
by Dan McCarroll
Cybersecurity Consultant
How many times a week do many of us question whether we are cybersecurity
minded, have we somehow been exposed to an intrusion or become victims of an
attack? If approached with a little planning, shared language, and some
commonsense steps, many of the mysteries cybersecurity carries may be solved.
Obviously, nothing is 100% guaranteed, nor can we ensure our
systems are completely secure and all vulnerabilities cannot be known since they
will be unique to our organization. There is not a single solution for securing
information systems and it is not possible to “copy, paste, and execute” a cybersecurity
plan. What can be accomplished though, is replicating, and adapting some well thought
out standards and practices.
In a broad discussion, advancing a collective cybersecurity
posture seems the least pejorative topic area and approach. It is assumed in
the material that follows that our Information technology professionals are working
from a cybersecurity framework. The intent of this piece is not to retell or
challenge a cybersecurity professional on how to best secure infrastructure and
the information riding on it. It is, however, presented with the idea that
gaining a better understanding of what an organization has at risk and where additional
emphasis and capabilities should be applied to reduce risk.
Many of these tips are presented with the idea that an
organization has an IT department and maybe a helpdesk capability. It does not assume
there is a separate cybersecurity director or officer solely dedicated to
information security. Along those lines, it is worth considering that IT
support is not a good place for cybersecurity responsibilities and governance
to reside. The inherit conflict is that IT is a support element where both
internal and external users go to for resources, answers, and solutions to their
day-to-day user needs. The cybersecurity
responsibilities are less about support and more about protecting, detection
and recovery. IT support is customer service-like and cybersecurity is more
about policies and procedures with a bent toward restrictions and limits in
place to prevent network attacks.
Formulating a Plan
Ideally, an effective cybersecurity plan flourishes with the separation in
duties between the two requirements. That is not to say IT is not inextricably tied
to and part of a sound and effective cybersecurity solution, but rather having
both IT and cybersecurity responsibilities under one office proves to be a difficult
in practice. It is especially challenging when compliance (which includes best
practices and or accepted norms) and conveyance decisions are in conflict.
When conducting a cybersecurity assessment, ask questions
with that focus and you are on the way to having the right information to be
implement in a cybersecurity strategy and plan or to refine your existing plan.
A good question to ask is where are you organizationally in terms of protecting
digital systems and the information these systems deal in, process, store, transfer,
and then interact with in every expanding data and information world we find
ourselves indulging in every minute of every day?
An assessment should be viewed and conducted with the goal
of gaining a better understanding of where a certain set of policies, process
and procedures stand in terms of effectiveness. The results of an assessment
should provide findings that are factual and then from these findings we can
take steps to address gaps or shortfalls in our organization specific needs.
Assessing an organizations cybersecurity methods and
procedures can be daunting but taken a piece at time can reduce the sense of
peril normally felt as organizations attempt to increase the cybersecurity
effectiveness. This piece should not be viewed as anything more than a healthy
start from which to build on. The actions taken after an assessment will become
your cybersecurity strategy and plan. The assessment is your due diligence
piece of the process. In a chicken or egg scenario, the cybersecurity strategy and
plan will almost always specify the requirement for a cybersecurity assessment
with a certain periodicity.
Taking the First Cybersecurity Steps
The first piece of the puzzle is best solved with a business
unit and staff level effort. A cybersecurity assessment team should be created
and at a minimum membership should include:
- Senior management providing oversight and to ensure the C-suite
has a touch point.
- An information security and or Information technology officer technical lead
for system infrastructure and network security practices.
- A privacy and or compliance officer to help identify the systems where personally
identifiable information, the Health Information Portability and Accountability
Act (HIPAA), and other security such as best practice out of the Department of Commerce,
National Institute of Standards and Technologies Cybersecurity Framework (NIST CSF).
- Someone from each of the business units, including finance, marketing, human
resources, and any of the other organization unique units.
This assessment team brings their business unit specific understanding
and perspective in achieving organizational objectives. It is common to need
further tailoring as the team forms and better understands the organizational
cyber security posture.
The assembled assessment team now takes on some very
specific while not all-inclusive steps such as:
- Identify the information the business units deal in, ingest,
generate, store, process and or share.
- Identify where and how information is stored and archived.
- Identify how information is accessed from within the organization and remotely.
- Identify service providers who have access to the onsite networks or provide
access to users.
- Identify the various methods users access services, onsite networks, and other
subscription accounts.
- Identify Wi-Fi systems and VPN for remote desktop access, hot spots and devices
such as cell phones and company or user provided IT systems.
- Identify all the servers, laptop, printers, file storage systems utilized
- Identify all software, web service, remote vendor connections to the
information system
- Identify the service providers that interact with the infrastructure, or your
organizational user and client have account with or access to.
Using these steps, which are periodically reviewed, the team
identifies a prioritized list of assets that are most important and potentially
most likely to be the things that can be attacked or compromised. This list is
based on the type of data being handled and the users and systems this critical
information or service resides on or interacts with.
In some cases where information is being outsourced for storage
or processed by a vendor, the service license agreement (SLA) must be reviewed
to establish potential risk of data loss or release.
To effectively protect assets, the next steps fall under the
risk management process, where network management and system configurations
controls are refined. It should be noted that additional monitoring of logs and
network traffic may be recommended. Along with these technical controls it is
highly likely the risk management process will require stronger password
control policies addressing lengthening the reused password list, as well as shortening
time a password can be used. It is rare the management process does not refine or
direct user awareness training in the areas of protections from malware
ingestions to response and procedures for suspected phishing attacks.
Establishing Policies
While insider threats are regarded as being a big risk to information security,
they remain one of the weakest aspects of most risk management processes. While
it doesn't address all the concerns of insider threats, the establishing and monitoring
of a "least privilege” policy for all users can help to mitigate some
risks from insider threats.
A least privilege policy reduces cyber security risk by
limiting user access to IT resources based on position, functions, and or need.
An example of least privilege: If only 2 of 100 users have access to the
payroll system the risk of a weak password being exposed and resulting in an
attack is lower than if 10 of 100 users have account privileges. Most contemporary software systems allow for
limited users privileges where some users have only read access or can only see
information and or files. This nuanced privilege management approach greatly
reduces the chance a file or data can be altered intentionally or otherwise. Data
integrity risks are reduced when the number of users that can alter or edit the
data is limited to those who absolutely need to.
This same concept is applied every day when we restrict
access to physical locations in our facilities. Least privileges reduce our
exposure to attack or compromise.
In a least privilege environment, all users are treated as
if they should not have access or privileges unless there is a clearly
justified and defined need. As an example, new users, by default are given
access to corporate network with word processing, spread sheet applications and
an email. Then based on position and or
organizational assignments (team, group, or business unit) a user is granted
additional accesses to resources.
User training programs that focus on protecting information
through use of separation of duty principals, least privileges where users are trained
to recognize phishing emails, and the procedures for handling suspected
attempts can help minimize risk, as will the maintenance of software and
hardware with appropriate patches installed as available.
While these ideas are neither new nor cover every aspect of
risk assessment, this type of approach offers organizations a way approach to
cybersecurity and steps to implement understandable and low-cost policies and
procedures.
Dan McCarroll has over thirty-five years as a system
engineer and network administration across the Department of Defense. He
currently consults on supply chain security and cybersecurity with emphasis in
the Department of Defense Cybersecurity Maturity Model (CMMC). Dan is a CISSP and
PMP with a MS in Cybersecurity, Fordham University.
Copyright © 2021 USFN. All rights reserved.
Fall 2021 USFN Report