Introduction
In today’s complex threat landscape, aligning with established security frameworks is essential for designing resilient cloud access and cybersecurity architectures. The NIST, CISA, and DISA frameworks provide structured, authoritative guidance for safeguarding information systems. NIST offers a comprehensive, risk-based approach through its Cybersecurity Framework (CSF), which is widely adopted across various industries. CISA complements this by providing real-time threat intelligence and operational best practices to bolster national cybersecurity. DISA, tailored for defense and government environments, ensures mission-critical systems meet strict security compliance through its STIGs and SRGs. Together, these frameworks form a robust foundation for securing users, endpoints, and cloud infrastructure.
Here in part one of this multi-part skill, we will be exploring these topics:
- Security Framework Overview
- Common Security Frameworks
- The NIST Framework
- The NIST Core Functions
Resources:
Anki deck:
Security Framework Overview
A security framework is a structured set of guidelines, best practices, and standards designed to help organizations protect their information systems and data. These frameworks provide a repeatable and measurable approach to managing cybersecurity risk, offering clarity in a space where threats are constantly evolving. Instead of focusing solely on tools or technologies, frameworks provide a strategic and operational model for aligning security efforts with business and regulatory needs. They serve as a common language among security teams, executives, and regulators.
Knowledge Check
What is the primary purpose of a security framework?
Common Security Frameworks
In today’s ever-changing threat landscape, organizations depend on established security frameworks to develop structured and effective cybersecurity programs. These frameworks offer best practices, standardized controls, and guidance for managing risk across various industries and organizational sizes. The most widely recognized include the NIST Cybersecurity Framework, the CISA Zero Trust Maturity Model, and the DISA Security Technical Implementation Guides (STIGs). Each of these frameworks provides a unique approach to strengthening security posture, and understanding their foundations is crucial for building a resilient and compliant security strategy.
Knowledge Check
Which of the following are examples of commonly used security frameworks?
The NIST Framework
The NIST Cybersecurity Framework (CSF) was created by the National Institute of Standards and Technology to provide voluntary guidance for organizations to manage and reduce cybersecurity risks. Although initially designed for critical infrastructure, it is now widely used across various sectors because of its flexibility and relevance.
The NIST CSF does not mandate specific controls; however, it offers a risk-based, flexible approach to managing cybersecurity efforts at the organizational level. It helps align business and security goals by assisting organizations in identifying their current security posture, setting a target state, and outlining a plan to achieve it.
Knowledge Check
What is the primary purpose of the NIST Cybersecurity Framework (CSF)?
The NIST Core Functions
The updated NIST Cybersecurity Framework (CSF 2.0), as adopted and promoted by Cisco, defines six core functions that guide organizations in managing cybersecurity risks: Govern, Identify, Protect, Detect, Respond, and Recover. These functions represent a comprehensive, high-level approach to organizing cybersecurity activities across all stages of the risk lifecycle. The addition of governance emphasizes the importance of establishing policies, oversight, and accountability structures that support effective cybersecurity management. Together, these six functions provide a scalable foundation for aligning security efforts with business objectives and regulatory requirements.
Knowledge Check
What are the six core functions of the NIST Cybersecurity Framework?
Challenge
Now that you’ve explored the core concepts of this Skill, it’s time to test your understanding. This short challenge includes a series of questions designed to reinforce key ideas and evaluates your ability to apply what you’ve learned. Use this opportunity to review your comprehension and identify any areas that may require further attention before proceeding.
Good Luck!
Knowledge Check
Which NIST CSF function focuses on restoring services after a cybersecurity event?
Knowledge Check
Which organization is responsible for publishing cybersecurity standards for DoD systems?
Knowledge Check
Which of the following is a benefit of the NIST Cybersecurity Framework?
Knowledge Check
What is a key benefit of using the NIST CSF in a commercial environment?
Solution:
Anki deck for challenge:
Knowledge Check
Which of the following do you believe is the MOST critical factor in a successful cybersecurity framework?
This interactive assessment is available in the full learning experience.
View Transcript
Security Framework Overview
0:00So as we jump into our discussion on security frameworks,
0:05I think it's really important to answer the question,
0:08why do security frameworks really matter?
0:11And the short answer to that is security frameworks give us the playbook
0:16for how we're going to implement security in our environment.
0:20And this is really important because modern IT environments are increasingly
0:25complex
0:27and interconnected.
0:29These are going to span things like on premise systems, cloud services, mobile
0:36endpoints,
0:37and third party integrations.
0:40So there's a lot of different things that we have to get working together
0:44and without a coherent plan, organizations are going to struggle to defend
0:49against an increasingly diverse range of threats.
0:52Now, the question becomes, given this challenge of how we approach these
0:57different threats,
0:58we have to have, like we said, a really good game plan.
1:02So how is it that we're going to address this with a security framework?
1:08How does this help?
1:10Well, the first thing we're going to do is we're going to establish baseline
1:14controls.
1:15And this is going to include covering things such as, how are we going to
1:19secure our data?
1:20How are we going to secure our devices?
1:23And that's not just things like PCs and servers,
1:26but of course, all of our networking equipment.
1:29And as we move into smart devices, those need to be protected as well.
1:34We need to make sure that they're secured.
1:36Even things like printers could be compromised.
1:39And of course, that is also going to include the network itself.
1:44And again, that's really talking about things like our routers, our switches,
1:48providing things like firewalls, intrusion prevention systems, and so on.
1:53Next, we're going to provide the methodologies that we're going to use for
1:58assessing the risk
1:59and prioritizing our mitigation efforts.
2:03Again, this is basically setting out what our plan is going to be,
2:07not only to prevent things from happening, but also how do we handle things if
2:12they do happen?
2:14So again, that's where the mitigation comes into play.
2:17We can also use our security framework to enable compliance.
2:22And this could be to any number of standards.
2:26There are industry standards, and there are governmental standards
2:30that we may have to comply with depending what this exact company does.
2:35So for example, if your company does something medically related,
2:40particularly if they're dealing with patient records and patient information,
2:44there are HIPAA laws that we have to abide by in the United States
2:48and other countries around the world have their own privacy laws as well.
2:52Also, if you deal with financials, there are a lot of regulations from the
2:56government
2:57around financial security and such, handling credit card information, things
3:01along those lines.
3:03So there's a lot of standards out there that we have to make sure that we're in
3:07compliance with
3:08either government regulation or again, just private sector standards,
3:13that we want to make sure we meet to give our customers that peace of mind,
3:17that our network and our environment is secure.
3:20We also of course need to have support for the incident response planning.
3:25What do we do in response to something that actually does occur?
3:29How do we mitigate that?
3:31And how do we moving forward?
3:33Make sure that doesn't happen again.
3:36So that's going to involve ongoing security assurances as well
3:40to make sure that any problems that do occur don't happen moving forward.
3:46Now, like most things, security frameworks are going to have some key
3:50components
3:51that we want to be aware of as we move forward.
3:54Here we have a list of them all.
3:56Let's go over each one individually.
3:58So first, we have our policies and procedures, policies and procedures,
4:03define the rules, the responsibilities, actions that must be taken to protect
4:09sensitive information and systems.
4:11This is going to cover things such as data classification, access control,
4:16incident response, and a whole lot more.
4:20Then we have risk management.
4:22This is going to cover the methodologies for identifying vulnerabilities,
4:27assessing potential threats and determining the potential impact of security
4:32incidents.
4:33What's going to happen if we do have some sort of an issue in our environment?
4:40And of course, one of our other goals is going to make sure that these things
4:44actually don't happen.
4:45So that's where security controls come into play.
4:48These are going to be specific measures and mechanisms that we're going to
4:52implement to safeguard our IT systems.
4:55This can include all sorts of things such as firewalls, encryption, intrusion
5:00prevention systems, access control policies,
5:03and even security training, physical control surveillance.
5:07So camera systems, access badges, all sorts of things.
5:11There's a lot of things that fall under security controls, but these are all
5:15the things that we have in place to try to ensure that we don't have to deal
5:20with the risks.
5:22There's always going to be risks, of course, but we want to make sure that we
5:25mitigate that as much as possible.
5:28Next up is compliance.
5:30And again, we've sort of already discussed this, but again, the main idea here
5:34is we have to meet regulatory requirements.
5:36And industry standards.
5:38And again, that might just be industry standards. It can also, of course, be
5:42government regulations as we sort of already discussed there.
5:46The other thing we have to do is have continuous monitoring.
5:50We have to understand what's going on in our environment.
5:54So we have to continually monitor and assess our currently implemented security
5:58measures.
5:59We need to review our structure, do audits to make sure that everything is as
6:03we expect it to be and that our environment is being protected as it should be.
6:09And we have to keep up with any ongoing or new threats and vulnerabilities.
6:16Now, of course, no matter how careful we are, there can still be an incident.
6:21So, of course, the whole idea behind incident response is we have to be
6:25prepared to effectively manage and mitigate the impact of any security breaches
6:31.
6:32So there has to be a plan. We don't want to wait till something happens and
6:35then go, Oh, my goodness. What do we do now?
6:38We should already know what we're going to do in response to different
6:42instances.
6:43So that, of course, is going to involve trying to think things through and
6:46figure out what are the potential things that could go wrong.
6:50Now, again, if possible, we want to then mitigate that.
6:54So we might want to revisit our policies and procedures to see if there's
6:58something we can do to prevent any thought of instance.
7:03But we do still need to make sure we have an incident response plan in place in
7:07case something that we didn't think of actually does happen.
7:11Of course, I think one of the biggest and most important things to talk about
7:15with the security framework is training and awareness.
7:19This one really is key.
7:21Because if I'm being completely honest in all of the security testing that I've
7:25ever done and penetration testing that I performed.
7:29Some of the weakest areas in most corporations are the employees, the humans,
7:35and it's because of training and awareness.
7:39So for me personally, I think this is one of the most important things because
7:43those of us trained for security.
7:46We really understand all the rest of these things.
7:49We're going to do our best on all of these other aspects.
7:52But that doesn't help us if the security guard escorts a stranger into the
7:57server room and gives them full access.
8:00And I have had that happen.
8:02I personally have done penetration testing at a company where I have gone to
8:06what was supposed to be a secure and at the time closed facility.
8:12The way I got in, I busted in the front door, ran right up to the security
8:15guard.
8:16I said, listen, we're having a breach.
8:18We have to get to the email server immediately to stop this from spreading to
8:21the entire company.
8:22They called me in on my way home from dinner.
8:24I've got to get into the server room now and stop this threat.
8:27And I had the security guard actually badge me in to their server room.
8:32So I can tell you the first thing on my security analysis that I turned into
8:36the company was I'm standing in your server room.
8:39It's that simple.
8:41Never should have happened.
8:43They didn't ask for ID.
8:45He didn't ask for anything.
8:47Now, that's just an example of what I'm talking about where that guard was
8:52clearly lacking training and awareness.
8:55They should have known never to let anybody into that building under any
8:59circumstances without proper authorization.
9:02Again, I didn't have ID.
9:03I didn't have anything.
9:05And I was standing right in their server room.
9:07And as I'm sure most of you are aware, having physical access to something is
9:12the first step in getting full access to it.
9:15And one last thing that we want our security framework to handle is going to be
9:19vendor management.
9:21We are going to have third party vendors involved in our network.
9:25So we want our security framework to address third party vendor relationships.
9:31It should have guidelines for evaluating the security practices of the
9:35different vendors and ensuring that their products and service meet the
9:39organization's security requirements.
9:42We want to make sure that we're not bringing in a third party product that is
9:46then going to introduce a vulnerability point into our network.
9:51[ raise your hand ]
Common Security Frameworks
0:00So now that we understand the basics of the security framework and how it's
0:06again going
0:07to act as a playbook for how we run the security in our environment, let's talk
0:12about some
0:13of the common frameworks.
0:15Now there's a lot out there.
0:17We're going to be focusing here on three of the biggest ones.
0:20The first one is the NIST, or the National Institute of Standards and
0:25Technologies.
0:27NIST produces something called the Cybersecurity Framework or the CSF.
0:34They also produce a lot of special publications.
0:38These are called things like SP800-53.
0:40There's of course a bunch of them.
0:43This is just an example.
0:45But these resources help both public and private sector organizations structure
0:51their cybersecurity
0:52program around our core functions.
0:56What are those core functions?
0:59There's identify, protect, detect, respond, recover, and govern.
1:06Now we are going to be covering each of these frameworks in much more detail in
1:12the upcoming
1:13lessons.
1:14So we're not going to focus on the details of each one of these things right
1:17now, but
1:18these are the basic core values that are supplied by the NIST CSF.
1:25Another function of the NIST is to emphasize risk-based decision making.
1:31It's also widely regarded for its depth and adaptability to be put into place
1:38in many
1:38different environments.
1:40So NIST CSF is a very, very common security framework.
1:46Another common security framework that we want to look at is the CISA or the
1:51Cybersecurity
1:53and Infrastructure Security Agency.
1:56This is actually part of the US Department of Homeland Security, so this is a
2:01government
2:01agency and it is responsible for protecting critical infrastructure.
2:07It actually publishes different guidances, toolkits, best practices that we
2:13should use
2:13in our environments.
2:15And again, they may be more aimed towards government infrastructure, however
2:19they can
2:20apply to the private sector just as much.
2:23One of the aims of the CISA is to improve resilience.
2:28That's one of their main focuses.
2:31And as such, this makes it very, very helpful in things like operational
2:35security, helping
2:37with incident management.
2:38Again, what do we do if something does occur and public-private threat
2:43coordination?
2:44In other words, handling things that happen between government agencies and the
2:48private
2:48sector.
2:49So those are the main focuses of the CISA.
2:53Again, we'll be covering this in more detail coming up.
2:56And finally, we have the DISA or the Defense Information System Agency.
3:03This one is really oversight for the US Department of Defense or the DOD.
3:10So this is the agency that's pretty much in charge of how the Department of
3:14Defense
3:15runs their networks.
3:17They produce sort of two major things that we want to be aware of.
3:21The first one is the Security Technical Implementation Guidelines or the STIGs.
3:29These are implementation guides, again, telling us how we should do certain
3:35things.
3:36We also have, of course, the Security Requirements Guide or the Sargis.
3:41And these pretty much tell us what the STIGs should do.
3:45So one of them is the Requirements Guide, of course.
3:49And the other one is how we actually implement things to meet those
3:53requirements.
3:55Now again, this is really for government defense contexts, but it's also not
3:59necessarily bad
4:00to look at the practices for the private sector.
4:04This framework also helps to ensure compliance, again, with the Security
4:08Requirements Guides,
4:10the interoperability, so things, of course, will still work together, and
4:14mission assurance
4:15to make sure that everything happens the way it's supposed to.
4:19Now this is a very prescriptive framework, which means there's not a whole lot
4:24of flexibility
4:25here is that it ensures the compliance, the interoperability, and the mission
4:31assurance
4:32in a high security environment.
4:35And finally, let's talk a little bit about how we would actually apply some of
4:40these frameworks
4:41in actual practice.
4:43The first thing to understand, organizations are going to choose which
4:47frameworks they're
4:49going to use.
4:50And again, they could take aspects from different frameworks or choose to
4:54implement all of them.
4:56This is, of course, entirely up to the organization, but it's going to be based
4:59sort of on two major
5:01things.
5:02First is their industry.
5:04As I mentioned before, depending on what industry this organization is involved
5:09with, things
5:09like financial, medical, military, or DOD contracts, they may have to abide by
5:17certain security
5:18frameworks.
5:19There are going to be regulations that they have to abide by depending on their
5:23industry.
5:24And another part of this is what's their actual risk profile.
5:28What this is referring to is the risk that a company is willing to take in
5:33contrast to
5:34the security mechanisms that they want to implement.
5:38Remember, it's all coming down to money at the end of the day.
5:44Implementing security frameworks is expensive.
5:47We have to buy additional hardware.
5:49We have to implement practices.
5:50We have to invest in training.
5:52I mean, there's a lot of things involved in implementing a security framework.
5:57And depending on what that company does, it may or may not be worth that
6:01financial investment.
6:02I don't think that a barber shop down on the corner called Bob's Haircuts is
6:08going
6:08to worry too much about implementing security on their network to the point of
6:14a DOD contractor.
6:16They don't have that much to protect.
6:18What's the worst that's going to happen?
6:19Somebody's going to break into their network and get a list of their customers
6:22or their
6:23customers' addresses.
6:25It's not a high-risk environment.
6:28So companies have to balance what is the risk of being compromised and what
6:32does that company
6:33have to lose as opposed to the cost it's going to take to protect it to a
6:39higher level.
6:40Now, there's always, of course, some risk.
6:44But the more security we implement, the lower the risk becomes.
6:48So again, that's the trade-off and the organization has to make that choice.
6:53That's where they're going to have to choose how much security they want to
6:57implement in
6:58their environment.
6:59Now, there are some principles of security that are universal, meaning that all
7:03companies
7:04are probably going to want to do this.
7:06They're going to want to have some sort of structured planning.
7:09What's going to happen if there's a compromise?
7:12Now, again, maybe Bob's Haircuts doesn't care a whole lot, but they should have
7:16something
7:17in place.
7:18If we get compromised and somebody gets a list of all of our customers and
7:22their addresses,
7:23maybe what we should do is send out an email or a mailer to all of our
7:26customers saying,
7:28"Look, we've been compromised.
7:30Watch out for compromises of your personal information.
7:33Also, if somebody else tries to get you to go to their shop and poach you as a
7:38customer,
7:38you know, don't fall for it.
7:40We still offer the best haircuts out there."
7:42But there needs to be some sort of planning as to what's going to happen and,
7:46of course,
7:47planning to prevent it as we've discussed.
7:50We also want to have some form of measurable control implementation.
7:55How do we handle our security?
7:57How do we control our security?
7:58How do we monitor our security?
8:01We need to know that a security breach occurred before we can implement our
8:05mitigation plan.
8:06And, of course, we always want to have continuous improvement.
8:11This can be anything from constantly updating all of our software, our firmware
8:15, our security
8:16mechanisms, implementing new things.
8:18We want to make sure our security cameras can actually get clear pictures of
8:22things.
8:22You know, older security cameras, things were often blurry, fuzzy.
8:26They call them potato cams, whereas very hard to see what's going on.
8:29So we should always be updating things to the latest standards.
8:32And again, that can be anything from patches on operating systems, patches on
8:37routers and
8:38switches, ensuring that the network equipment isn't compromised, updating
8:42signatures for
8:43things like antivirus, our intrusion prevention systems, all sorts of things
8:48need to be done
8:48need to be continuously updated and maintained.
8:52And we always want to look for ways to improve as well.
8:56Part of our job as a security officer is to constantly look for vulnerabilities
9:01, constantly
9:01try to think of ways that people could try to compromise our environment and
9:05then mitigate
9:06those by implementing some form of a security mechanism.
9:11Something else we want to watch for when we're applying our frameworks is to
9:15make sure that
9:16they actually help align our daily operations with some form of a long-term
9:22strategy.
9:23And this could include things like building out a cloud policy.
9:26Keep in mind that cloud is relatively new in the IT sphere.
9:33Now it's not that new overall anymore, but more and more companies are moving
9:37towards
9:38cloud and cloud is new to a lot of companies.
9:41Some companies have stayed away from the cloud and now they're finally
9:45migrating to it.
9:46But one way or another, we probably need to at some points start talking about
9:50cloud
9:51policies for an organization.
9:54We also want to make sure that we're deploying secure endpoints.
9:57We need to make sure our workstations and servers and so on are not
10:00vulnerability points.
10:03And also as part of our daily operations and long-term strategy, we do need to
10:07be responding
10:09to threats to our environment.
10:11We need to make sure threats that we've seen coming because again we should
10:14constantly
10:15be doing analysis or maybe just new threats that have emerged in the industry
10:20due to a
10:21newly discovered vulnerability.
10:23So either way, we need to be constantly keeping up and making sure that our
10:29security framework
10:30is assisting not only our daily operations but also helping us implement a long
10:35-term
10:36strategy.
10:37[BLANK_AUDIO]
The NIST Framework
0:00So let's begin here by talking about the three main components of the NIST CSF.
0:10The first of those components is the core.
0:14And really the core is the heart of the framework.
0:18What exactly does that mean?
0:20Well, the core organizes our cybersecurity activities into six high-level
0:26functions, which
0:28are then further divided into categories and subcategories.
0:32So the main idea behind the core is organization.
0:38We're trying to organize what it is we're trying to do.
0:41As we said, there are in fact six separate functions here in the core.
0:46And as such, there's a lot to discuss around the core itself.
0:51So we're going to actually do that in a separate lesson rather than trying to
0:55approach it here.
0:57The second component is the implementation tiers.
1:02The implementation tiers represent how an organization views their
1:08cybersecurity risk.
1:10Where do they think they currently are?
1:12Where are they headed?
1:13What are they trying to do?
1:16These tiers represent the processes that are in place to manage that risk.
1:22And it sort of tells us where we are in that process, basically going from we
1:27don't really
1:28have much of a security structure all the way up to we are fully implemented.
1:34There are four tiers that represent this.
1:36So we go from tier one to tier four, and we will break down these four tiers
1:40and what
1:41they relate to coming up in just the moment.
1:44The third and final component is the framework profile.
1:50The idea behind the framework profile is we're going to take the core functions
1:55, which are
1:55again, what we were referring to up here, these six core functions that we
2:00haven't broken
2:01down in detail just yet.
2:03But the idea behind the profile is we want to define how those core functions
2:08are going
2:09to align with our current business requirements.
2:12Again, it's good to have a lot of security, but it does have to align with our
2:16business
2:17requirements.
2:19What our risk tolerance is and what resources we have available.
2:24And remember that risk tolerance and resources often go hand in hand because it
2:31takes resources
2:32to be able to have a low risk tolerance.
2:35So the profile is defining how the core functions are going to work within our
2:41business requirements,
2:42risk tolerance, and our available resources.
2:46So if you think about it, that really means that this serves as a customization
2:51layer
2:51between the full security framework and what we've chosen to implement in our
2:57own environment.
2:59So as I said, we're going to jump into the core in much more detail coming up.
3:04But for now, let's move on and talk in a little more detail about these other
3:08two components
3:09and let's start with the implementation tiers.
3:13As we mentioned, there are four implementation tiers.
3:17The first one is tier one.
3:21And this one is called partial.
3:24This basically means that the corporation is currently using like what we call
3:29ad hoc
3:30cybersecurity, meaning they've maybe sort of implemented a firewall and maybe
3:35they're requiring
3:36secure passwords for their users.
3:38So they've got some security going on, but it's not really a coherent plan.
3:44There are no actual formal processes on how we're implementing our security.
3:49Again, it's not saying that there is no security.
3:52That's why it's called partial.
3:54But there's really no structured process.
3:57And we really sort of have limited awareness as far as what's going on in our
4:01environment
4:02because we don't have anything fully implemented.
4:06The second tier is defined as risk informed.
4:11This means that we've actually done a little bit of research.
4:14We've looked into our environment and we've identified the areas in our network
4:19that do
4:19present a formidable risk.
4:22So we know what needs to be protected.
4:25And at this point, we're going to do an initial policy development.
4:30We're going to start putting together the pieces that we want to have in our
4:35overall
4:35cybersecurity practice.
4:37However, at this tier, we still have inconsistent enforcement.
4:43So we're not standard on our security across the board.
4:47Again, we're definitely better off than tier one, but we're still not where we
4:51really
4:51want to be.
4:53Number three, which is called repeatable, this is where we finally have a
4:59formalized process.
5:01We know what our security is supposed to be.
5:03Hopefully, we have actually implemented that.
5:06That's the idea behind tier three.
5:09And we're performing regular audits to make sure that that formalized process
5:14is actually
5:15being implemented in our environment.
5:18Also, we're doing ongoing training.
5:22Making sure that not only is our staff and our security team properly trained,
5:27but also
5:28all of the end users and employees.
5:30Again, remember, everybody has to be trained from a cybersecurity perspective.
5:36And then finally, we have tier four, which arguably is where we want to be.
5:41So this is where we're adaptive.
5:44And we now have a dynamic posture.
5:47This means that we're in a really good position to modify our security posture.
5:53If new risks come along, we have a lot of threat intelligence.
5:57We're watching what's going on in the industry, continuously monitoring our
6:01posture and adapt
6:03to emerging threats.
6:05And we have a very integrated strategy.
6:09Cyber security at this point is integrated into the organization's overall risk
6:14management
6:15strategy.
6:16So again, these are referred to as the maturity tiers.
6:19A lot of organizations, of course, started tier one.
6:22And our goal is to get to tier four.
6:25So this is the idea behind the different implementation tiers.
6:29Now let's talk about those profiles.
6:32So generally, they're going to be two key profiles used.
6:36The first one is the current profile, pretty self explanatory, I think.
6:42But this is the organization's existing cybersecurity posture.
6:47What's already in place and what do they currently have implemented in their
6:51environment?
6:52So our main focus here is going to be looking at existing protections and, most
6:57importantly,
6:58where gaps may exist in that current profile.
7:03So that's the idea is we want this to help us identify where those gaps are.
7:08And given the gaps, we then look at our target profile.
7:13This is the desired state.
7:16This is where we want to end up.
7:18So basically, this is what we want to be the before.
7:22And this should be the after.
7:24And we have to understand that the target profile really needs to be based on
7:28the business
7:29goals, the compliance needs, and/or the risk thresholds.
7:35So we really have to make sure that the target profile is what the company is
7:39after and trying
7:40to accomplish in their environment.
7:42So how are these profiles actually used then?
7:45Well, the main idea is it's supposed to help or aid the organization, do things
7:51like conduct
7:53that gap analysis.
7:54We want to know where the weaknesses are in our network.
7:58So we want to know what the gap is between our current and our target states.
8:03And once we know that, we can then start to prioritize the different actions
8:08and, like
8:09we said, this costs money.
8:10So investments that we want to make in order to get to that target profile.
8:18Another benefit here is it will make sure that we're aligning our strategy with
8:23our risk
8:24management.
8:25Again, why is this important?
8:27We need to make sure that when we're implementing security, that we're doing it
8:31in such a way
8:32that it matches up with what the company actually needs and wants.
8:37And as part of that process, we are also going to have to facilitate
8:41communication.
8:43We have to bring everybody into alignment with what we're trying to accomplish.
8:48And this is going to involve the technical teams, the executive teams.
8:52We have to make sure that everybody's on the same page with what we're trying
8:56to accomplish.
8:57And that's exactly what a profile is going to accomplish.
9:01Now moving away a little bit from the components, let's talk about some of the
9:05benefits of using
9:06the CSF.
9:07Well one of the big benefits is it's flexible and scalable.
9:11Some of the other models we're going to look at are not so flexible and
9:15scalable.
9:16But this can be adopted by organizations really of any size or maturity level
9:21as far as their
9:22security stance.
9:24This can be applied across different industries.
9:26Again, this can be applied in both the private and the public sector.
9:31This is very, very risk focused.
9:33How many times through this whole discussion do we talk about risk management?
9:38We're going to encourage prioritization based on impact and the likelihood of
9:43something
9:44happening.
9:45It's also important by the way that we use a common language.
9:49And this is sort of going back to that, getting the teams together.
9:52We need to make sure that the technical teams and the administrative teams are
9:56actually talking
9:57about the same thing.
9:59Of course, quite common for that not to be the case.
10:02We need to make sure everybody's together on what we're trying to accomplish.
10:06And of course, one of the other big benefits here is it's going to improve
10:11resilience.
10:12We want to build a proactive and dynamic security posture that's going to work
10:16well for the
10:17company.
10:18And finally, let's wrap up with some of the steps we would need to apply the N
10:23IST framework.
10:25So the first thing we want to do is create our current profile so that we know
10:29where
10:30we currently are as we're beginning our journey.
10:33The next step, of course, would be to create the target profile.
10:38Where do we want to go?
10:39Where do we want to end up when this whole thing's finished?
10:43Then we want to compare those two things.
10:46We want to create that gap analysis so that we know the difference between our
10:51current
10:52and our target environment.
10:54Once we know the difference is, we then have to prioritize our actions.
10:59What do we do first?
11:01What resources do we need?
11:02Do we have those resources?
11:04So we need to prioritize everything we're going to do to get to the target
11:10profile.
11:11And of course, another important part of applying the NIST framework is
11:15measuring our progress
11:17as we go.
11:19Not only of course, for our benefit, but generally speaking, managers and those
11:23people
11:24in the executive suites may want to know exactly what's going on.
11:28Remember that the framework is most effective when it's integrated with our
11:32enterprise risk
11:33management strategies and it's revisited periodically.
11:37[BLANK_AUDIO]
The NIST Core Functions
0:00So now let's take a little bit of a closer look at those six core functions of
0:08the NIST model.
0:11First on the top of the list is govern.
0:14Govern is simply defined as the policies, the procedures, the management
0:20practices,
0:21all that guide the organization's cybersecurity program.
0:25So in other words, this is sort of like the oversight.
0:29And the oversight here is going to be in charge of watching things like risk
0:34management,
0:35making sure that our risk is within the tolerances that we've decided as a
0:40company we're willing to accept.
0:42Also that we are in compliance with any and all necessary,
0:46either governmental or industry standard security practices
0:51and that our own security policies are in fact being implemented and followed
0:58as they should be.
1:00Next up, we have identify.
1:03The identify function is where we're supposed to develop that understanding of
1:09the current business context,
1:11assets, data and the current risks.
1:15So in order to accomplish that, we're going to be taking a look at identifying
1:19things like, again, the available assets.
1:22So what do we have available? What can we use?
1:25Then we have our business environment.
1:27What are we trying to accomplish?
1:29What does the business do?
1:31We're trying to identify again, maybe any security policies that need to be ad
1:36hered to for that particular business.
1:38Again, maybe medical or financial.
1:41This is also where we want to do a risk assessment.
1:44Figuring out what are the possible risks and what our susceptibility to those
1:49risks would be.
1:51And don't forget that part of those risks could be our supply chain.
1:55A lot of corporations need to be able to get products to make product.
2:00So if something happens with a supply chain, then they can't make those
2:04products.
2:05And that's going to fall under our security umbrella as well, making sure that
2:09things like business partner relationships are secure and things like that.
2:13From a business perspective, that's not really our problem.
2:16But from a security perspective, we need to make sure that connections with,
2:20again, things like business partners and so on are secure and needed for the
2:26business.
2:27Next up is protect.
2:29In protect, this is where we're going to actually develop and implement the
2:34safeguards that we're going to use to try to limit the impact of any cyber
2:38security event.
2:40So this is going to involve things like identity management and access control,
2:44making sure that only the right people have access to the right things.
2:49And usually we want to go with the concept of least privilege.
2:53So people have the least amount of privilege they need to do their job to the
2:58least number of assets that they need access to.
3:02Part of this also is going to be awareness and training.
3:05I've mentioned this a few times now, but we have to make sure that everybody in
3:09the corporation understands security procedures.
3:13We also have to do things like secure our data.
3:16This could involve things like encryption, data backup, things along those
3:20lines.
3:21So that's going to fall under things like information protection processes and
3:25procedures.
3:26How do we do that?
3:28When do we run backups, for example?
3:30Where are the offsite backups stored?
3:32All of these things have to be documented and we have to have a process.
3:37We also need to make sure we're doing proper maintenance.
3:40So again, this is going to be things like updating antivirus software, updating
3:44anti malware software, ensuring that the intrusion prevention system has the
3:48latest signatures, making sure operating systems get the patches they need.
3:53This is of course a very long list of things. I'm just filling out some
4:01examples, but part of the protect process is making sure that the devices
4:03themselves are protected and having protective technology itself.
4:05And again, that could be part of the intrusion prevention system.
4:09Also things like firewalls VPNs to protect wide area links.
4:14So a lot of things fall under protective technology, but a lot of different
4:18things we're going to implement under the protect umbrella.
4:21Next is the tech.
4:24The idea behind detect is we have to have ways to identify any cyber security
4:30incidents.
4:32Number one, we have to know that something actually happened.
4:36So we want to keep track of anomalies and events.
4:40Anomalies could just indicate that an event is going to happen or the anomaly
4:44itself could indicate that an event is happening.
4:48Event could be again, current and ongoing, or it could be something even that
4:52happened in the past.
4:54We still want to be aware of it if we can.
4:57So this is going to involve constantly monitoring our security environment.
5:01Now, keep in mind that this is not going to be very feasible for a human to be
5:06continuously monitoring all of our security software.
5:10And it's a little bit beyond the scope of what we're talking about right this
5:13moment, but there's a lot of software out there that can work as a call.
5:17And then we're going to talk about what we're going to do.
5:20And then we're going to talk about what we're going to do.
5:23And then we're going to talk about what we're going to do.
5:26And then we're going to talk about what we're going to do.
5:28And then we're going to talk about what we're going to do.
5:30And then we're going to talk about what we're going to do.
5:32And then we're going to talk about what we're going to do.
5:34And then we're going to talk about what we're going to do.
5:36And then we're going to talk about what we're going to do.
5:38And then we're going to talk about what we're going to do.
5:40And then we're going to talk about what we're going to do.
5:42And then we're going to talk about what we're talking about that's then going
5:47to trigger some sort of an event, maybe send an email telling us things are
5:49going wrong, or some sort of notification process.
5:52Once we've detected something though of course, we're also going to have to
5:56respond.
5:57So the response is of course going to be taking action of some sort after that
6:01sort of the key here, a detected incident happened.
6:06And then we have our incident response plan and that's exactly what this is.
6:11This is our response planning. What do we do after something happened.
6:15Now this is going to involve a lot of communication.
6:17We have to communicate with the affected stakeholders.
6:20We have to analyze what happened.
6:23We have to have good analysis in order to communicate to those stakeholders
6:27what actually occurred.
6:29We have to figure out what to do about it. What's our mitigation. How do we
6:34recover from whatever happened.
6:36So that might mean restoring from backup. That might mean contacting customers.
6:42There's a lot of different things that could fall under the mitigation process.
6:45But we need to have some plan in place of what we're going to actually do.
6:50And finally, we want to try to make sure that events don't occur again in the
6:55future. So how do we actually improve our environment to make sure these things
7:00don't happen again.
7:02And finally, although I sort of threw it in under mitigation there, we have
7:06recover itself, which is again, after we've implemented things we need to be
7:11able to restore our capabilities.
7:13What is it going to take to get the environment back online after an incident
7:18occurred.
7:19So how do we recover from something that happened. And this is going to
7:23definitely involve a recovery plan.
7:26And this, of course, is a huge topic.
7:30We can talk about everything from just having backups, having redundant hard
7:34drives, having redundant network equipment, maybe just redundant supervisor
7:37engines and our switches, having power backup, having HVAC backup.
7:42Connecting our data center to separate power grids. All of these things are
7:46part of plans to get things to recover if things happen.
7:51And it could go all the way up to having a full offsite data center or a
7:55disaster recovery site where we can bring things back online.
8:00And once again, we sort of throw improvements in here as well.
8:04Part of the recovery process is to implement improvements. So hopefully this
8:08doesn't happen again.
8:10And of course, part of all of this as well, like always is good communication.
8:15Everybody needs to be on the same page. Everybody needs to know what we're
8:18trying to accomplish with our recovery process.
8:22Keep in mind that these core functions, they do not have to be accomplished in
8:28a linear fashion.
8:30They can operate concurrently and continuously to form an operational culture
8:36of cybersecurity risk management.
8:39So that concludes everything that we're going to discuss here in part one of
8:44this multi part skill.
8:46So I would encourage you to go ahead and take the challenge.
8:49And then after you've completed that challenge to go ahead and move on to part
8:53two of this skill.
8:55And I'll see you in part two of this skill.
8:58Thank you.
Challenge
0:00So, for this challenge, we're asked to jump in and answer a few questions about
0:08the contents
0:09of this skill to ensure our proper understanding.
0:13So let's go ahead and jump in here with the first question.
0:17Which NIST CSF function focuses on restoring services after a cybersecurity
0:25event?
0:26And of course, the key to this is going to be right here with the restoring.
0:31Which of these is going to involve restoring?
0:35So the first answer here is recover.
0:37Well, recover is generally going to involve restoring services.
0:41So that's probably a good answer.
0:43Let's just verify the others real quick.
0:46Protect is actually something that comes into play before we lose services.
0:52Identify happens way at the beginning when we're trying to figure out what to
0:55protect
0:56Respond is actually very close, but that's actually the step right before we're
1:03actually
1:03trying to restore services.
1:05So again, this is going to basically leave us with recover as the correct
1:11answer.
1:12Second question, which organization is responsible for publishing cybersecurity
1:18standards for
1:19DOD systems?
1:22So again, let's go down our list.
1:24Our first answer, CISA, this is one of the organizations we spoke of, but not
1:30specifically
1:31for DOD systems.
1:33That's from the Department of Homeland Security.
1:35NIST, again, this is also one of the organizations we discussed, but not
1:41related to the DOD.
1:43NSA is not even one of the agencies we discussed, although that is one of our
1:47agencies here
1:48in the United States.
1:50So that's going to leave DISA as our correct answer here for question two.
1:56Question three, which of the following is a benefit of the NIST cybersecurity
2:02framework?
2:03Our first answer is it mandates specific tools and vendors, and that's not
2:08something that
2:09NIST does, so that's going to be incorrect.
2:13It replaces all other compliance frameworks.
2:16Well, if that was the case, we probably wouldn't have discussed the other ones,
2:21so that's not
2:21going to be a correct answer.
2:24It provides a flexible, risk-based approach.
2:28That actually sounds like a good answer, but let's check the last one here
2:30first before
2:31we mark it.
2:33It is only applicable to federal agencies.
2:35No, in fact, one of the advantages of the NIST framework is that it can easily
2:40be applied
2:41to the private sector as well.
2:43So that means that it provides a flexible, risk-based approach is going to be
2:49our correct
2:50answer.
2:51Final question, what is a key benefit of using the NIST CSF in a commercial
2:59environment?
3:00First answer, it enforces mandatory DOD-level controls.
3:05Well that wouldn't make a whole lot of sense in a commercial environment, so
3:09this is not
3:09going to be correct.
3:11It includes government-only encryption algorithms.
3:14Well, again, if it's government-only, then it wouldn't apply in a commercial
3:18environment,
3:19so that's clearly not going to be the case either.
3:23It provides adaptable, risk-based guidance.
3:27Well we know that term "risk-based" definitely applies to NIST, so that's
3:32probably going
3:33to be our answer.
3:35If we look at the last answer, it replaces the need for SIMS.
3:40If you're not familiar with this, that stands for security information and
3:45event management.
3:46These are different systems that can collect information.
3:49That's not what NIST CSF does, so again it's going to leave our best answer at
3:57it provides
3:58adaptable, risk-based guidance.
4:02So that concludes this challenge as well as this first half of our two-part
4:08skill.
4:09So I would encourage you to now move on to part two.
4:12In the meantime, I hope this has been informative for you, and I'd like to
4:16thank you for viewing.
4:17[BLANK_AUDIO]
Team training path
Turn this skill into assignable team training
This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.
$708
seat / year