Risk Ranking Requires Classification Context - It's more than just the audit

Much like the value of a home, an asset's risk and value are all about location, location, location, or in this case, understanding the neighborhood surrounding your data.

Security needs to enforce asset classification. To effectively scope and prioritize mandated controls, all operations should be far down the path of asset classification. Whether government classified or non-classified information, the strata of classification on assets is the key to setting priority and removing findings from a relevant scope.

RISKRESPONSEBANDIMPACT

Some examples of classification used by Defense Information Systems Agency or DISA include:

  •  MAC-1_Classified - I - Mission Critical Classified
  •  MAC-1_Public - I - Mission Critical Public
  •  MAC-1_Sensitive - I - Mission Critical Sensitive
  •  MAC-2_Classified - II - Mission Support Classified
  •  MAC-2_Public - II - Mission Support Public
  •  MAC-2_Sensitive - II - Mission Support Sensitive
  •  MAC-3_Classified - III - Administrative Classified
  •  MAC-3_Public - III - Administrative Public

For non-military and unclassified systems, a simpler approach might include such classifications as 

  •  Level 1 - Workstation - Items in this profile intend to:
  • be practical and prudent.
  • provide a clear security benefit; and
  • not inhibit the utility of the technology beyond acceptable means.

Level 2 Workstation - This profile extends the "Level 1 - Workstation" profile. Items in this profile exhibit one or more of the following characteristics:

  • are intended for environments or use cases where security is paramount.
  • acts as a defense in depth measure.
  • may negatively inhibit the utility or performance of the technology.

Level 1 Server - Items in this profile intend to:

  • be practical and prudent.
  • provide a clear security benefit; and
  • not inhibit the utility of the technology beyond acceptable means.

Level 2 Server - This profile extends the "Level 1 - Server" profile. Items in this profile exhibit one or more of the following characteristics:

  • are intended for environments or use cases where security is paramount.
  • acts as a defense in depth measure.
  • may negatively inhibit the utility or performance of the technology.

Level 1 Domain Controller - Items in this profile apply to Domain Controllers and intend to:

  • be practical and prudent.
  • provide a clear security benefit; and
  • not inhibit the utility of the technology beyond acceptable means.

Level 2 Domain Controller - This profile extends the "Level 1 - Domain Controller" profile. Items in this profile exhibit one or more of the following characteristics:

  • are intended for environments or use cases where security is paramount
  • acts as a defense in depth measure
  • may negatively inhibit the utility or performance of the technology

Level 1 Member Server - Items in this profile apply to Member Servers and intend to:

  • be practical and prudent.
  • provide a clear security benefit; and
  • not inhibit the utility of the technology beyond acceptable means.

Items in this profile also apply to Member Servers that have the following Roles enabled:

  • AD Certificate Services
  • DHCP Server
  • DNS Server
  • File Server
  • Hyper-V
  • Network Policy and Access Services
  • Print Server
  • Remote Access Services
  • Remote Desktop Services
  • Web Server

Level 2 Member Server - This profile extends the "Level 1 - Member Server" profile. Items in this profile exhibit one or more of the following characteristics:

  • are intended for environments or use cases where security is paramount
  • acts as a defense in depth measure
  • may negatively inhibit the utility or performance of the technology

One final question: Isn't Compliance Fabric and Compliance Platform just another way to say GRC?

GRC tools provide the business view of Risk, Compliance & Security, whereas the compliance fabric solution supplies the evidence based operational and platform necessary to supply security operations with remediation work plans, as well as the necessary content for effective asset-based vulnerability, risk, compliance programs. 

EnterpriseGRC Solutions actively contributes to all major standards and organizations responsible for the mapping of regulatory requirements and the most highly leveraged national and international standards. In addition to organic CIS Benchmarks and DISA STIG NIST-based configuration hardening and change management, EnterpriseGRC Solutions has implemented all assessments with NIST Cybersecurity Framework (CSF) and NIST 800-53 r4 and Appendix J for Privacy. Clients who elect to use multiple policy packs, including ISO/IEC 27002:2013, will benefit from the extended use of multiple frameworks to align Information Security Programs and Policy.

About EnterpriseGRC Solutions

EnterpriseGRC Solutions is empowered to implement governance, security, risk, and compliance automation products and programs, emphasizing system-based policies specific to security settings for secure configuration management. EnterpriseGRC is a women-owned small business offering compliance readiness, Security & GRC tools, Enterprise Security Architecture, Cybersecurity Risk Assessment, and a wide variety of resources for security and GRC technology support. Founded in October of 2002 as Phoenix Business and Systems Process, and rebranded in 2011 as EnterpriseGRC Solution, the company is positioned to solve an organization's greatest cloud security and cyber challenges. True to its tagline "Simple Solutions to Complex Problems" the company offers pragmatic, remote, and on-site web-enabled compliance implementation, training, strategy, management consulting, security, and risk management services.

About Center for Internet Security

The Center for Internet Security, Inc. (CIS) is a 501c3 nonprofit organization focused on enhancing the cyber security readiness and response of public and private sector entities, with a commitment to excellence through collaboration. CIS provides resources that help partners achieve security goals through expert guidance and cost-effective solutions. 

About DISA

DISA, a Combat Support Agency, provides, operates, and assures command and control, information-sharing capabilities, and a globally accessible enterprise information infrastructure in direct support to joint warfighters, national-level leaders, and other mission and coalition partners across the full spectrum of operations.

Read more about CIS Critical Security Controls Version 8 and the CIS-CAT Pro

CIS CSC

 

Main Menu