0% found this document useful (0 votes)
8 views13 pages

Cybersecurity Skill Cube Explained

The document describes the Cybersecurity Skills Cube developed by John McCumber. The cube has three dimensions: 1) the three principles of security (confidentiality, integrity, and availability), 2) the three states of data (in transit, stored, and in process), and 3) the three categories of cybersecurity measures (technologies, policies, and knowledge). The cube provides a framework for cybersecurity professionals to protect the cyber world.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
8 views13 pages

Cybersecurity Skill Cube Explained

The document describes the Cybersecurity Skills Cube developed by John McCumber. The cube has three dimensions: 1) the three principles of security (confidentiality, integrity, and availability), 2) the three states of data (in transit, stored, and in process), and 3) the three categories of cybersecurity measures (technologies, policies, and knowledge). The cube provides a framework for cybersecurity professionals to protect the cyber world.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Chapter 2: The Cybersecurity Skill Cube

The term 'hecicero' is a label that describes professionals in cybersecurity who protect the
cyber world. Like the sorcerers of the mystical world, cyber sorcerers are interested
in promoting good and protecting others. John McCumber is one of the first wizards in
cybersecurity. Developed a framework called the McCumber Cube that the wizards of
cybersecurity is used to protect the cyber world. The McCumber cube resembles the Cube of
Rubik.

The first dimension of the cybersecurity skill cube includes the three principles of security.
computer science. Cybersecurity professionals refer to the three principles as the Triad of
CID. The second dimension identifies the three states of information or data. The third dimension of
cube identifies the powers of wizards that provide protection. These powers are the three
categories of mechanisms for cybersecurity measures.

The chapter also analyzes the ISO cybersecurity model. The model represents a framework of
international work to standardize the management of information systems.

The principles of security

The first dimension of the cybersecurity skills cube identifies the objectives to protect
cyber world. The objectives identified in the first dimension are the basic principles of the world
of cybersecurity. These three principles are confidentiality, integrity, and availability. The principles
provide the approach and allow the cyber sorcerer to prioritize actions in the protection of
cyber world.

Confidentiality prevents the disclosure of information to people, resources, or processes.


Authorized. Integrity refers to the accuracy, consistency, and reliability of data.
Finally, availability ensures that users can have access to the information whenever it is needed.
necessary. Use the acronym CID to remember these three principles.

Data states

The cyber world is a world of data; therefore, cyber wizards focus on the
data protection. The second dimension of the cybersecurity skills cube focuses on
the problems of protecting all states of data in the cyber world. Data has three
possible states:
Data in transit

Stored data

Data in process

The protection of the cyber world requires cybersecurity professionals to explain the
data protection in the three states.

Cybersecurity measures

The third dimension of the cybersecurity skills cube defines the types of powers to which a
sorcerer in cybersecurity seeks to protect the cyber world. The professionals in
cybersecurity must utilize all available powers at their disposal to protect the data of
cyber world.

The cybersecurity skills cube identifies the three types of powers and instruments used to
provide protection. The first type of power includes technologies, devices, and available products
to protect information systems and keep cybercriminals at bay.
cybersecurity professionals have a reputation for mastering technological tools at their
disposal. However, McCumber reminds that technological tools are not sufficient to
defeat cybercriminals. Cybersecurity professionals must also create a
solid defense in establishing the policies, procedures, and guidelines that enable citizens
from the cyber world to stay safe and follow the proper practices. Finally, just like the
in the world of wizards, the citizens of the cyber world must strive to obtain more
knowledge about their world and the dangers that threaten their world. They must continuously seek a
greater knowledge and establish a culture of learning and awareness.

The principle of confidentiality


Confidentiality prevents the disclosure of information to people, resources, and processes.
authorized. Another term for confidentiality is privacy. Organizations restrict the
access to ensure that only authorized operators can use the data or other network resources.
For example, a programmer should not have access to the personal information of all employees.

Organizations need to train employees on best practices in protection.


confidential information to protect themselves and the organization from attacks. The methods
used to ensure confidentiality include data encryption, authentication, and control of
access.

Data privacy protection

Organizations collect large amounts of data. Most of this data is not


confidential because it is publicly available, such as names and phone numbers. Other data
collected, however, are confidential. Confidential information refers to the data
protected against unauthorized access to protect a person or organization. There are three types
of confidential information:

Personal information in personally identifiable information (PII) that leads to a person.


In Figure 2, this category of data is listed.

Commercial information is the information that includes everything that represents a risk to the
organization if the public or the competition discovers it. Figure 3 lists this category of
data.

Classified information is information that belongs to a government entity classified by


its level of confidentiality. Figure 4 lists this category of data.

Access control

Access control defines several protection schemes that prevent unauthorized access to a
computer, network, database or other data resources. The concept of AAA involves three services
of security: Authentication, Authorization, and Auditing. These services provide the framework
main to control access.

The first 'A' in AAA stands for authentication. Authentication verifies a user's identity to
prevent unauthorized access. Users verify their identity with a username or an ID.
In addition, users must verify their identity using one of the following methods, as stated
shown in figure 1:

Something that you know (for example, a password)

Something they have (for example, a token or card)

Something that is (for example, a fingerprint)

For example, if you go to an ATM to withdraw cash, you need your bank card (something you have) and you need
conocer el PIN. Este también es un ejemplo de autenticación de varios factores. La autenticación de varios
factors require more than one type of authentication. The most popular form of authentication is the use of
passwords.

Authorization The authorization services determine which resources users can access, along with
the operations that users can perform, as shown in Figure 2. Some systems achieve
this with an access control list or ACL. An ACL determines whether a user has certain privileges of
access once the user authenticates. Just because they cannot log into the company network does not
means that I am allowed to use the high-speed color printer. The authorization may also
control when a user has access to a specific resource. For example, employees may have
access to a sales database during working hours, but the system blocks them afterwards
of the schedule.
Accounting tracks user activities, including the sites they have access to.
amount of time they have access to resources and the changes made. For example, a bank does
a tracking of each customer account. An audit of that system can reveal the time and the
amount of all transactions and the employee or the system that executed the transactions. The
cybersecurity audit services work in the same way. The system keeps track
of each data transaction and provides audit results. An administrator can configure the
computer policies, as shown in Figure 3, to enable system auditing.

The concept of AAA is similar to the use of a credit card, as indicated in Figure 4. The card of
credit identifies who uses it and how much the user can spend on it and explains how many elements or
services acquired by the user.

The cybersecurity audit tracks and monitors in real time. Websites like Norse show the
real-time attacks based on data collected as part of an audit or tracking system.
Laws and responsibilities

Confidentiality and privacy seem interchangeable, but from a legal perspective, they have
different meanings. Most privacy data is confidential, but not all data
confidentials are private. Access to confidential information occurs after confirming the
appropriate authorization. Financial institutions, hospitals, medical professionals, studies
Legal entities and companies manage confidential information. Confidential information has status
private. Maintaining confidentiality is more than an ethical duty.

Privacy is the proper use of data. When organizations collect information


provided by clients or employees, can only use that data for its intended purpose. The
most organizations require a client or employee to sign an authorization form that
grants permission to the organization to use the data.

All the laws listed in the figure include a provision to address privacy that begins
with US laws in Figure 1. Figure 2 lists a sample of international efforts.
Most of these laws are a response to the massive growth of data collection.

The growing number of statutes related to privacy creates a huge burden on the
organizations that collect and analyze data. Policies are the best way for an organization
comply with the increasing number of privacy-related laws. The policies allow for
organizations apply rules, procedures, and specific processes when collecting, storing, and sharing
data.
Principle of data integrity

Integrity is the accuracy, consistency, and reliability of data throughout its lifecycle. Another term
For integrity, it is quality. Data undergo various operations such as capture,
storage, retrieval, updating, and transfer. Unauthorized entities must
keep the data unchanged during all these operations.

The methods used to ensure data integrity include the hash function, the
data validation checks, data consistency checks, and controls
of access. Data integrity systems may include one or more of the mentioned methods
previously.

The need to ensure data integrity

Data integrity is a fundamental component of computer security. The need to have


Data integrity varies depending on how an organization uses the data. For example, Facebook does not
verify the data that a user publishes on a profile. A bank or financial organization assigns a higher
importance of data integrity that Facebook. The transactions and customer accounts
They must be accurate. In a healthcare service organization, data integrity can be a
matter of life or death. Information about prescriptions must be accurate.

Protecting the integrity of data is a constant challenge for most organizations. The
data integrity loss can make all data resources questionable or
useless.
Integrity verifications

An integrity check is a way to measure the uniformity of a data collection.


file, an image, a record). Integrity verification carries out a process called function of
hash to take a snapshot of the data at a specific moment in time. Integrity verification uses
the snapshot to ensure that the data remains unchanged.

A checksum is an example of a hash function. A checksum verifies the integrity of files or


strings, before and after they transfer from one device to another through a
local network or Internet. Checksums simply convert each piece of information into a value and sum them up.
the total. To verify the integrity of the data, a receiving system simply repeats the process. If
the two sums are equal, the data is valid (Figure 1). If they are not equal, a change occurred in
some part of the line (Figure 2).

Common hash functions include MD5, SHA-1, SHA-256, and SHA-512. These hash functions use
complex mathematical algorithms. The hash value is simply there for comparison. By
For example, after downloading a file, the user can verify the integrity of the file by comparing
the hash values of the source with which any hash calculator generates.

Organizations use version control to prevent accidental changes made by users.


authorized. Two users cannot update the same object. The objects can be files, records
from the database or transactions. For example, the first user to open a document has permission
to change that document; the second person has a read-only version.

Accurate backups help maintain data integrity if the data is damaged.


the company needs to verify the backup process to ensure the integrity of the copy
security before data loss occurs.

Authorization determines who has access to an organization's resources based on the need for
information. For example, file permissions and user access controls ensure that
only certain users can modify the data. An administrator can set permissions to only
reading for a file. As a result, a user with access to that file cannot perform any
change.
The principle of availability

The availability of data is the principle used to describe the need to maintain the
availability of information systems and services at all times. Cyber attacks and the
System failures can prevent access to information systems and services. For example, to alter
the availability of competitors' websites when removed can provide an advantage to your rival.
These denial of service (DoS) attacks threaten the availability of the system and prevent
legitimate users have access to and use information systems when necessary.

The methods used to ensure availability include system redundancy, backups of


system security, greater system recoverability, equipment maintenance, operating systems
updated software and plans to quickly recover from unplanned disasters.

The five nines

People use different information systems in their daily lives. Computers and the
Information systems control communications, transportation, and product manufacturing.
The continuous availability of information systems is fundamental to modern life. The term
high availability, describes systems designed to avoid downtime. High availability
availability ensures a level of performance for a period higher than normal. High systems
availability usually includes three design principles (Figure 1):

Eliminate single points of failure

Provide a reliable cross connection

Detect failures as they occur

The objective is the ability to continue functioning in extreme conditions, such as during an attack. A
One of the most popular high availability practices is the practice of five nines. The five nines
they refer to 99.999%. This means that the downtime is less than 5.26 minutes per
year.

Ensure availability

Organizations can ensure availability by implementing the following:

Perform maintenance on the equipment

Perform updates of the OS and the system

Perform backup copy tests

Make a plan to prevent disasters

Implement new technologies

Monitor unusual activities

Perform the availability test


Types of data storage

The stored data refers to the saved data. The stored data means that a
type of storage device retains data when no user or process is using it. A
Storage device can be local (on a computing device) or centralized (on the network).
There are several options for storing data.

Direct Attached Storage (DAS) provides storage connected to a computer.


A hard drive or a USB flash drive is an example of storage.
direct connection. By default, systems are not configured to share the
direct connection storage.

The Redundant Array of Independent Disks (RAID) uses multiple hard drives in an array, which is a
method to combine multiple disks so that the operating system sees them as a single disk. RAID
provides better performance and better fault tolerance.

A network-attached storage (NAS) device is a storage device


connected to a network that allows for the storage and retrieval of data from a location
centralized by authorized users of the network. NAS devices are flexible and
scalable, which means that administrators can increase capacity as needed.

A storage area network (SAN) architecture is a storage system based on


the network. SAN systems connect to the network through high-speed interfaces that enable
better performance and the ability to connect multiple servers to a centralized repository of
disk storage.

Cloud storage is a remote storage option that uses space on a


data center provider and is accessible from any computer with internet access. Google
Drive, iCloud, and Dropbox are examples of cloud storage providers.

Challenges in the protection of stored data

Organizations have a difficult task when trying to protect stored data. To improve the
data storage, companies can automate and centralize data backups.

Direct connection storage can be one of the most difficult types of storage.
data in managing and controlling. Direct connection storage is vulnerable to attacks
malicious on the local host. The stored data may also include backup data.
Backups can be manual or automatic. Organizations should limit the types of
data stored in direct connection storage. Specifically, an organization does not
I would store the critical data on direct connection storage devices.

Network storage systems offer a safer alternative. Storage systems of


Network storage including RAID, SAN, and NAS provides greater performance and redundancy. Without
However, network storage systems are more complicated to configure and manage.
They also handle more data, which poses a greater risk to the organization if the device fails.
The specific challenges of network storage systems include configuration, testing and
system supervision.

Data transmission methods

Data transmission involves sending information from one device to another. There are various methods.
to transmit information between devices, including the following:

Transfer network: uses removable media to physically move data from one
computer to another

Wired networks: use cables to transmit data

Wireless networks: they use radio waves to transmit data

Organizations will never be able to eliminate the use of a transfer network.

Wired networks include copper wiring and fiber optic networks. Wired networks can serve
to a local geographical area (local area network) or can cover large distances (wide area networks).

Wireless networks are replacing wired networks. Wireless networks are increasingly
faster and are able to handle more bandwidth. Wireless networks extend the amount
of guest users with mobile devices in the small office and home office (SOHO) and the
business networks.

Wired and wireless networks use packets or data units. The term packet refers to
a unit of data that moves between a source and a destination on the network. Standard protocols such as
the Internet Protocol (IP) and the Hypertext Transfer Protocol (HTTP) define the structure and formation of
data packets. These standards are open source and available to the public. The protection of
the confidentiality, integrity, and availability of transmitted data is one of the responsibilities
most important for a cybersecurity professional.

Challenges in the protection of data in transit

The protection of transmitted data is one of the most challenging tasks for a professional.
cybersecurity. With the growth of mobile and wireless devices, professionals
Cybersecurity is responsible for protecting massive amounts of data that cross the network daily. The
Cybersecurity professionals must face several challenges when protecting this data:

Protection of data confidentiality: cybercriminals can capture,


store and steal data in transit. Cyber professionals must take measures to
counteract these actions.

Protection of data integrity: cybercriminals can intercept and alter


data in transit. Cybersecurity professionals implement integrity systems for the
data that evaluate the integrity and authenticity of the transmitted data to respond to these
actions.

Protection of data availability: cybercriminals may use


false or unauthorized devices to disrupt data availability. A device
A simple mobile can present itself as a local wireless access point and deceive users.
unprepared when associating with the fake device. Cybercriminals can hijack
an authorized connection to a service or a protected device. Security professionals
they can implement mutual authentication systems to respond to these actions. The
mutual authentication systems require the user to authenticate the server and request that the
server authenticates the user.

You might also like