Implementing Cybersecurity with NIST Cybersecurity Framework and COBIT 5

Cybersecurity risks, like financial and reputational risks, are business risks. The NIST Cybersecurity Framework (CSF) focuses on the use of business factors that guide the activities to respond to cybersecurity risks as an integral part of the organizational risk management processes.

The framework consists of three parts:

  • The framework core
  • A framework profile
  • Framework implementation tiers

The Framework Core
The framework core is a set of cybersecurity activities, desired outcomes and references that are common to all critical infrastructure sectors. It provides detailed guidelines for the development of individual organizational profiles.

A Framework Profile
Through the use of profiles, the framework will help the organization align cybersecurity activities with business requirements, risk tolerance and resources.

Framework Implementation Tiers
Framework implementation tiers provide a mechanism for organizations to observe and understand the cybersecurity risk and the processes in place to manage that risk.

Since the framework refers to recognized global standards for cybersecurity, it can be used by any organization and can serve as a model for international cooperation in strengthening cybersecurity for critical infrastructures.

Organizations have unique risks, different threats, different vulnerabilities and varied risk tolerances, all of which will influence how the practices of the framework are implemented.

Definition of Critical Infrastructure
Critical infrastructure can be defined as systems and assets so vital that the incapacity or destruction of such systems and assets would have a critical impact on national economic security or public health or safety, or any combination of those matters.

The CSF offers a risk-based approach that uses metrics to continuously improve cybersecurity. Though it was originally intended to support critical infrastructure providers, it is applicable to any organization wishing to manage and reduce the risk of cybersecurity. The CSF helps improve risk management of each organization and ultimately reduce the risk of cybersecurity worldwide.

As part of its Cybersecurity Nexus (CSX) program, ISACA offers a step-by-step guide for the implementation of NIST CSF. The activities and processes that are proposed can help to determine what to do in each phase, but are not prescriptive and should be adapted to meet individual organizational goals:

  • CSF Step 1: Prioritize and Scope: COBIT Phase 1: What are the drivers?
  • CSF Step 2: Orient
  • CSF Step 3: Create a Current Profile: COBIT Phase 2: Where are we now?
  • CSF Step 4: Conduct a Risk Assessment
  • CSF Step 5: Create a Target Profile: COBIT Phase 3: Where do we want to be?
  • CSF Step 6: Determine, Analyze and Prioritize Gaps: COBIT Phase 4: What needs to be done?
  • CSF Step 7: Implement Action Plan: COBIT Phase 5: How do we get there?
  • CSF Action Plan Review: COBIT Phase 6: Did we get there?
  • CSF Lifecycle Management: COBIT Phase 7: How do we keep the momentum going?

The challenges and opportunities lead to risk assessments and priorities, and foster organizational commitment and ownership. Thus, successful governance and management processes are institutionalized in the organizational culture.

Juan Carlos Morales, CISA, CISM, CGEIT, CRISC
IT governance and risk management consultant and trainer
COBIT 5 accredited trainer

[ISACA]

New (ISC)² Executive Director Introduction: Building on Our Successes & Striving for Excellence

I’m pleased to start off 2015 as the new (ISC)² executive director. As someone who has been entrusted with information security responsibilities throughout my career, I welcome the opportunity to speak out about the challenges we face on behalf of those working to keep our cyber world safe.

During my past two years as COO at (ISC)², I’ve seen the organization make positive strides toward establishing a member focus; however, this is a sustained commitment with more work to be done. I want to build on the momentum of our successes while continuing to evaluate areas that we need to improve so that we’re continually striving for excellence in everything we do.

As the new (ISC)2 executive director, I want to continue on the path of success we’ve achieved under the leadership of Hord Tipton, whose boundless energy and enthusiasm for all things information security and (ISC)2 are unrivaled in the industry. I understand that I have big shoes to fill.

My own background includes 14 years working with the U.S. Coast Guard before moving to the U.S. Department of Interior, where I ultimately served as deputy CIO. At both organizations, I was fortunate to work with some true visionaries who understood the role IT could play in these large, disbursed organizations with diverse missions. The last ten years of my government career, I served at the senior executive level before joining (ISC)2 in 2012. My full bio can be found on the (ISC)2website at https://www.isc2.org/management-team.aspx.

Having worked in the profession and having dealt with the challenges of managing large infrastructure as well as the challenges associated with information security, I come into this role with passion and sincerity to advocate for the profession. I also have a sense for the hard work that goes into this across the board – not just the security roles, but IT professionals that may monitor and manage infrastructure that hosts or provides access to enterprise information assets.

I think there are some parallels between public service and a not-for-profit that’s membership oriented. We’re here on behalf of you – the global membership. The investments and decisions we make should stand up to the questions and transparency we need to demonstrate to our members and always need to deliver value.

I take my new responsibility of being the leader and public face of this organization very seriously. My first order of business will be to continue to advance our global partnerships to ensure a smooth transition and to continue building rapport with the lifeblood of our organization – the global (ISC)² membership. There’s certainly more work to be done on behalf of the membership to advance our mission globally, and I plan to roll my sleeves up to further that cause.

We have a broad range of initiatives underway, so I will ensure those projects come to fruition. It’s not always about adding new ideas to the pipeline. I’ve always respected people and organizations that demonstrate the ability to make great ideas a reality. During my tenure as executive director, I plan to advance the goals and objectives that our Board of Directors has put forth for the organization and its 100,000-plus global membership.

I look forward to this exciting new challenge of becoming the leader of (ISC)². Let’s make 2015 a prosperous and progressive year!

[(ISC)² Blog]

Lessons from the Sony Breach: Four Things That Need to Happen Now

When the finger pointing about attribution stops, the recent Sony breach will endure as one of the three most significant cybersecurity events of 2014 because it once again highlighted a number of critical gaps in the ability of individual organizations to defend themselves against targeted attacks. A breach of this magnitude can make us all wonder, how are organizations supposed to defend themselves when attacked by a nation state, or a highly organized criminal group with deep pockets and high levels of know how?

Think about it this way. If an organization’s headquarters or a branch office were under physical attack by armed assailants, they normally would call the police, who would dispatch the SWAT teams and other resources needed to physically protect the organization from further harm. But in today’s world of advanced cyberthreats, when an organization is under siege, there generally is no such protection offered to them.

Organizations must defend their information assets in today’s threat landscape. And here are four steps they should take immediately.

  1. First of all, organizations must develop a stark sense of reality about what they can do well and what they cannot in cybersecurity. CIOs, CISOs, and security leaders must revisit the organizational structure and skills of their security teams and IT staffs that have any responsibility for securing information assets. This analysis involves a deep review of what currently are or can be core competencies for the organization, and where they might need help from outsiders. Important questions to ask include:
    • What is the right structure for the security team?
    • What skills are required and where are the gaps?
    • If we need to have these skills in-house, do we need training and certifications?
    • Which additional skills should we hire, and which should we outsource to service providers who are more experienced in these areas?
  2. Foster deeper collaboration within your industry and across industries. We all know that the bad guys share information freely and across borders and do not have to play by the rule of law. So, it is critical for the good guys to have more opportunities at all levels to collaborate both electronically and in person to share information and intelligence about current attack techniques and emerging threats. We need more effective collaboration forums than we have today. Better collaboration will help alert companies to the latest threats and help them identify the right solutions and service providers. There is some great collaboration happening in certain industry sectors today—the financial services is the most successful example—but we need a significant increase in information sharing and collaboration—and this change requires more trust among practitioners and changes to regulatory and legal frameworks. One of the missions of ISACA’s Cybersecurity Nexus(CSX) is to create additional collaborative environments going forward for practitioners at all levels to share information.
  3. Take a back-to-basics approach by focusing on protecting that which matters most to the organization with solid security controls. More organizations should implement effective governance and controls frameworks, such as the U.S. NIST Cybersecurity Framework and ISACA’s COBIT framework. When an organization fully commits to implement a model framework, it has a much higher likelihood of success in protecting its crown jewels—with the added benefit of not having to reinvent the wheel. If a company focuses on good controls based on accepted standards and frameworks, some of the cyber risks they are facing would be greatly reduced.
  4. Do not just create good contingency plans and incident response plans—practice them. It is critical to involve a wide variety of players across the organization—not just IT and security. Communications, legal and senior management all must be involved—and so must the necessary outside service providers who augment an organization’s key cyber skills. For incident response plans to be effective, the internal and external ecosystem must be well understood, and all parties must be ready to act. Given what we all observed in 2014, practice may not make perfect, but it sure will help a lot.

Last, but certainly not least, it is critical that security practitioners understand the relationship between their organization, its people, its IT assets and the kinds of adversaries and threat actors they are facing. It is only through this analysis can the right cybersecurity program be designed and implemented where budget, skills, intensity, and performance all are balanced at the appropriate levels.

Eddie Schwartz, CISA, CISM
President, White Ops, Inc.
Chair, ISACA’s Cybersecurity Task Force

[ISACA]

ISACA: International President: Highlights of 2014

ISACA celebrated its 45th anniversary in 2014, and marked this accomplishment with a year of great advancements. One of the most visible and impactful events was the launch of Cybersecurity Nexus(CSX). At a time when cybersecurity breaches and devastating hacks make news daily, CSX offers innovative ways to help provide resources for cybersecurity professionals at all levels and fill the global skills gap. ISACA also successfully introduced the Cybersecurity Fundamentals Certificate and several workshops were sold out, which further supports the need and acceptance of CSX worldwide.

In addition, the online version of COBIT 5 was released, complete with a new Goals and RACI (responsible, accountable, consulted, informed) planner. This tool helps organizations of all sizes and industries improve governance and management of enterprise IT. COBIT 5 is used globally to help create value and address business issues.

We also implemented our digital strategy and are able to provide members with fresher content more frequently and in an easy-to-use format. Most notably, the ISACA Journal—one of the top member benefits—is now publishing online articles every two weeks instead of every two months. COBIT Focus, which provides the latest news and case studies about COBIT, is also publishing articles more frequently.

And in September, ISACA took another step toward its future by welcoming our new chief executive officer, Matt Loeb. Matt brings to ISACA a depth of experience, and he will be an instrumental factor in our future growth.

Driving all of these activities is ISACA’s commitment to what ultimately makes us a successful organization—our valued members around the world. For all of you who have attended chapter meetings, obtained CISA, CISM, CGEIT or CRISC certifications, participated in a Training Week or conference, or read the ISACA Journal or one of our many other excellent research publications, the board of directors and I thank you for your support and expertise. The future of ISACA has never looked brighter.

Robert E Stroud, CGEIT, CRISC
2014-2015 ISACA International President

[ISACA]

4 Infosec Resolutions For The New Year


Don’t look in the crystal ball, look in the mirror to protect data and defend against threats in 2015.

As the year draws to a close, security gurus begin the annual ritual of predicting what horrors will befall us after the calendar turns from December to January. While this gloomy approach ignores the potential for actually improving infosec, it also sidesteps the opportunity for reflection. The truth is, any security incidents that will occur in 2015 will be the result of lingering errors created in the past. Here are four dangers that will continue unless we resolve to act now.

Legacy code, present danger
Just because some bit of code has been used since the dawn of time does not mean it has been thoroughly vetted. In the past few months, we saw years-old (or even decades-old) vulnerabilities unearthed in the form of the Heartbleed,Shellshock, Poodle, and Unicorn bugs. It’s nearly impossible to predict where the next of these ancient vulnerabilities will surface, but it’s a fair bet that you’ll find them wherever there is a piece of code that has been used by millions and has been largely unchanged for years. In 2015, security teams should resolve to give that legacy code a thorough review.

Expedience at the expense of security
Last year was not a good one as far as major payment card security goes. It brought us breaches at Neiman Marcus, Michael’s craft store, P.F. Chang’s, Dairy Queen, Jimmy Johns, Goodwill, Staples, and Home Depot, among others. Predicting another year full of yet more breaches seems like something of a no-brainer. In the largest of these breaches, at Home Depot, company officials had been warned about flaws in their security. Instead of taking action, they chose expediency over security, and they are now paying the price of millions of unhappy customers. The causes of all these breaches are all basic security concerns: loss of login credentials, lack of adequate network segmentation, absence of encryption, use of default device passwords, and disabling of security features. While we can’t say better security would have prevented all of these events, we can resolve to make breaking-in far more difficult for the attackers.

Malware: Everything old is new again
The headlines may be all about the newest and most unusual malware, but the majority of what affects the average person is still the same old, boring stuff that has been around for ages. Infecting computers usually doesn’t require the newest vulnerabilities, and it doesn’t necessitate the stealthiest tactics. The most effective threats often still rely on old-fashioned social engineering, because criminals are not going to pull out the metaphorical “big guns” if they know they can get their payday with tactics that are simply “good enough.”

Right now, the cost of entry for malware writers is exceedingly low, and the return on investment is very high. Until that equation changes, we’re not likely to see much of a decrease in malware in particular or cybercrime in general. The coming year is likely to bring some improvements, but in fits and starts rather than as a complete sea change. Let’s get that process moving faster.

Looking back to look ahead
For most people, technology is a new and often confusing thing. Many organizations are going digital fairly reluctantly, choosing only the easiest and most user-friendly aspects to deploy. Historically, this has led to a general perception that information security is a drag on innovation — not an essential feature of the technology infrastructure. As people become more informed, as security products become easier to implement, and as more people become aware of the costs of leaving themselves open to attack, this situation is likely to evolve for the better.

The good news is that old problems, by and large, already have solutions: All we have to do is recognize and implement them. There are a lot of things that we can all do to improve our security. Once we remove the low-hanging fruit, we will make it more costly and difficult for criminals to do their jobs. That’s not to say that removing that fruit will be an easy task — in fact, it’s far more difficult than our current policy of worrying about the most challenging (one might even say “advanced, persistent”) fruit.

It is my hope that in the coming year, the brilliant minds in this industry will reflect on what we can do to make security simpler and more approachable for the general public.

What are your infosec resolutions for 2015? Please share them in the comments.

Lysa Myers began her tenure in malware research labs in the weeks before the Melissa virus outbreak in 1999. She has watched both the malware landscape and the security technologies used to prevent threats from growing and changing dramatically. Because keeping up with all this change can be difficult for even the most tech-savvy users, she enjoys explaining security issues in an approachable manner for companies and consumers alike. Over the years, Myers has worked both within antivirus research labs, finding and analyzing new malware, and within the third-party testing industry to evaluate the effectiveness of security products. As a Security Researcher for ESET, she focuses on providing practical analysis and advice of security trends and events.

[DarkReading]

English
Exit mobile version