ethical obligation to protect your organization, its internal
infrastructure, and the people involved with the organization. To do this:
You must remain unbiased and conduct your work honestly, responsibly, and with the
highest respect for the law.
Ensure that you are consistently invested in the work you are doing, so you can appropriately
and ethically address issues that arise.
Stay informed and strive to advance your skills, so you can contribute to the betterment of
the cyber landscape.
As an example, consider the Health Insurance Portability and Accountability Act (HIPAA), which is a
U.S. federal law established to protect patients' health information, also known as PHI, or protected
health information. This law prohibits patient information from being shared without their consent.
So, as a security professional, you might help ensure that the organization you work for adheres to
both its legal and ethical obligation to inform patients of a breach if their health care data is exposed.
Key takeaways
As a future security professional, ethics will play a large role in your daily work. Understanding ethics
and laws will help you make the correct choices if and when you encounter a security threat or an
incident that results in a breach.
Availability: The idea that data is accessible to those who are authorized to access it
Confidentiality: The idea that only authorized users can access specific assets or data
Confidentiality, integrity, availability (CIA) triad: A model that helps inform how organizations
consider risk when setting up systems and security policies
Health Insurance Portability and Accountability Act (HIPAA): A U.S. federal law established to
protect patients' health information
Integrity: The idea that the data is correct, authentic, and reliable
National Institute of Standards and Technology (NIST) Cyber Security Framework (CSF): A voluntary
framework that consists of standards, guidelines, and best practices to manage cybersecurity risk
Privacy protection: The act of safeguarding personal information from unauthorized use
Protected health information (PHI): Information that relates to the past, present, or future physical
or mental health or condition of an individual
Security architecture: A type of security design composed of multiple components, such as tools and
processes, that are used to protect an organization from risks and external threats
Security frameworks: Guidelines used for building plans to help mitigate risk and threats to data and
privacy
Security governance: Practices that help support, define, and direct security efforts of an
organization
Sensitive personally identifiable information (SPII): A specific type of PII that falls under stricter
handling guidelines