Identifying risk, analyzing risk, and planning appropriate actions. 

  • Risk-related actions are planned, scheduled and tracked as additional tasks in the project plan
  • Risk tracking occurs in a risk watch list
  • On-going activity throughout the project
  • Depends on all project team members being risk-aware, utilizing the defined risk management process
  • Phase IV. Implement and Monitor
  • Integrated Evidence for ISO27001+ISO27017, SOC 2, HITRUST, PCI-DSS ROC
  • Mature Enterprises, Harmonize Control Frameworks, Risk Based Approach
  • Risk Response requires cybersecurity programs
  • Incident Response
  • Security Playbooks
  • Computer Security Incident Response Team (CSIRT)
  • Event Analysis (CSIRT EA) tuning meeting
  • Investigation's meeting
  • Operations and Engineering biweekly and monthly meetings
  • Delivery and Implementation meetings
  • Threat Intelligence meetings
  • Threat and Vulnerability Management
  • Configuration Management: Secure Host Baseline Config

Let’s take out a high-profile target

  1. Get access to the target’s outlook calendar (schedule)
  2. Discover the route they travel (location)
  3. Get fake uniforms so we blend in (identity)
  4. Distract the guards (opportunity)
  5. Interrupt the live camera feed so they don’t see us (time)
  6. Purchase a weapon that can’t be traced (malware, spyware…)
  7. Go – Go – Go: Take out the target

Burn down the structure so there’s nothing left, or just encrypt everything and sell the target their own key. (ransomware)

  • A successful kill only requires 5 elements
  • Systems & Configuration Management Objective
  • Incidents Require Root Cause Analysis
  • What is the root cause for any failure?
  • Example: “metrics indicate 80% of malicious code infections are attributed to vulnerable versions of Java”
  • What were the steps to create the finding?
  • What are the expectations as a result of this finding?
  • What is the measure of Security Program health?
Main Menu