This website uses cookies to store information on your computer. Some of these cookies are used for visitor analysis, others are essential to making our site function properly and improve the user experience. By using this site, you consent to the placement of these cookies. Click Accept to consent and dismiss this message or Deny to leave this website. Read our Privacy Statement for more.
Home   |   Contact Us   |   Sign In   |   Register
Article Library
Blog Home All Blogs
Search all posts for:   

 

View all (1227) posts »
 

Cyber Hygiene is a Full Contact Team Sport

Posted By USFN, Friday, October 15, 2021

 

by Dan McCarroll
Cybersecurity Consultant

How many times a week do many of us question whether we are cybersecurity minded, have we somehow been exposed to an intrusion or become victims of an attack? If approached with a little planning, shared language, and some commonsense steps, many of the mysteries cybersecurity carries may be solved.

 

Obviously, nothing is 100% guaranteed, nor can we ensure our systems are completely secure and all vulnerabilities cannot be known since they will be unique to our organization. There is not a single solution for securing information systems and it is not possible to “copy, paste, and execute” a cybersecurity plan. What can be accomplished though, is replicating, and adapting some well thought out standards and practices.

 

In a broad discussion, advancing a collective cybersecurity posture seems the least pejorative topic area and approach. It is assumed in the material that follows that our Information technology professionals are working from a cybersecurity framework. The intent of this piece is not to retell or challenge a cybersecurity professional on how to best secure infrastructure and the information riding on it. It is, however, presented with the idea that gaining a better understanding of what an organization has at risk and where additional emphasis and capabilities should be applied to reduce risk.

 

Many of these tips are presented with the idea that an organization has an IT department and maybe a helpdesk capability. It does not assume there is a separate cybersecurity director or officer solely dedicated to information security. Along those lines, it is worth considering that IT support is not a good place for cybersecurity responsibilities and governance to reside. The inherit conflict is that IT is a support element where both internal and external users go to for resources, answers, and solutions to their day-to-day user needs.  The cybersecurity responsibilities are less about support and more about protecting, detection and recovery. IT support is customer service-like and cybersecurity is more about policies and procedures with a bent toward restrictions and limits in place to prevent network attacks.

 

Formulating a Plan
Ideally, an effective cybersecurity plan flourishes with the separation in duties between the two requirements. That is not to say IT is not inextricably tied to and part of a sound and effective cybersecurity solution, but rather having both IT and cybersecurity responsibilities under one office proves to be a difficult in practice. It is especially challenging when compliance (which includes best practices and or accepted norms) and conveyance decisions are in conflict.

 

When conducting a cybersecurity assessment, ask questions with that focus and you are on the way to having the right information to be implement in a cybersecurity strategy and plan or to refine your existing plan. A good question to ask is where are you organizationally in terms of protecting digital systems and the information these systems deal in, process, store, transfer, and then interact with in every expanding data and information world we find ourselves indulging in every minute of every day?

 

An assessment should be viewed and conducted with the goal of gaining a better understanding of where a certain set of policies, process and procedures stand in terms of effectiveness. The results of an assessment should provide findings that are factual and then from these findings we can take steps to address gaps or shortfalls in our organization specific needs.

 

Assessing an organizations cybersecurity methods and procedures can be daunting but taken a piece at time can reduce the sense of peril normally felt as organizations attempt to increase the cybersecurity effectiveness. This piece should not be viewed as anything more than a healthy start from which to build on. The actions taken after an assessment will become your cybersecurity strategy and plan. The assessment is your due diligence piece of the process. In a chicken or egg scenario, the cybersecurity strategy and plan will almost always specify the requirement for a cybersecurity assessment with a certain periodicity.

Taking the First Cybersecurity Steps

The first piece of the puzzle is best solved with a business unit and staff level effort. A cybersecurity assessment team should be created and at a minimum membership should include:

 

  1. Senior management providing oversight and to ensure the C-suite has a touch point.

  2. An information security and or Information technology officer technical lead for system infrastructure and network security practices.

  3. A privacy and or compliance officer to help identify the systems where personally identifiable information, the Health Information Portability and Accountability Act (HIPAA), and other security such as best practice out of the Department of Commerce, National Institute of Standards and Technologies Cybersecurity Framework (NIST CSF).

  4. Someone from each of the business units, including finance, marketing, human resources, and any of the other organization unique units.

 

This assessment team brings their business unit specific understanding and perspective in achieving organizational objectives. It is common to need further tailoring as the team forms and better understands the organizational cyber security posture.

 

The assembled assessment team now takes on some very specific while not all-inclusive steps such as:

 

  1. Identify the information the business units deal in, ingest, generate, store, process and or share.

  2. Identify where and how information is stored and archived.

  3. Identify how information is accessed from within the organization and remotely.

  4. Identify service providers who have access to the onsite networks or provide access to users.

  5. Identify the various methods users access services, onsite networks, and other subscription accounts.

  6. Identify Wi-Fi systems and VPN for remote desktop access, hot spots and devices such as cell phones and company or user provided IT systems.

  7. Identify all the servers, laptop, printers, file storage systems utilized

  8. Identify all software, web service, remote vendor connections to the information system

  9. Identify the service providers that interact with the infrastructure, or your organizational user and client have account with or access to.

 

Using these steps, which are periodically reviewed, the team identifies a prioritized list of assets that are most important and potentially most likely to be the things that can be attacked or compromised. This list is based on the type of data being handled and the users and systems this critical information or service resides on or interacts with.

 

In some cases where information is being outsourced for storage or processed by a vendor, the service license agreement (SLA) must be reviewed to establish potential risk of data loss or release.

 

To effectively protect assets, the next steps fall under the risk management process, where network management and system configurations controls are refined. It should be noted that additional monitoring of logs and network traffic may be recommended. Along with these technical controls it is highly likely the risk management process will require stronger password control policies addressing lengthening the reused password list, as well as shortening time a password can be used. It is rare the management process does not refine or direct user awareness training in the areas of protections from malware ingestions to response and procedures for suspected phishing attacks.

 

Establishing Policies
While insider threats are regarded as being a big risk to information security, they remain one of the weakest aspects of most risk management processes. While it doesn't address all the concerns of insider threats, the establishing and monitoring of a "least privilege” policy for all users can help to mitigate some risks from insider threats.

 

A least privilege policy reduces cyber security risk by limiting user access to IT resources based on position, functions, and or need. An example of least privilege: If only 2 of 100 users have access to the payroll system the risk of a weak password being exposed and resulting in an attack is lower than if 10 of 100 users have account privileges.  Most contemporary software systems allow for limited users privileges where some users have only read access or can only see information and or files. This nuanced privilege management approach greatly reduces the chance a file or data can be altered intentionally or otherwise. Data integrity risks are reduced when the number of users that can alter or edit the data is limited to those who absolutely need to.

 

This same concept is applied every day when we restrict access to physical locations in our facilities. Least privileges reduce our exposure to attack or compromise.

 

In a least privilege environment, all users are treated as if they should not have access or privileges unless there is a clearly justified and defined need. As an example, new users, by default are given access to corporate network with word processing, spread sheet applications and an email.  Then based on position and or organizational assignments (team, group, or business unit) a user is granted additional accesses to resources.

 

User training programs that focus on protecting information through use of separation of duty principals, least privileges where users are trained to recognize phishing emails, and the procedures for handling suspected attempts can help minimize risk, as will the maintenance of software and hardware with appropriate patches installed as available.

 

While these ideas are neither new nor cover every aspect of risk assessment, this type of approach offers organizations a way approach to cybersecurity and steps to implement understandable and low-cost policies and procedures.

 

Dan McCarroll has over thirty-five years as a system engineer and network administration across the Department of Defense. He currently consults on supply chain security and cybersecurity with emphasis in the Department of Defense Cybersecurity Maturity Model (CMMC). Dan is a CISSP and PMP with a MS in Cybersecurity, Fordham University.

 

Copyright © 2021 USFN. All rights reserved.

 

Fall 2021 USFN Report

 

This post has not been tagged.

Permalink | Comments (0)
 
Membership Software Powered by YourMembership  ::  Legal