The modern day Payment Card Industry Data Security Standard (PCI DSS) v3.1, applies a robust layered approach for the security of cardholder data, applying the concept of defence in depth (DiD). This concept is nothing new and can be seen to have been applied by the Roman Empire in the 4th century AD1 and developed over 700 years, during the enhancements of the city of Troy2 , between 1700 BC and 1190 BC.
DiD was successfully developed as the result of numerous ‘lessons identified’, following numerous conflicts and incidents over many years.
However, given this strong legacy and long history of successful application of the DiD methodology, why is it that successful business leaders are still struggling to recognise the importance of creating a robust PCI DSS citadel, for the safety and security of their customers’ cardholder data operations?
The major difference between the Romans and the Trojans and now is that the types of assets have changed.
Historically, the assets were visible, tangible assets (Helen of Troy, precious jewellery, etc.) that were clearly identifiable and easier to see. Today, technological advancements have changed the assets into a mix of tangible assets (physical credit cards, receipts, chargeback letters, etc.) and virtual, intangible assets (eCommerce, Mail Order/Telephone Order computer processed, etc.) that are more difficult to identify and locate where they might reside (databases, spreadsheets, flat files, etc.).
Added to this is the fact that most acquiring banks grant approval for merchants to process cardholder data before they have created their secure citadel, in support of their card payment operations, or they are not made aware of the associated costs and complexities of building and maintaining secure card payment processes.
How can the lessons of the Romans and Trojans be applied to modern day business card payment operations?
Likened to history, today there is a clear and present threat from hostiles attempting to penetrate your defences, in order to gain from stealing customers’ cardholder data. These attackers can range from the opportunist, amateur hacker, who is driven by 3 incentives:
Inquisitiveness
Challenge
Reward (mostly not financial reward, but more personal reward—like winning a game of strategy)
Or:
The attacker could be a determined, organised criminal gang, who is informed of the value of the assets within an organisation. The criminal fraternity have changed their modus operandi to reflect the gains of the modern day. No longer do they need to go through the complexities of planning to rob a bank, much like they might have done in the 1950s or 1960s, when they can gain the same benefit from dropping in a simple piece of malware (such as a RAM scraper) into a large retail business.
These examples present the ‘kinetic’ (external) threat vectors. However, the successful application and management of PCI DSS also helps protect against the non-kinetic (insider) threat—that authorised insider who carries out an activity (either maliciously or accidentally) that causes a breach.
Would your staff help to wheel a Trojan Horse through your suite of defensive countermeasures?
What steps are required?
The city of Troy took 700 years to construct; PCI DSS is only 12 years old and still in development. However, there are a great deal of lessons we can take from history, as shown in figure 1 and listed here:
Figure 1: Nettitude PIE FARM methodology
Plan & Prepare3
Set up a team, within the business, to design architectural and project plans, presented within a business case, which clearly articulates what the predicted set-up and maintenance costs might be, along with defined milestones.
Identify & Isolate
What are the methods of taking card payments (payment channels)?
What are your businesses card data flows?
What assets (technologies, people, processes, locations, etc.) support the card payment operations?
Are there any inter-connecting assets?
Is it possible to reduce the scope, through the creation of a Secure Bunker/Citadel (RED Channel) where the card payment systems reside, that is isolated from the non-card payment systems?
Which of the PCI DSS controls apply to the business?
Evaluate
Having established the baseline, carry out a gap analysis to provide the rapid identification of areas requiring improvement.
Fix
Work through a suite of remediation activities.
Assess
Carry out an investigation into the maturity and effectiveness of the application of the baseline controls.
Report
Complete a Self-Assessment Questionnaire (SAQ), against each of your payment channels (low-volume merchants) or have an independent onsite assessment, by a Qualified Security Assessor (QSA), to validate that your card payment operations are safe and secure.
Maintain
Do not become complacent, once having completed the process to ‘get across the line’ and achieve the compliance status. PCI DSS requires a number of mandated, scheduled activities:
6-month firewall reviews
Quarterly card data discovery
Annual web application testing
Vulnerability and patch management
Daily audit trails reviews
Weekly change detection reviews
Quarterly wireless checks
Quarterly internal and external
Annual penetration testing (or after any significant change)
In complex environments, how can you hope to effectively govern your PCI DSS footprint, ensuring that assigned responsibilities are being carried out effectively and in a timely manner?
Scheduling?
On The Job (OJT)?
Security Awareness?
Well-written and -communicated, effective policies and procedures?
Effective security incident response?
Employment of a governance, risk and compliance tool? (shown in figure 2)4
The associated PCI DSS worlds are ever-changing, dynamic environments, with the attackers become ever more creative. Therefore, as attackers create new and innovative approaches, we need to ensure that our defensive responses are just as innovative and responsive.
The benefit of this approach is that it will help to reduce the chance of suffering a breach, whilst reducing the cost and improve the overall security culture within an organisation.
“Cyber Security is everyone’s responsibility”
Federal Bureau of Investigations5
Unit 42 is currently researching an attack campaign that targets government and military personnel of India. This attack appears to overlap with the Operation Transparent Tribe andOperation C-Major campaigns that targeted Indian embassies in Saudi Arabia and Kazakhstan, as well as the Indian military.
We are tracking the group of actors involved in this campaign as ‘ProjectM’. During our research, we found a linkage between the infrastructure used by ProjectM and an individual from Pakistan. We cannot definitively confirm this individual is involved with this attack campaign, but the evidence that we will discuss in this blog post suggests that it is highly likely that this individual has some involvement with the threat group.
This blog post highlights the trail of evidence individuals leave on the Internet when they are not careful about disguising their identity. All of the information collected about this actor is public and accessible through open source research.
Overview of Transparent Tribe
The ProjectM actors rely on both spear-phishing emails and watering hole sites to deliver a variety of different tools to target the Indian government and military. ProjectM actors used a blog with a theme related to the Indian military titled “India News Tribe” (intribune.blogspot.com) as a watering hole to deliver their payloads. This group also used spear-phishing emails with malicious RTF files exploiting CVE-2010-3333 or CVE-2012-0158, in addition to Excel files that contained malicious macros to download and install their payloads as well.
The actors have access to a sizeable toolset of Trojans that they use in their attack campaigns, including custom developed tools called Crimson and Peppy, along with off-the-shelf remote administration tools (RATs) and downloaders, such as DarkComet and Bozok. Another interesting part of this campaign is the use of techniques and Trojans often seen in cybercrime attacks, such as the use of the Andromeda Trojan as an initial payload in their attacks to download and execute other tools in their toolset. The Operation Transparent Tribe report by Darien Huss of Proofpoint provides an excellent analysis of the various tools used by this group, including Crimson and Peppy and their associated infrastructure.
Registration Slip Up
During our research, we analyzed the registration information of the Andromeda, Crimson and Preppy Trojan command and control domains used by ProjectM. A majority of the infrastructure associated with ProjectM was registered using WHOIS protection services, which conceals the actual registrant’s information (name, email, etc.) used to register the domain name. However, we discovered that the actors had in all likelihood, inadvertently neglected to use WHOIS protection on two domains in their infrastructure that they used to host C2 servers for the Andromeda Trojan.
The two undisguised domains were “winupdater[.]info” and “ordering-checks[.]com”, which were registered using the email address “mshoaib.yaseen [at] gmail.com”, as seen in Figure 1. The Andromeda samples used these undisguised domains to deliver Peppy Trojans that used the previously observed ProjectM domain “bbmdroid.com” as a C2 server. The email address and information used to register these domains appears to be real and associated with the actor, which differs from most infrastructure used in targeted attacks that use fake information and a disposable email account during registration. On August 5, 2014, the actor seemingly discovered his mistake as the “ordering-checks[.]com” domain was updated with WHOIS protection.
Domain Name: ordering-checks.comCreated On: 2014-02-11
Expiration Date: 2015-02-11
Registrant Name: Muhammad Kamran
Registrant Street1: R02323 Karachi
Registrant City: Karachi
Registrant State/Province: Sindh
Registrant Postal Code: 74200
Registrant Country: PK
Registrant Phone: +92 3452183117
Registrant Fax: +92 3452183117
Registrant Email: mshoaib.yaseen@gmail.com
Figure 1 WHOIS Information for Two Command and Control Domains without Whois Protection
Who is in ProjectM?
The Gmail address seen in Figure 1 is directly linked to Facebook, LinkedIn, Google+, and Skype accounts. All of the accounts have corroborative biographical content, giving us a possible identity of a potential actor, who appears to be a 26-year-old individual from Karachi, Pakistan. At this time, we cannot absolutely confirm this individual’s involvement with ProjectM, Operation Transparent Tribe or Operation C-Major campaigns; however, strong evidence was discovered linking this individual’s online presence to entities related to the threat group, which can be seen in the chart in Figure 2. Additionally, content posted to the social networking accounts suggest that the actor has an anti-Indian sentiment, which may be a motivating factor for the actor to participate in such attack campaigns.
Figure 2 Diagram of links between the actor and ProjectM
Web Designer by Trade
We believe the individual associated with the email address “mshoaib.yaseen [at] gmail.com” was at one time and possibly still involved in web design services, as well as revenue generating efforts using Google AdSense. Interestingly, it appears that the individual reused servers and domains set up during web design efforts to host malicious content used in attack campaigns as well.
The web design and technology services company hosted at “apnits[.]4t[.]com” listed the phone number “0345-2183117” for its chief executive and as its support number. This phone number is the same as seen in the registration information in Figure 1 without the country code “+92”. We did not find any malicious content on this site; however, we did find content that suggests it was last revised in November 2006.
Another web design company created by the individual was discovered at “xtexhosts.com”. The phone number “+92.3452183117” was also found in the WHOIS information and was registered using the email “spid3rsoft [at] gmail.com”. We do not have any indication of malicious content hosted on xtexhosts.com, but it appears that the actor created it for Xtex Studios, which appears to be another web design company started by the actor.
We found a third domain, “easternkingsology[.]com,” that contained registration information with the name “Xtex Studios” and the registration email of “mshoaib.yaseen [at] gmail.com” until the domain expired in December 2015. The “easternkingsology[.]com” domain hosted a Bozok RAT sample at hxxp://easternkingsology[.]com/det/dllbb.exe (SHA256: e4dfcf3db512260e1a4ff414907610d5d5279143fa9ade9219d8691be02e512f), which suggests the threat actor hosted this Trojan on an Xtex Studios related domain for use in a ProjectM campaign. Figure 3 shows an advertisement of the services provided by Xtex Studios using “mshoaib.yaseen [at] gmail.com” and “karachian.gem [at] hotmail.com” for contact purposes.
We found the registration phone number and email address for xtexhosts[.]com on an advertisement for another web design company called SPID3R[.]SOFT. The advertisement seen in Figure 4 was hosted on “sahirlodhi[.]com”, which was a domain also used by ProjectM as the download location for a sample of the Crimson tool. At first we hypothesized that sahirlodhi[.]com may have been a compromised site, as it appeared to be the official site for the Pakistani television actor Sahir Lodhi. On May 10, 2008, the domain registration information was updated to include the registrant email of “mshoaib.yaseen[at]gmail.com”, suggesting the threat actor was involved in the creation of this website. The registration information for this domain remained the same until May 21, 2014 when it was updated to include WHOIS privacy protection. We believe that the threat actor still had access to the sahirlodhi[.]com webserver and used it to host the payload for ProjectM, further suggesting that the actor reuses domains and servers to host content and payloads unrelated to its original purpose.
Figure 4 Advertisement of SPID3R.SOFT Web Design
In addition to xtexhosts[.]com, the domain “thefriendsmedia[.]com” was also registered using the email “spid3rsoft[at]gmail.com”. This domain hosts a multimedia website that claims it is “Asia’s Biggest Entertainment Portal”. Unit 42 saw this domain hosting several ProjectM tools, including the exact same Andromeda and Peppy samples as those previously observed using bbmdroid[.]com as a C2, which were hosted at “/est/estma.exe” and “/est/controller.exe” respectively.
The “thefriendsmedia[.]com” site makes references to “thefriendsfm[.]com”, which was originally registered in October 2010 using the email “mshoaib.yaseen[at]gmail.com”. On March 24, 2014, the actor shared a link on his Facebook (figure 5) and Google+ accounts to an article hosted on “thefriendsfm[.]com” titled “MOD Assistant Director and Staff Grade NTS Results 2014”, which is currently still present on the “thefriendsmedia[.]com” domain. The post discusses applying for positions at the Pakistani Ministry of Defense (MOD), but we do not have any conclusive evidence that the actor applied to or is connected in anyway with the MOD.
Figure 5 Actor’s Facebook post to an article regarding jobs in Pakistan’s Ministry of Defense
Social Media Activity
The email address “karachian.gem[at]hotmail.com” seen in the advertisement of Xtex Studios led to the discovery of the possible identity of an individual that is likely involved with ProjectM. Unit 42 found the individual’s Google+ profile, seen in Figure 6 and noticed that the profile had several posts that included domains that had hosted payloads or were C2 servers associated with ProjectM, such as:
bbmdroid[.]com (Peppy, Bozok)
shobitech[.]com (Peppy, DarkComet, Andromeda)
mustache-styles[.]com (Andromeda)
messagerieneuf[.]com (Crimson)
sahirlodhi[.]com (Crimson)
Figure 6 Possible Actor Involved with ProjectM
Also, Facebook and Google+ posts include “Bind an exe in excel file | Microsoft Excel Exploit | ShobiTech” (Figure 7), which is interesting as ProjectM has used malicious Excel delivery documents with macros to download and install payloads in its attack campaign.
Figure 7 – Actor discusses technique seen in campaigns
The “shobitech[.]com” domain also appeared in one of the actor’s Facebook accounts. This Facebook account provided a great deal of information about the actor, specifically in the photos section. The actor used the shobitech[.]com domain in 2013 to host details of a training course (Figure 8) that he was conducting on how to monetize YouTube using Google AdSense.
Figure 8 Advertisement Associated with a Training Conducted by Actor
The photos also show the actor obtained a certificate for completing the “Windows Exploit Development Megaprimer” online course hosted on udemy.com and screenshots of the actor using various offensive security tools, such as Metasploit on Kali Linux (Figure 9). The Operation Transparent Tribe report suggested that Meterpreter samples were used as payloads in the campaign, which is interesting as Meterpreter is part of the Metasploit Framework that the individual has had experience with according to the photos uploaded to his Facebook account.
Figure 9 Photo Uploaded to Facebook Account of Individual Using Metasploit
Furthermore, another Facebook account belonging to this actor points to “shoaibyaseen[.]com”, which appears to host this individual’s personal blog. The blog has a total of twelve posts between February 29, 2016, and March 2, 2016. The topics posted to this blog include network port scanning and data gathering techniques, as well as commands to run using Metasploit and Meterpreter to accomplish various tasks to exploit systems and carry out post-exploitation activities. While the use of Meterpreter in Figure 9 and the topics in the “shoaibyaseen[.]com” blog in Figure 10 do not directly implicate this individual, it does strongly suggest that he possesses skills that would be valuable to offensive campaigns like those conducted by ProjectM.
Figure 10 Recent posts on the actor’s blog with topics including Metasploit and post exploitation activities
Another interesting observation about this actor is that his name shows up in the debug symbol path of several Crimson tools. The actor’s name appears in the debug symbol path of samples of the Crimson downloader and the remote administration tool, suggesting the actor may have been involved with the development of this Trojan. For instance, the following shows an example of the actor’s name in the debug symbol path of a Crimson downloader (SHA256: dc8bd60695070152c94cbeb5f61eca6e4309b8966f1aa9fdc2dd0ab754ad3e4c):
The email address “karachian.gem[at]hotmail.com” also led us to the individual’s blogger account, which was created in April 2008. The “About Me” section of this blogger account states that this individual lives in Karachi, Pakistan and studied computer science. This account also created several other blogs as well, most of which had little content of interest with the following exceptions:
bbmdroid[.]blogspot[.]com
indian-attack[.]blogspot[.]com
Freeowlsofminerva[.]blogspot[.]com
Figure 11 Picture of Individual Associated with Blogger Accounts
The first related blog of interest is bbmdroid[.]blogspot[.]com that contains a link to “bbmdroid[.]com”, which hosted C2 services for various ProjectM tools. The indian-attack[.]blogspot[.]com does not contain any malicious exploit code or payloads, but has a theme of terrorism in India. A blog with a theme related to India closely resembles the India News Tribe (intribune[.]blogspot[.]com) blog that ProjectM used in Operation Transparent Tribe to deliver Crimson payloads.
The “freeowlsofminerva[.]blogspot[.]com” blog was created on August 24, 2013, to offer a service for players of the MapleStory MMORPG. The links on the blog point to Excel spreadsheets hosted on “microsoftexcel[.]united-host[.]us”, such as:
The blog also includes a link at the bottom of the page to a VirusTotal scan of a file named “(Bera) FM Price List.xlsx” that showed that no antivirus vendors detected the file as malicious. We do not have access to the spreadsheets hosted “microsoftexcel[.]united-host[.]us” to confirm if they were malicious or not; however, we did observe a DarkComet payload (SHA256: cc488690ce442e9f98bac651218f4075ca36c355d8cd83f7a9f5230970d24157) hosted on this server at “microsoftexcel[.]united-host[.]us/update.exe”. The fact that a payload was hosted on this server leads us to believe the inclusion of the link to a VirusTotal analysis is a social engineering attempt to increase the likelihood a victim would click the links.
Figure 12 Use of VirusTotal Report to Increase Likelihood of Victim Clicking Links
Conclusion
ProjectM is a threat group conducting targeted attacks on government and military personnel of India. Unit 42 has linked several different domains within ProjectM’s infrastructure to an individual residing in Pakistan. This corresponds with the suspicions of David Sancho and Feike Hacquebord at Trend Micro, who documented a likely Pakistani link to the activity in theirOperation C-Major report.
At this time, we cannot elaborate on the extent of this individual’s involvement with the targeted attacks; however, it does appear that the individual was involved with setting up some portion of the infrastructure used by the various payloads delivered in the attack campaign. According to the individual’s social media pages and blogs, it strongly suggests he possesses skills to carry out offensive activities in ProjectM campaigns. Also, the individual’s name appearing within Crimson Trojan samples suggests that he may have been involved with the creation of the malware as well.
Trend Micro reported finding gigabytes of personal identifiable information (PII) in open directories on C2 servers related to ProjectM, mostly belonging to Indian Army personnel. Although such PII might be used for financial gain, we find multiple instances in social media and blogs where this actor states anti-Indian sentiments, suggesting he is potentially politically motivated.
While knowing the identity and motivations of a possible actor is not necessarily actionable from a defensive perspective, it does provide a good reminder that people are always behind an attack, as it is easy to become fixated solely on the technical aspects of malware and infrastructure.
Palo Alto Networks researchers Tongbo Luo and Hui Gao were credited with the discoveries of new critical Microsoft vulnerabilities affecting Internet Explorer (IE) versions 7, 8, 9, 10 and 11 on affected Windows clients. These vulnerabilities are documented in Microsoft Security BulletinMS15-106 and MS15-112.
In our continued commitment to the security research community, these vulnerabilities were disclosed to Microsoft through our participation in the Microsoft Active Protections Program (MAPP) program, which ensures the timely, responsible disclosure of new vulnerabilities and creation of protections from security vendors.
Palo Alto Networks is a regular contributor to vulnerability research and has discovered more than 90 critical vulnerabilities over the past two years. By proactively identifying these vulnerabilities, developing protections for our customers, and sharing them with Microsoft for patching, we are removing weapons used by attackers to compromise enterprise, government and service provider networks.
During this exciting time of technological advancements, when there is an app for every facet of our lives, from letting you know the right time to take a bathroom break during a movie to how to build a space shuttle, why am I continually disappointed? We have become a generation addicted to our apps and having the latest and greatest technologies, but that comes with a steep price. We have to continually ask ourselves with every purchase and click, what is my data and privacy worth if and when it is leaked, breached or stolen?
George Santayana wrote: “Those who cannot remember the past are condemned to repeat it.” (The Life of Reason, 1905)
With all the massive security breaches that happen daily around the globe, why are we not learning from them and from each other? Why are we not taking the necessary precautionary steps as consumers and manufacturers? Maybe a better term for “Internet of Things” should be “Anyone Can Control my Things?”
Just because it is convenient to connect all your devices doesn’t mean you should. The price for convenience can cost our privacy, our reputation, our livelihood, and even our lives. To the average user, a connected smart thermostat is just a thermostat. We would never imagine that it could be a fully equipped, connected and functioning computer that is able to influence the physical world. Through these in-home devices, an entry point is established to enter your home, access all of your connected devices, and ultimately your entire digital DNA. Over 70% of these devices are vulnerable to cyber-attacks, due to loopholes and backdoors that were left in the hardware and software and being exploited daily by anyone.
We, the consumers, need to band together to push these security threats back onto the responsibility of the companies that create them. The best way to do that is by voting with our feet, our wallets and through legislation. We need to demand that companies build in security. Not just in the beginning with the initial discovery phase when they are researching new products and services, but also carry it out all through the software/hardware development life cycle (SDLC) to include support and maintenance.
What can I do as a consumer?
Research before you buy, and vote with your wallets. Read the EULA, security features and the privacy policies. Install patches, software updates and product upgrades when available.
Don’t buy the first or beta version of the product. Let someone else test it out and wait for the manufacturer to rev the product.
Become active with legislation to help create or change privacy laws for public and private companies to become more accountable for their products and services they bring to the market.
Stop connecting everything. Don’t give up security for convenience.
Use strong passwords and two factor authentication.
What can I do as an employee/manufacturer?
Adopt a security focused approach, build and design security in, create use cases and test cases, write security related requirements through out every iteration. Develop threat models, pen testing and offensive security plans to test potential attacks. Ensure your Business Analysts, Project Managers, QA Engineers, Developers, Architects and Managers are measured on quality and security. Don’t be afraid to speak up if the product does not use proper encryption or privacy controls to secure user data and network services properly.
Stop collecting so much user data, provide consumers with more choices to opt-out of data collection.
Build in a line item into your budget just for security, and that does not mean buy more hardware and software. Invest in your employees, get them trained, cross trained or certified.
Purchase and partner with key manufacturers for the memory, chips, sensors and processors who you trust, don’t pass the buck onto the consumers to pay for your laziness or cheapness.
Don’t create backdoors or leave them open. Harden and secure endpoints.
Listen to your customers, put quality first. Take the lead on creating a secure product line.
Invest in systems that automate the detection of malicious activity so that it can be contained and remediated before data is lost or damage is done. Your network has to be configured to automatically prevent or detect these nefarious behaviors.
Secure the data. Most data is unprotected in the cloud; personally identifiable information (PII) is open to anyone who wants it. The protection needs to start from the sensors and go all the way up to where the data is stored to cover data at rest and data in transit. Companies need to have and enforce a strict data retention policy and make sure they maintain a high level of security compliance.
I often get asked by friends and family, whose responsibility is security, isn’t it the companies that make it? The answer is a resounding, “no,” it is ours. It is our data, we own it and we should protect it. We need to become educated and aware of all the risks that come with surrounding ourselves with IoT connected devices. Companies are not good at securing their products or even their own infrastructures. They are starting to see and feel the effects of these poor decisions and security breaches by firing C-level executives or paying out millions in fines for lost consumer data. Security is every human’s responsibility to ensure that they are taking the necessary precautions to protect their own data. Do not rely on companies to do this on your behalf. As long as being first to market (quickly and cheaply) is their main driver, then security will most likely continue to be an afterthought and a reactionary gesture.
There is good news through all these breaches; the knowledge, experience and awareness is already here, we just need to learn from it. Listen and adapt to fit the constraints of IoT devices into our lives properly. Technology will continue to advance at a rapid pace and get better over time, but so will the bad actors.
Change your passwords frequently, install anti-malware, set up firewalls for your home networks, and most of all, never stop learning and educating yourself on security. Take control of your data and your lives, it is your responsibility. – – Wesley Simpson, COO, (ISC)²
Editor’s note: ISACA Now recently sat down with Frank Downs, ISACA’s senior manager cyber/information security, to discuss CyberSecurity Nexus’ (CSX) new CSX Practitioner Boot Camp.
What is CSX Practitioner Boot Camp? CSX Practitioner Boot Camp is a great opportunity for cybersecurity professionals looking for a more thorough mastery of the hands-on, complex and advanced technical skills they need to protect and defend their enterprises and advance their careers.
The five-day, intensive cybersecurity course will help attendees make significant gains in their training and prepare them for the CSX Practitioner (CSXP) certification exam. It provides an environment to discuss and practice methods implemented by cybersecurity professionals in key areas aligned with global cybersecurity frameworks. The CSXP was recently named Best Professional Certification Program by the 2016 SC Magazine Awards. Becoming CSXP certified is a testament to an individual’s real-life skills and shows employers that he or she has the knowledge and technical ability to walk into an organization and do the job from day one. CSXP Boot Camp is also a great opportunity for organizations that want to develop their cyber workforces.The immersive training will prepare students for five key cybersecurity responsibilities:
Identify: Identification, assessment and remediation of threats and vulnerabilities in internal and external frameworks
Protect: Implementation of cybersecurity controls to protect a system for identified threats
Detect: Detection of network and system incidents, events and compromise indicators and assessment of potential damage
Respond: Execution of comprehensive incident response plans and mitigation of cyber incidents
Recover: Recovery from incidents and disasters, including post-incident response documentation and implementation of continuity plans
What sets it apart from other cybersecurity training?
What really sets CSXP Boot Camp apart—and what makes it so exciting and innovative—is that it is conducted in an adaptive, live, hands-on cyber lab environment, which enables students to build their critical technical skills by learning complex concepts and applying industry-leading methods. Participants will use the latest open-source tools on actual, real-world scenarios. Attendees receive a complimentary 6-month subscription to the virtual cyber lab environment where they can continue practicing and building technical skills.
Another differentiating factor is the use of PerformanScore®, a learning and development tool that measures a professional’s ability to perform specific cybersecurity job tasks. PerformanScore recognizes that there are multiple ways to respond to cybersecurity threats, so it measures performance skills across the entire solution set of possibilities. It compares a professional’s actions to grading criteria, and then references those actions against an adaptive scoring rubric in real-time, allowing instructors to give immediate feedback and helping professionals to better learn and understand more efficient cybersecurity techniques.
Why should a cybersecurity professional make the investment in CSXP Boot Camp training?
Eighty-one percent of respondents to ISACA’s 2016 Cybersecurity Snapshot survey said they would be more likely to hire a candidate with a performance-based certification, so obviously a cybersecurity certification is critical to anyone interested in a cybersecurity career. The Boot Camp positions cybersecurity professionals very well for the CSXP certification exam, which is exactly what cybersecurity hiring managers are looking for. Upon completion of the course students will be prepared to serve as workforce-ready cybersecurity professionals.
Who should attend the Boot Camp?
It is for professionals with up to five years of experience in a cybersecurity role and an intermediate technical skill set. If you are interested in registering for CSXP Boot Camp, you should already demonstrate proficiency in the following areas:
Network scanning
Specialized port scans
Network topologies
Network log analysis
Centralized monitoring
Hotfix distribution
Vulnerability scanning
Traffic monitoring
Compromise indicators
False positive identification
Packet analysis
When/where does the Boot Camp take place?
The expert-led Boot Camp courses will be offered at five US locations in 2016:
Chicago, Illinois (4-8 April)
Washington, D.C. (11-15 April)
New York, New York (16-20 May)
Denver, Colorado (13-17 June)
San Francisco, California (20-24 June)
How Do I Register?
To register for the CSXP Boot Camp, please click here.
Frank Downs, Senior Manager Cyber/Information Security, ISACA