Essentials of Cybersecurity
Module 2
Q.1. Define Cybersecurity Management. What are the various components
in cybersecurity management?
Cybersecurity management encompasses the strategies, policies, and procedures
organizations use to protect their information and systems from cyber threats. It
involves planning, organizing, implementing, and monitoring security practices to ensure
confidentiality, integrity, and availability of data and systems. This includes risk assessment,
incident response planning, access control. Cybersecurity management must employ a variety
of administrative, legal, technological, procedural, and employee practices to reduce
organizations’ risk exposure.
Components of Cybersecurity management include.
a) Risk Management b) Incident Response c) Compliance management
d) Security awareness and training.
Q.2. What is risk management? Describe various phases of risk
management process.
Risk Management involves identifying, assessing, and prioritizing risks, which are then
followed by coordinated efforts to minimize, monitor, and control the probability or impact of
adverse events. This is a systematic way of managing uncertainty with the assurance that an
organization can achieve its objectives while mitigating potential threats.
Risk management process involves.
Identify Assets
Assets need to be identified before they can be protected. This initial step identifies all the
applications, services, and devices that are crucial to the business – or support mission-
critical processes
Identifying Risks
This is one of the most important initial steps in risk management, which deals with the
identification of those risks that could affect an organization. This generally means a
profound analysis of both internal and external factors, which might constitute threats or even
opportunities. Internal threats may involve financial uncertainties, inefficiency in operations,
and human resource-related challenges, while external ones may relate to market fluctuations,
changes in regulations, environmental conditions, and geopolitical events.
Assess Risks
After the significant risks are noted, evaluation must be done to establish the likelihood and
the possible impact. It also considers examining, for every risk, the probability of its
occurrence and the severity of the consequences. Scoring of risk assists in rating each risk
with a score set by its likelihood and impact, hence prioritizing the same.
Developing Strategies
After analyzing the risks, strategies need to be formulated on the basis of the organization.
Some of the strategies for handling the risk include
Treatment – finding security tools and best practices to resolve the issue
causing the risk; examples include installing firewalls, proxy servers, and
antimalware.
Tolerance – accepting the risk is unavoidable and deciding to tolerate its
existence; this calculated risk should fall within established risk acceptance
criteria.
Termination – completely cutting the system, software, or hardware out and
redesigning affected processes to run without them.
Transferal – reducing the risk by dividing the risk with another party;
examples here could be outsourcing security to a technology company or
buying insurance.
Implement Measures
It is at this stage that the developed risk management strategies are put into actual practice.
This step ensures that the planned measures are well executed, with resources being put to
good use.
Monitor and Review
Risk management is not a one-time activity but a continuous process. Strategies must be
continuously monitored and reviewed to ensure that they remain effective and relevant.
Monitoring on a regular basis would include monitoring of the risks and effectiveness of
mitigation measures for any changes or new risks. The updating of risk assessments and
strategies should be done based on new information, or any changes in the risk environment,
or organizational change.
Q.3. What is incident response? Describe various phases of Incident
response
Incident Response in Cybersecurity is a structured way for organizations to take care of
cyberattacks and mitigate data breaches. It involves finding and containing incidents,
minimizing damages, and preventing such similar future security events.
Preparation
The organization prepares to create an incident response plan. It selects the right incident
response tools and resources to train teams.
Detection and Analysis
In this phase of the incident response lifecycle, organizations will focus on accurately
detecting and assessing security incidents.
Containment, Eradication, and Recovery
The business tries to reduce the impact of security incidents. They try to keep the scope of
damage as small as possible and mitigate service disruptions.
Post-Event Activity
This is one of the stages of the incident response lifecycle, where the goal is to learn the
lessons of an incident and improve afterwards. It limits the chances of such events and
identifies ways to strengthen future incident response activities.
Q.4. Name some tools that are used in response phase of incident management.
Endpoint Security Solutions
These protect endpoints, users, networks, and assets by continuously monitoring your
endpoints and upgrading perimeter defenses.
Threat Intelligence Tools
allow organizations to collect data, analyze logs, and make informed business decisions. They
protect brands from reputational hazards and analyze data from diverse and multiple sources.
SIEM Platforms (Security Information and incident Management)
SIEM platforms provide comprehensive business security through automated incident
response, data analytics, and log management.
Q.5. Name some security controls that can be used during incident
management.
Security controls exist to reduce or mitigate the risk to those assets. They include any type of
policy, procedure, technique, method, solution, plan, action, or device designed to help
accomplish that goal. Recognizable examples include firewalls, surveillance systems, and
antivirus software.
Physical controls - describe anything tangible that’s used to prevent or detect unauthorized
access to physical areas, systems, or assets. This includes things like fences, gates, guards.
Technical controls - (also known as logical controls) include hardware or software
mechanisms used to protect assets. Some common examples are authentication solutions,
firewalls, antivirus software, and intrusion detection systems (IDSs)
Administrative Controls - refer to policies, procedures, or guidelines that define personnel
or business practices in accordance with the organization's security goals. These can apply to
employee hiring and termination, equipment and Internet usage, physical access to facilities.
Q.6. How can the security controls be classified on the basis of their
functionality?
Preventative controls - Describe any security measure that’s designed to stop unwanted or
unauthorized activity from occurring. Examples include physical controls such as fences,
locks, and alarm systems; technical controls such as antivirus software, firewalls, and IPSs;
and administrative controls like separation of duties, data classification.
Detective controls- Describe any security measure taken or solution that’s implemented to
detect and alert to unwanted or unauthorized activity in progress or after it has occurred.
Physical examples include alarms or notifications from physical sensors.
Corrective controls - include any measures taken to repair damage or restore resources and
capabilities to their prior state following an unauthorized or unwanted activity. Examples of
technical corrective controls include patching a system, quarantining a virus, terminating a
process, or rebooting a system.
Q.7. Define Cybersecurity Governance.
Cybersecurity governance refers to the set of policies, processes, and practices that
organizations implement to ensure the effective management, protection, and oversight of
their information systems and digital assets. It establishes a structured framework to address
cybersecurity risks, compliance requirements, and the evolving threat landscape.
Q.8. Why is Cybersecurity governance Important?
Cybersecurity governance serves as the backbone of an organization’s defense against cyber
threats, providing a set of strategies to safeguard sensitive information, uphold regulatory
compliance, and ensure the continuity of business operations. Some of the major areas where
cybersecurity plays an important role includes.
Protection of Sensitive Information- By upholding the principles of confidentiality,
integrity, and availability (CIA), governance measures ensure that unauthorized access to
critical data is prevented, data integrity is maintained, and information remains accessible
when needed.
Risk Management and Mitigation- By closely aligning with relevant laws and regulations,
governance frameworks help organizations avoid legal repercussions and financial penalties.
Also, adherence to industry standards demonstrates a commitment to ethical practices.
Preservation of Business Continuity-Through the development of incident response plans,
governance frameworks enable organizations to react swiftly and cohesively in the face of
cybersecurity incidents
Customer and Stakeholder Trust-Organizations that demonstrate a commitment to robust
cybersecurity measures through effective governance practices instill confidence in their
clients and partners
Q.9. What are the principles on which cybersecurity governance is based?
Cybersecurity governance is guided by a set of principles that organizations should abide by
to establish effective and resilient security measures. The following serve as foundational
elements for developing a comprehensive cybersecurity governance framework.
Risk-Based Approach — allows organizations to prioritize efforts based on the potential
impact and likelihood of threats
Alignment with Business Objectives — ensures that security measures support and enhance
the organization’s mission and values
Proactive Protection — includes proactive monitoring, vulnerability management, and
secure-by-design practices
Comprehensive Policies and Procedures — cover all aspects of information security
Continuous Monitoring and Adaptation — enables timely detection and response to
cybersecurity incidents in real-time
Governance Structure and Accountability — ensures accountability at all levels of the
organization
Regulatory Compliance — allows updated knowledge of relevant laws, regulations, and
industry
Q.10. What are the different roles in Cybersecurity management?
Chief Information Security Officer (CISO): A senior executive responsible for the
organization's overall information security strategy.
Cybersecurity Manager: Oversees cybersecurity operations, manages security teams, and
develops security policies.
Security Consultant: Provides expert advice on security best practices and strategies to
clients.