0% found this document useful (0 votes)
7 views4 pages

Cybersecurity Framework Best Practices

The document outlines a cybersecurity framework focusing on soft and hard controls, including policies, processes, and best practices for data protection. It emphasizes the importance of identifying, protecting, detecting, responding to, and recovering from cyber threats, along with a gap analysis of current and target profiles. The framework, endorsed by NIST and adopted by various organizations, provides a tiered approach to building an effective cybersecurity program.

Uploaded by

hackerjvn
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
7 views4 pages

Cybersecurity Framework Best Practices

The document outlines a cybersecurity framework focusing on soft and hard controls, including policies, processes, and best practices for data protection. It emphasizes the importance of identifying, protecting, detecting, responding to, and recovering from cyber threats, along with a gap analysis of current and target profiles. The framework, endorsed by NIST and adopted by various organizations, provides a tiered approach to building an effective cybersecurity program.

Uploaded by

hackerjvn
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Soft control ?

Policy, process, best practices

Hard control ? Technical contro, backup and test recovery, encrypted, riks
assessment

Do we have policy ?

Do our data have a backup and recovery testing ?

Data is encrypted, different things, assessment , determine where you are


today, gap analysis.

Identify: identify what you have in your org,

protect: how to identify what you identified in the first phase

detect: ongoing monitoring for breaches and dif type of infiltrations that may
be happend

Respond: response when a breach happens

Recover: get your business up and running to 100%

Profiles:

target profile

Current profile

Gap analysis:

Implementation Tiers:

There are 2 ways to use the framework, one is followin the framework to
build the cybersecurity program, the other can use the framework to identify
critical controls

1) Partial: no formal process in place, you are waiting for something happen
and you deal with that

2) Risk Informed:you understand what;s going on, paying attention for what's
happening, no no formal policy in place to deal with it when it does happen
3) Repeatable: policy and procedure in placem, not a ton of tools to deawl
with incidents in real time, detect what's happening , policies in place, no
tool to deal with real time basic

4) Adaptive: enough controls in orga to deal with attacks on a real time basis
when things, they understand quickly how to isolate that, how to reduce the
threat surface, damamge done to their organization, to recovery quickly

It is a bit overskill

National institute of standards and technology (NIST)

2014 - Barrack Obama

2017 - Donald Trump orders all goverment agencies should use this
framework to protect themselves from cyber attcks

You should ask VF is not goverment agency in US, but the framework is
adopted by lots of large businesses, lots of small businesses, because it is a
very good framework

Category and subcategory - improve cyber posture.

Identify: you cannot protect something if you cannot be aware of its


existence, assure nothing out of your radar

asset management:

all the hardwares that you use, server, pc, printer, lapto, internet devies:

software: cloud service, email service, in the identify stage

risk assessment: old version of software, all needed to be picked up in the


identify

every thing inside business that needs some kind of protection

Protects:
all tools, processes, in place to protect assets against cyber attack

So take one example: Microsoft365, Outlook Exchange , what is the risk


associated to that email solution ? you can be phished (course 1) for leaking
sensitive info, like your account name + password, so how to protect ? MFA,
enable 2 second defense, cover the risk. Identify risk => implement
solution/polciy

Detect:

tools, processs in your business , to detect cyber attacks,

alert the risk ? intruder alarm ? CCTV ? really good to detect when your home
at risk, the same in cybersecurity, who is providing security monitoring ?
internal or staff, external vendor, looking for anomaly

MS365, you log into mailbox in Russia, when you do not have any member in
Russia, that could indicate that as a breach

Respond:

when detected a cyber attack, how does your business respond to that ?

Analysing the breach is, containing damangem action plan

our home: intruder in home, what next ? call a police ? response plan,

notify people, customer, stakeholder, left the door open, should close.

Recover:

is not to have a cyber attack, what strategy in place to be recovered form


the cyber attack ?

restore after the cyber attack to what it was before the cyber event, but a
proper state and higher protection thatn before

Recovering from ransomware , using a very good backup , key ingredient in


recovery stage.

this is happenned ? make sure it will not happen again.

Recovery: Communicate with people, staff, partners,

This is happened and this is what we have done about is the victime,
Activities (what)

Activities breakdown (what/how)

Subcategories (Detailed statements on how to implement (HOW))

Common questions

Powered by AI

The main stages of the cybersecurity framework are Identify, Protect, Detect, Respond, and Recover. - 'Identify' involves recognizing all organizational assets, both hardware and software, to be aware of what needs protection . - 'Protect' involves implementing tools and processes to safeguard these assets from cyber attacks, such as using multi-factor authentication . - 'Detect' includes ongoing monitoring for potential breaches using tools like security monitoring systems and anomaly detection . - 'Respond' involves enacting a response plan when a breach is detected to minimize damage, including notifying stakeholders and containing the breach . - 'Recover' focuses on restoring normal operations post-attack, often involving backups and communicating recovery steps to interested parties . These stages contribute to resilience by promoting a proactive and structured approach to cybersecurity.

The 'Detect' function plays a critical role in identifying and monitoring for potential cyber breaches through ongoing surveillance. Tools such as anomaly detection software, security monitoring systems, and alerts for unusual activity (e.g., logging into accounts from unexpected locations) enhance its effectiveness . By employing these tools, organizations can promptly identify and address unauthorized access attempts, thus maintaining a secure environment.

The NIST cybersecurity framework is widely adopted by businesses of all sizes because it offers a comprehensive, flexible, and scalable approach to cybersecurity, which can be tailored to fit various organizational needs regardless of size . Its ability to improve cybersecurity posture effectively makes it a preferred choice beyond governmental usage.

'Gap Analysis' helps by comparing the organization's current cybersecurity profile against desired standards, highlighting areas needing improvement. It allows the organization to tailor its cybersecurity program to bridge these gaps . This process ensures that resources are allocated effectively to fortify critical areas, thereby facilitating a more robust cybersecurity posture.

The implementation tiers are Partial, Risk Informed, Repeatable, and Adaptive. - 'Partial' tier reflects a lack of formal processes, leading to reactive management of cyber incidents . - 'Risk Informed' tier indicates awareness and understanding of cyber risks, though without formal policies, limiting proactive measures . - 'Repeatable' tier means that policies are in place, but there's limited real-time capability to handle incidents effectively . - 'Adaptive' tier showcases an organization with comprehensive controls and real-time incident response capabilities, allowing for quick threat isolation and minimizing damage . The ability to manage cyber risks improves significantly from Partial through Adaptive, with Adaptive being the most robust in preventing and mitigating cyber threats.

To transition from 'Partial' to 'Adaptive,' an organization should first conduct a thorough gap analysis to understand deficiencies . Develop and document formal policies and procedures, invest in real-time monitoring tools, and ensure the staff is trained for dynamic threat response. Establish a continuous improvement plan focusing on adaptive strategies for threat isolation and surface reduction, involving regular reviews and updates to security controls to respond effectively in real-time .

Ongoing monitoring and anomaly detection help identify potential breaches in real-time by tracking unusual activities such as unauthorized logins or atypical traffic patterns . This continuous surveillance allows for immediate interventions, minimizing the window of opportunity for attackers and thereby strengthening the organization's cybersecurity posture by maintaining constant vigilance and swift response capabilities.

The 'Protect' stage is crucial as it proactively implements safeguards to secure assets against cyber attacks. Specific measures include using tools and processes such as enabling multi-factor authentication, particularly for services like Microsoft365 . By strengthening these defenses, an organization can mitigate risks like phishing, thereby reducing the chance of a breach. This stage is vital to preventing unauthorized access and protecting sensitive information.

Conducting regular risk assessments allows organizations to stay aware of emerging threats, out-of-date software, and vulnerable points within their operational technology and systems . This proactive identification of risks aids in prioritizing protective measures and strategies, maintaining a robust security posture, and reducing the likelihood of successful cyber attacks through timely interventions.

The 'Respond' stage involves executing an action plan to contain and minimize damage, which includes notifying affected parties and stakeholders . It ensures that immediate steps are taken to stop further damage and manage communication effectively. The 'Recover' stage focuses on restoring systems to their pre-attack state, in addition to ensuring improved protection post-recovery . These stages mitigate consequences by ensuring swift containment, effective communication, and enhanced future protection.

You might also like